Incident Command Platform
← Home

Cyber Breach Notification Deadlines

A consolidated reference of the major cyber breach notification clocks that US organizations operate under. Last reviewed April 7, 2026.

Federal — United States

RegulationDeadlineClock TriggerNotify
SEC 8-K Item 1.054 business daysDetermination of materialitySEC via Form 8-K
HIPAA Breach Notification Rule60 days (individuals); 60 days (HHS if ≥500)Discovery of breachIndividuals + HHS OCR + media (if ≥500 in state)
GLBA Safeguards Rule (FTC)30 daysDiscovery of notification event affecting ≥500 consumersFTC
CIRCIA (when effective)72 hours (substantial incident); 24 hours (ransomware payment)Reasonable belief of covered cyber incidentCISA

European Union

RegulationDeadlineClock TriggerNotify
GDPR Article 3372 hoursAwareness of personal data breachLead DPA + concerned DPAs
GDPR Article 34Without undue delayHigh risk to data subjectsAffected data subjects
NIS224 hours (early warning); 72 hours (full); 1 month (final)Significant incidentNational CSIRT / competent authority
DORA (financial entities)Initial: as soon as possible; intermediate: 72 hours; final: 1 monthMajor ICT incidentCompetent authority

US State Examples

StateDeadlineTrigger
California (CCPA / 1798.82)Without unreasonable delayDiscovery of unauthorized acquisition of PII
New York SHIELD ActMost expedient time possibleDiscovery of breach of private information
NY DFS Part 50072 hoursCybersecurity event with reporting to any supervisory body, or material harm
Texas (Bus. & Com. 521.053)60 daysDiscovery of breach
Florida (FIPA)30 daysDiscovery of breach
Illinois (PIPA)Most expedient time possible, without unreasonable delayDiscovery of breach
Virginia (VA Code 18.2-186.6)Without unreasonable delayDiscovery or notification
Colorado (CPA 6-1-716)30 days (residents); 30 days (AG if ≥500)Discovery of breach

Industry / Contractual

FrameworkDeadlineClock Trigger
PCI DSSImmediatelySuspected account data compromise
Cyber insurance (typical)24–72 hoursFirst awareness of potential claim
Customer DPAs (typical)24–72 hoursSecurity incident involving customer data
Disclaimer: This table is a quick reference for planning and exercise purposes. It is not legal advice. Deadlines, exemptions, and triggers vary by jurisdiction and by fact pattern. Verify with counsel during any actual incident. For the operational workflow, see our Incident Response Playbook, SEC 96-Hour Notification, and GDPR 72-Hour Notification.