Cyber Compliance Reference

Cyber Incident Reporting Windows
by Jurisdiction

When a cyber incident occurs, the clock starts immediately. Every jurisdiction has different mandatory reporting deadlines โ€” and when you operate across multiple markets, the strictest deadline governs. This reference page covers every major jurisdiction's mandatory notification obligations.

Multi-jurisdiction rule: When operating across multiple jurisdictions, the shortest applicable deadline governs your response timeline. A company with operations in India and the EU must meet the CERT-In 6-hour deadline โ€” not the GDPR 72-hour deadline.

Quick Reference by Deadline

โ‰ค 6 hours
๐Ÿ‡ฎ๐Ÿ‡ณIndiaCERT-In
24 hours
๐Ÿ‡จ๐Ÿ‡ณChinaCSL
๐Ÿ‡ช๐Ÿ‡บEU โ€” NIS2NIS2
๐Ÿ‡บ๐Ÿ‡ธUSA โ€” CIRCIACIRCIA
72 hours / 4 days
๐Ÿ‡ช๐Ÿ‡บEU โ€” NIS2NIS2
๐Ÿ‡ช๐Ÿ‡บEU โ€” GDPRGDPR
๐Ÿ‡ฌ๐Ÿ‡งUKUK
๐Ÿ‡บ๐Ÿ‡ธUSA โ€” CIRCIACIRCIA
๐Ÿ‡บ๐Ÿ‡ธUSA โ€” SECSEC
๐Ÿ‡ฐ๐Ÿ‡ทSouth KoreaPIPA
๐Ÿ‡ฆ๐Ÿ‡ชUAEPDPL
๐Ÿ‡ธ๐Ÿ‡ฆSaudi ArabiaPDPL
๐Ÿ‡จ๐Ÿ‡ฆCanadaPIPEDA
๐Ÿ‡ฆ๐Ÿ‡บAustralia โ€” SOCISOCI
2โ€“3 days
๐Ÿ‡ง๐Ÿ‡ทBrazilLGPD
๐Ÿ‡ธ๐Ÿ‡ฌSingaporePDPA
30 days / flexible
๐Ÿ‡ฏ๐Ÿ‡ตJapanAPPI
๐Ÿ‡จ๐Ÿ‡ฆCanadaPIPEDA
๐Ÿ‡ฆ๐Ÿ‡บAustralia โ€” NDBNDB
๐Ÿ‡ฆ๐Ÿ‡บAustralia โ€” SOCISOCI

Full Jurisdiction Comparison

JurisdictionLaw / RegulationDeadlineReport ToScopeMax Fine
๐Ÿ‡ฎ๐Ÿ‡ณIndiaCERT-In Rules 20226 hoursCERT-In All organisations operating in IndiaCriminal liability under IT Act 2000
๐Ÿ‡จ๐Ÿ‡ณChinaCSL 2017 / DSL 2021 / PIPL 202124 hoursMIIT / CACAll organisations processing Chinese data or operating in ChinaUp to RMB 50m; business suspension
๐Ÿ‡ช๐Ÿ‡บEU โ€” NIS2NIS2 Directive 202424h early warning / 72h fullNational CSIRT18 critical sectors + supply chainsUp to โ‚ฌ10m or 2% global turnover
๐Ÿ‡ช๐Ÿ‡บEU โ€” GDPRGDPR Article 3372 hoursNational supervisory authorityAll organisations processing EU personal dataUp to โ‚ฌ20m or 4% global turnover
๐Ÿ‡ฌ๐Ÿ‡งUKUK GDPR / Data Protection Act 201872 hoursICO All organisations processing UK personal dataUp to ยฃ17.5m or 4% global turnover
๐Ÿ‡บ๐Ÿ‡ธUSA โ€” CIRCIACIRCIA 202272h incidents / 24h ransomwareCISA 16 critical infrastructure sectorsCivil penalties; final rules pending
๐Ÿ‡บ๐Ÿ‡ธUSA โ€” SECSEC Cybersecurity Rules 20234 business daysSEC (Form 8-K)US public companiesSEC enforcement action
๐Ÿ‡ฐ๐Ÿ‡ทSouth KoreaPIPA (amended 2023)72 hoursPIPCAll organisations processing South Korean personal dataUp to 3% of relevant revenue
๐Ÿ‡ฆ๐Ÿ‡ชUAEPDPL (Federal Decree-Law 45/2021)72 hoursUAE Data OfficeAll organisations processing UAE personal dataUp to AED 5m
๐Ÿ‡ธ๐Ÿ‡ฆSaudi ArabiaPDPL (effective September 2023)72 hoursSDAIAAll organisations processing Saudi personal dataUp to SAR 5m
๐Ÿ‡ง๐Ÿ‡ทBrazilLGPD (2020)2 working daysANPDAll organisations processing Brazilian personal dataUp to 2% of Brazilian revenue, capped at R$50m per violation
๐Ÿ‡ธ๐Ÿ‡ฌSingaporePDPA (amended 2021)3 calendar daysPDPCAll organisations processing Singapore personal dataSGD 1m or 10% of annual Singapore turnover
๐Ÿ‡ฏ๐Ÿ‡ตJapanAPPI (amended 2022)30 days (60 if foreign actors)PPCAll organisations processing Japanese personal dataUp to JPY 100m (corporate)
๐Ÿ‡จ๐Ÿ‡ฆCanadaPIPEDA / Quebec Law 25As soon as feasible (QC: 72h)OPC / CAI (Quebec)All organisations processing Canadian personal dataUp to CAD 100,000
๐Ÿ‡ฆ๐Ÿ‡บAustralia โ€” NDBNDB Scheme (Privacy Act 1988)30 daysOAIC Organisations covered by the Privacy ActUp to AUD 50m (Privacy Act Review reforms)
๐Ÿ‡ฆ๐Ÿ‡บAustralia โ€” SOCISOCI Act (amended 2022)12h serious / 72h otherASD11 critical infrastructure sectorsCivil penalties

Jurisdiction Notes

๐Ÿ‡ฎ๐Ÿ‡ณ
India
CERT-In Rules 2022
6 hours

Strictest deadline globally. Also: 180-day log retention in India. Covers ransomware, data breaches, DDoS, malware.

๐Ÿ‡จ๐Ÿ‡ณ
China
CSL 2017 / DSL 2021 / PIPL 2021
24 hours

Strict data localisation requirements. Cross-border data transfer restrictions. Security assessments required for certain transfers.

๐Ÿ‡ช๐Ÿ‡บ
EU โ€” NIS2
NIS2 Directive 2024
24h early warning / 72h full

Supply chain security obligations: covered entities must assess their suppliers. 1-month final report also required.

๐Ÿ‡ช๐Ÿ‡บ
EU โ€” GDPR
GDPR Article 33
72 hours

Also notify affected individuals if high risk (Article 34). Applies regardless of where the organisation is based.

๐Ÿ‡ฌ๐Ÿ‡ง
UK
UK GDPR / Data Protection Act 2018
72 hours

Post-Brexit retained UK GDPR. NIS Regulations 2018 also apply to essential services. UK Cyber and Resilience Bill (2025) will expand scope.

๐Ÿ‡บ๐Ÿ‡ธ72h incidents / 24h ransomware

72 hours for significant cyber incidents; 24 hours for ransomware payments. CISA final rules expected 2025โ€“2026.

๐Ÿ‡บ๐Ÿ‡ธ
USA โ€” SEC
SEC Cybersecurity Rules 2023
4 business days

4 business days from determining materiality. Annual disclosure of cyber risk management in Form 10-K. Creates supply chain pressure.

๐Ÿ‡ฐ๐Ÿ‡ท
South Korea
PIPA (amended 2023)
72 hours

2023 amendments significantly strengthened requirements. ICNA also requires incident reporting to KISA for digital service providers.

๐Ÿ‡ฆ๐Ÿ‡ช
UAE
PDPL (Federal Decree-Law 45/2021)
72 hours

UAE Cybersecurity Council also mandates critical infrastructure incident reporting. DIFC and ADGM have separate data protection regimes.

๐Ÿ‡ธ๐Ÿ‡ฆ
Saudi Arabia
PDPL (effective September 2023)
72 hours

NCA (National Cybersecurity Authority) mandates critical infrastructure incident reporting. Vision 2030 driving rapid regulatory expansion.

๐Ÿ‡ง๐Ÿ‡ท
Brazil
LGPD (2020)
2 working days

ANPD guidance specifies 2 working days from awareness. LGPD applies regardless of where the organisation is based.

๐Ÿ‡ธ๐Ÿ‡ฌ
Singapore
PDPA (amended 2021)
3 calendar days

Notifiable breach = likely significant harm or affects 500+ individuals. MAS also has separate cyber incident reporting for financial institutions.

๐Ÿ‡ฏ๐Ÿ‡ต
Japan
APPI (amended 2022)
30 days (60 if foreign actors)

Cybersecurity Basic Act + Economic Security Promotion Act 2022 add supply chain security requirements for critical infrastructure.

๐Ÿ‡จ๐Ÿ‡ฆ
Canada
PIPEDA / Quebec Law 25
As soon as feasible (QC: 72h)

Quebec Law 25 (in force Sept 2023): 72-hour notification to CAI. Bill C-26 (proposed) would add mandatory cyber reporting for critical infrastructure.

๐Ÿ‡ฆ๐Ÿ‡บ
Australia โ€” NDB
NDB Scheme (Privacy Act 1988)
30 days

Eligible breach = likely serious harm. Privacy Act Review (2023) may tighten timelines.

๐Ÿ‡ฆ๐Ÿ‡บ
Australia โ€” SOCI
SOCI Act (amended 2022)
12h serious / 72h other

12 hours for serious incidents; 72 hours for other incidents. Supply chain security requirements for critical infrastructure operators.

Is your incident response plan multi-jurisdiction ready?

ESG Stress Free's Cyber AI Analyst helps SMEs understand their reporting obligations across all the jurisdictions they operate in โ€” and build an incident response plan that meets the strictest applicable deadline.

Open Cyber AI Analyst
Last reviewed: April 2026 ยท This page is for general information only and does not constitute legal advice. Consult a qualified lawyer for advice specific to your situation.