In short
- Cyber Resilience Act reporting has been mandatory since 11 September 2026, on a 24, 72 and 14 day cadence for actively exploited vulnerabilities.
- NIS2 also opens at 24 hours with an early warning, followed by a fuller notification at 72 hours.
- GDPR gives 72 hours from awareness of a personal data breach, and the AI Act gives 2 to 15 days depending on the harm.
- The same event can engage all four. The AI Act clock is almost always the slowest, which is why an AI specific incident process is the wrong place to start.
- Four regimes means four recipients: a CSIRT and ENISA, a data protection authority, a market surveillance authority, and in NIS2 cases the national competent authority.
What do AI assistants say about your organisation?
Model answers are becoming a channel your communications team does not control. EntityRise audits how assistants describe your company and whose name they give instead. From $19.
Yesterday the fourth clock started. Cyber Resilience Act reporting became mandatory on 11 September 2026, including for products already on the market.
An organisation running an AI feature inside a digital product can now trip four separate notification regimes with one event.
01What are the four clocks?
| Regime | First deadline | Goes to |
|---|---|---|
| Cyber Resilience Act, Article 14 | 24 hours | Coordinating CSIRT and ENISA |
| NIS2, Article 23 | 24 hours | CSIRT or competent authority |
| GDPR, Article 33 | 72 hours | Supervisory authority |
| AI Act, Article 73 | 2 to 15 days | Market surveillance authority |
Two regimes open at 24 hours. Neither of them is the AI Act, which is the point most AI governance programmes have backwards.
02Which one applies to an AI incident?
That depends on what the incident touched, and often more than one applies.
The Cyber Resilience Act attaches to manufacturers of products with digital elements and fires on an actively exploited vulnerability or a severe incident affecting product security. If your AI feature ships inside a product, this is now live.
NIS2 attaches to essential and important entities and fires on a significant incident, judged by operational disruption or by harm caused. GDPR fires on a personal data breach. The AI Act fires on a serious incident as defined in Article 3(49), which requires death, serious harm to health, serious and irreversible disruption of critical infrastructure, or infringement of fundamental rights obligations.
The AI Act threshold, set out in Article 3(49) and reported under Article 73, is the highest of the four. That is why an incident can be reportable under three regimes and not under the Act at all.
03How do the follow up stages differ?
| Regime | Second stage | Final report |
|---|---|---|
| Cyber Resilience Act | 72 hours | 14 days, or 1 month for incidents |
| NIS2 | 72 hours | 1 month |
| GDPR | Phased where justified | No fixed final report |
| AI Act | Complete an incomplete report | Investigation, Article 73(6) |
The Cyber Resilience Act’s 14 day final report is tied to the availability of a corrective measure rather than to the calendar alone, which is a different shape from the others and worth flagging to whoever owns the runbook.
04What does this mean for the runbook?
One owner, four branches, decided in the first hour.
The design failure is a separate AI incident process, convened by a governance forum, running in parallel to the security incident process. By the time that forum meets, two 24 hour clocks have consumed most of their budget, and the answers depend on logs that were designed months earlier.
What works is a single intake with a triage question set: is a product with digital elements affected, are we an essential or important entity, is personal data involved, and does this meet the Article 3(49) threshold. Four yes or no answers, asked by the on call responder, each pointing at a named filer.
05Who actually files?
Name them before the incident, because four regimes means four relationships.
The CRA notification runs through a single reporting platform to the coordinating CSIRT and ENISA. NIS2 goes to the CSIRT or competent authority designated in your Member State. GDPR goes to your lead supervisory authority. The AI Act goes to the market surveillance authority of the Member State where the incident occurred, which for a system serving several markets may be more than one.
That last detail is the one that surprises legal teams, because the other three regimes generally resolve to a single point of contact and the AI Act does not.
06Frequently asked questions
When did Cyber Resilience Act reporting become mandatory?
11 September 2026. From that date manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents to ENISA and the relevant national CSIRT, including for products already placed on the market.
What is the 24 72 14 rule?
The Cyber Resilience Act reporting cadence. An early warning within 24 hours of becoming aware, a fuller notification within 72 hours, and a final report within 14 days after a corrective measure is available for an actively exploited vulnerability.
Which deadline is shortest after an AI incident?
Usually 24 hours, under either the Cyber Resilience Act or NIS2. The AI Act's fastest clock is two days and its standard clock is fifteen, so it is rarely the binding constraint on the first day.
Do you file one report or four?
Four, to different recipients. There is no single filing that satisfies all four regimes, although the CRA uses a single reporting platform that routes one notification to the coordinating CSIRT and ENISA.
07References and method
- Regulation (EU) 2024/2847 (Cyber Resilience Act), Article 14, and European Commission reporting guidance, for the 24 hour early warning, 72 hour notification and 14 day final report, and for the 11 September 2026 start date.
- Directive (EU) 2022/2555 (NIS2), Article 23, for the 24 hour early warning and 72 hour incident notification.
- Regulation (EU) 2016/679 (GDPR), Article 33, for the 72 hour personal data breach notification.
- Regulation (EU) 2024/1689 (AI Act), Article 73, for the 2, 10 and 15 day serious incident deadlines.