Four regimes, four clocks. Which one fires first after an incident?

CRA reporting went live on 11 September 2026. With NIS2, GDPR and the AI Act, one event can start four clocks, and the fastest gives you 24 hours.

In force EU

In short

  • Cyber Resilience Act reporting has been mandatory since 11 September 2026, on a 24, 72 and 14 day cadence for actively exploited vulnerabilities.
  • NIS2 also opens at 24 hours with an early warning, followed by a fuller notification at 72 hours.
  • GDPR gives 72 hours from awareness of a personal data breach, and the AI Act gives 2 to 15 days depending on the harm.
  • The same event can engage all four. The AI Act clock is almost always the slowest, which is why an AI specific incident process is the wrong place to start.
  • Four regimes means four recipients: a CSIRT and ENISA, a data protection authority, a market surveillance authority, and in NIS2 cases the national competent authority.
Advertisement

What do AI assistants say about your organisation?

Model answers are becoming a channel your communications team does not control. EntityRise audits how assistants describe your company and whose name they give instead. From $19.

Audit your AI visibility at EntityRise.ai →

Yesterday the fourth clock started. Cyber Resilience Act reporting became mandatory on 11 September 2026, including for products already on the market.

An organisation running an AI feature inside a digital product can now trip four separate notification regimes with one event.

01What are the four clocks?

Deadlines read from the operative text of the cited provisions. Comparison prepared by The Guardrail; each figure traces to one regime, not to a combined rule.
RegimeFirst deadlineGoes to
Cyber Resilience Act, Article 1424 hoursCoordinating CSIRT and ENISA
NIS2, Article 2324 hoursCSIRT or competent authority
GDPR, Article 3372 hoursSupervisory authority
AI Act, Article 732 to 15 daysMarket surveillance authority

Two regimes open at 24 hours. Neither of them is the AI Act, which is the point most AI governance programmes have backwards.

02Which one applies to an AI incident?

That depends on what the incident touched, and often more than one applies.

The Cyber Resilience Act attaches to manufacturers of products with digital elements and fires on an actively exploited vulnerability or a severe incident affecting product security. If your AI feature ships inside a product, this is now live.

NIS2 attaches to essential and important entities and fires on a significant incident, judged by operational disruption or by harm caused. GDPR fires on a personal data breach. The AI Act fires on a serious incident as defined in Article 3(49), which requires death, serious harm to health, serious and irreversible disruption of critical infrastructure, or infringement of fundamental rights obligations.

The AI Act threshold, set out in Article 3(49) and reported under Article 73, is the highest of the four. That is why an incident can be reportable under three regimes and not under the Act at all.

03How do the follow up stages differ?

Follow up stages read from the operative text of each regime. Where a regime uses different periods for vulnerabilities and incidents, both are shown.
RegimeSecond stageFinal report
Cyber Resilience Act72 hours14 days, or 1 month for incidents
NIS272 hours1 month
GDPRPhased where justifiedNo fixed final report
AI ActComplete an incomplete reportInvestigation, Article 73(6)

The Cyber Resilience Act’s 14 day final report is tied to the availability of a corrective measure rather than to the calendar alone, which is a different shape from the others and worth flagging to whoever owns the runbook.

04What does this mean for the runbook?

One owner, four branches, decided in the first hour.

The design failure is a separate AI incident process, convened by a governance forum, running in parallel to the security incident process. By the time that forum meets, two 24 hour clocks have consumed most of their budget, and the answers depend on logs that were designed months earlier.

What works is a single intake with a triage question set: is a product with digital elements affected, are we an essential or important entity, is personal data involved, and does this meet the Article 3(49) threshold. Four yes or no answers, asked by the on call responder, each pointing at a named filer.

05Who actually files?

Name them before the incident, because four regimes means four relationships.

The CRA notification runs through a single reporting platform to the coordinating CSIRT and ENISA. NIS2 goes to the CSIRT or competent authority designated in your Member State. GDPR goes to your lead supervisory authority. The AI Act goes to the market surveillance authority of the Member State where the incident occurred, which for a system serving several markets may be more than one.

That last detail is the one that surprises legal teams, because the other three regimes generally resolve to a single point of contact and the AI Act does not.

06Frequently asked questions

When did Cyber Resilience Act reporting become mandatory?

11 September 2026. From that date manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents to ENISA and the relevant national CSIRT, including for products already placed on the market.

What is the 24 72 14 rule?

The Cyber Resilience Act reporting cadence. An early warning within 24 hours of becoming aware, a fuller notification within 72 hours, and a final report within 14 days after a corrective measure is available for an actively exploited vulnerability.

Which deadline is shortest after an AI incident?

Usually 24 hours, under either the Cyber Resilience Act or NIS2. The AI Act's fastest clock is two days and its standard clock is fifteen, so it is rarely the binding constraint on the first day.

Do you file one report or four?

Four, to different recipients. There is no single filing that satisfies all four regimes, although the CRA uses a single reporting platform that routes one notification to the coordinating CSIRT and ENISA.

07References and method

  1. Regulation (EU) 2024/2847 (Cyber Resilience Act), Article 14, and European Commission reporting guidance, for the 24 hour early warning, 72 hour notification and 14 day final report, and for the 11 September 2026 start date.
  2. Directive (EU) 2022/2555 (NIS2), Article 23, for the 24 hour early warning and 72 hour incident notification.
  3. Regulation (EU) 2016/679 (GDPR), Article 33, for the 72 hour personal data breach notification.
  4. Regulation (EU) 2024/1689 (AI Act), Article 73, for the 2, 10 and 15 day serious incident deadlines.
OC

, Security Editor

Covers agent security and incidents: what an attacker can reach once an AI system holds credentials. Reach them at owen@theguardrailreport.com.