1 · Statutory incident-reporting deadlines
Rows appear only for regimes in your profile. Build these clocks into your incident response plan (§4 of the IR plan template).
| Regime | Trigger | Deadline | Recipient |
|---|---|---|---|
| NIS2 Art. 23 NIS2 | Significant incident | Early warning ≤ 24 h · notification ≤ 72 h · final report ≤ 1 month | National CSIRT / competent authority |
| GDPR Art. 33 GDPR | Personal data breach with risk to individuals | ≤ 72 h from awareness | Data protection authority |
| GDPR Art. 34 GDPR | High risk to individuals | Without undue delay | Affected data subjects |
| DORA Art. 19 DORA | Major ICT-related incident | Initial ≤ 4 h from classification / ≤ 24 h from awareness · intermediate ≤ 72 h · final ≤ 1 month | Competent financial authority |
| CRA Art. 14 CRA | Actively exploited vulnerability / severe incident in a product you manufacture | Early warning ≤ 24 h | ENISA / CSIRT via single reporting platform |
| Denmark — national channel DK | Significant incident (Danish entities) | NIS2 pattern: 24 h / 72 h / 1 month | Via virk.dk — CSIRT function: Forsvarets Efterretningstjeneste / CFCS |
Some reporting rows are hidden by your profile.
2 · Regulatory hooks per framework function
GOVERN
- Management bodies must approve measures, oversee implementation and follow training; personal liability possible — NIS2 Art. 20. NIS2
- All-hazards, proportionate risk-management approach — NIS2 Art. 21(1). NIS2
- Management body bears final responsibility for ICT risk — DORA Art. 5. DORA
- Controller accountability and appropriate measures — GDPR Art. 24 & 32. GDPR
- Registration duty on virk.dk for covered entities — NIS 2-loven § 33. DK·NIS2
- Top management approval and legal accountability for beredskabsplaner; requirements exceed the EU minimum. DK·ENERGI
IDENTIFY
- Risk analysis and vulnerability handling policies — NIS2 Art. 21(2)(a),(e); supplier/dependency knowledge — Art. 21(2)(d). NIS2
- Records of processing double as data-flow inventory — GDPR Art. 30. GDPR
- Identification of ICT-supported functions and information assets — DORA Art. 8. DORA
- Security requirements for products with digital elements feed procurement criteria. CRA
PROTECT
- Cryptography policies, access control, MFA, hygiene & training — NIS2 Art. 21(2)(f)–(j). NIS2
- Encryption and pseudonymisation as named measures — GDPR Art. 32. GDPR
- Protection and prevention measures — DORA Art. 9. DORA
- Mandated network segmentation, physical security integration, constraints on control-centre location. DK·ENERGI
- Physical resilience measures for critical entities complement cyber controls. CER
DETECT
- Reporting deadlines are only achievable with functioning detection — NIS2 Art. 21(2)(b), 23. NIS2
- Detection speed determines 72 h feasibility; security logs about employees are personal data — purpose-limit them. — GDPR Art. 33, Art. 5. GDPR
- Prompt anomaly-detection mechanisms — DORA Art. 10. DORA
- Real-time 24/7 monitoring of critical installations required. DK·ENERGI
RESPOND
- Incident handling and staged reporting — NIS2 Art. 21(2)(b), 23. NIS2
- Notify DPA ≤ 72 h; document all breaches, even non-notified — GDPR Art. 33(5), 34. GDPR
- Incident management, classification and reporting — DORA Art. 17–19. DORA
- Report via virk.dk; drill the flow against the 24 h early-warning clock. DK
RECOVER
- Business continuity, backups, disaster recovery and crisis management — NIS2 Art. 21(2)(c); final report ≤ 1 month — Art. 23. NIS2
- Ability to restore availability and access to personal data in a timely manner — GDPR Art. 32(1)(c). GDPR
- Response & recovery plans, backup policies, testing — DORA Art. 11–12. DORA
- Continuity of essential societal functions under all-hazards scenarios. CER
Some regulatory hooks are hidden by your profile.
3 · National implementations (all 27 member states)
\nTick your member state(s) in the panel. Status verified July 2026 — always confirm against the national gazette; detailed annexes live in docs/annexes/.
Denmark: NIS2/CER arrive as a family of acts (NIS 2-loven; energy, tele and finance sector acts; CER-loven), in force since 2025.
Coordination: Styrelsen for Samfundssikkerhed (SAMSIK); CSIRT: CFCS/FE; sector authorities supervise their sectors.
SAMSIK/CFCS guidance uses skal / bør / kan tiers — map your control evidence to it.
Full detail:
docs/annexes/annex-dk.md.
Other member states: transposition varies — contribute a national annex for your country (see CONTRIBUTING.md).
Country notes are hidden by your profile.