LEGAL COMPLIANCE CALCULATOR

Cyber Incident Breach Notification Deadline Calculator

Determine exact statutory disclosure deadlines and mandatory compliance clocks across multiple regulatory jurisdictions. Enter discovery and materiality timestamps to generate customized countdowns for legal counsel.

Incident Timestamps

Timestamp when security team confirmed unauthorized access.
Required for SEC Form 8-K Item 1.05 clock (4 business days).
Triggers 24-hour CIRCIA and NY DFS extortion reporting clocks.

Calculated Statutory Disclosure Clocks

Live Status Active
U.S. Securities and Exchange Commission

SEC Form 8-K (Item 1.05)

Calculating... --
Trigger: Determination of materiality (not initial discovery)
Statutory Mandate: 4 business days post materiality determination

Excludes federal holidays and weekends. A limited delay of up to 30 days is available only if the U.S. Attorney General determines disclosure poses a substantial risk to national security or public safety.

Scope: Public companies subject to the Exchange Act View Related Legal Statute →
Cybersecurity and Infrastructure Security Agency (CISA)

CIRCIA Covered Incident

Calculating... --
Trigger: Reasonable belief that a covered cyber incident occurred
Statutory Mandate: 72 hours from reasonable belief

Covers significant cyber incidents affecting critical infrastructure. Supplemental reports are required if substantial new information becomes available.

Scope: Entities within covered critical infrastructure sectors View Related Legal Statute →
Cybersecurity and Infrastructure Security Agency (CISA)

CIRCIA Ransomware Payment

Calculating... --
Trigger: Execution of a ransom payment disbursement
Statutory Mandate: 24 hours from ransom payment execution

Applies even if the underlying attack had not previously been classified as a covered incident.

Scope: Any covered entity that makes a ransom payment View Related Legal Statute →
EU / UK Data Protection Authorities (DPAs)

GDPR Article 33 (Supervisory Authority)

Calculating... --
Trigger: Becoming aware of a personal data breach
Statutory Mandate: 72 hours from awareness

Where notification is not made within 72 hours, it must be accompanied by reasons for the delay. Notification to data subjects (Art. 34) is required without undue delay if high risk to rights and freedoms.

Scope: Controllers processing personal data of EU / UK data subjects View Related Legal Statute →
U.S. Department of Health and Human Services (HHS OCR)

HIPAA Breach Notification Rule

Calculating... --
Trigger: Discovery of a breach of unsecured protected health information (PHI)
Statutory Mandate: 60 calendar days to individuals and HHS (immediate if >500)

Breaches affecting 500 or more residents of a state or jurisdiction require prominent media notices and immediate notification to the Secretary without unreasonable delay and in no case later than 60 days.

Scope: Covered entities and business associates under HIPAA View Related Legal Statute →
New York State Department of Financial Services

NY DFS 23 NYCRR 500.17

Calculating... --
Trigger: Determination that a cybersecurity event occurred meeting criteria
Statutory Mandate: 72 hours to Superintendent; 24 hours for extortion payments

Notice is required if the event has a reasonable likelihood of materially harming any material part of normal operations, or if notice is provided to any other regulator.

Scope: Banking, insurance, and financial services entities licensed in New York View Related Legal Statute →
Office of the Texas Attorney General

Texas Data Privacy and Security Act (Bus. & Com. Code § 521.053)

Calculating... --
Trigger: Discovery of breach of system security
Statutory Mandate: Notice to Texas AG within 30 days if >250 Texas residents

Electronic reporting portal must be utilized. Notice to affected individuals required without unreasonable delay and in no case later than 60 consecutive days.

Scope: Businesses conducting commerce in Texas possessing sensitive personal information View Related Legal Statute →
Payment Card Industry Security Standards Council & Card Brands

PCI DSS Requirement 12.10.5

Calculating... --
Trigger: Suspected or confirmed compromise of cardholder data environment
Statutory Mandate: Immediate alert to acquirer and card payment brands (Visa, Mastercard)

Requires immediate forensic engagement with a qualified Payment Card Industry Forensic Investigator (PFI).

Scope: Entities storing, processing, or transmitting cardholder data (CHD) View Related Legal Statute →