72-Hour Notification Requirement
The 72-hour notification requirement is a rule found in several different laws and regulations that generally requires an organization to report a qualifying data breach or cyber incident to a designated authority within 72 hours. The exact trigger, recipient, and content of the report depend on which specific regime applies, so the same phrase can mean different things across sectors and jurisdictions. It is not a single universal standard, and organizations must identify which particular obligation governs their situation.
"72-Hour Notification Requirement" is an informal umbrella label for a group of distinct legal and regulatory obligations, each imposing a maximum 72-hour window to notify a specified body following a qualifying event. Under the EU GDPR, a controller must generally notify the competent supervisory authority within 72 hours of becoming aware of a personal data breach that meets the applicable threshold (with certain exceptions and separate rules for processors and for communicating to data subjects). Distinct U.S. regimes use a comparable window but differ in trigger, scope, and recipient: NCUA rules require federally insured credit unions to notify the NCUA as soon as possible and no later than 72 hours after a reportable cyber incident (per the evidence, from September 1, 2023); CIRCIA-related provisions concern reporting significant cyber incidents affecting critical infrastructure to CISA; and Department of Defense contractor obligations require reporting a cyber incident to the DoD within 72 hours with a preliminary assessment. These regimes are not interchangeable — they differ in what counts as a qualifying event, who must report, to whom, and what information is required, and some (such as CIRCIA implementation) reflect evolving rulemaking. Readers should verify the precise trigger, timing calculation, and content requirements against the current authoritative text of the specific applicable law or regulation, as these provisions are periodically amended and their enforcement practice may diverge from the statutory or regulatory text.
Why it matters
The phrase "72-hour notification requirement" appears across multiple unrelated legal regimes, and treating it as a single universal rule is a common and consequential error. The same 72-hour window governs personal data breaches under the EU GDPR, reportable cyber incidents at federally insured credit unions under NCUA rules, cyber incidents affecting critical infrastructure under CIRCIA-related provisions reported to CISA, and cyber incidents affecting certain Department of Defense contractors. Each regime defines a different qualifying event, a different reporting entity, and a different recipient authority. An organization that satisfies one obligation has not necessarily satisfied another, and some organizations may fall under more than one at once.
The practical stakes are high because the clock is short and the triggers are technical. Determining when the 72-hour window begins — for example, when a controller "becomes aware" of a personal data breach under the GDPR, versus when a credit union identifies a reportable cyber incident under NCUA rules — requires a factual and often time-sensitive judgment made under pressure. Misidentifying which regime applies, or miscalculating the start of the window, can lead to late or misdirected reports.
Because these obligations differ in scope and are, in some cases, still the subject of evolving rulemaking (CIRCIA implementation being a notable example), organizations should map their specific exposure in advance rather than during an incident. This entry describes the general shape of these requirements; it does not substitute for the current authoritative text of any specific law or regulation, and application to a particular situation requires professional judgment.
Who it's relevant to
Inside 72-Hour Notification Requirement
Common questions
Answers to the questions practitioners most commonly ask about 72-Hour Notification Requirement.