Compliance

The Compliance Clock

NIS2, DORA and GDPR set deadlines in hours. Work backwards from them and see what your SOC actually has to do.

23 Jun 2026 · 7 min read

Executive summary

European regulation has quietly done something the security industry never managed on its own: it put a number on how fast incident response has to be. GDPR started it, with 72 hours to notify the authority of a personal-data breach. NIS2 tightened it for essential and important entities: an early warning within 24 hours of becoming aware of a significant incident, a fuller notification at 72 hours, a final report within a month. DORA, for financial entities, runs the hardest clock of all: an initial report within hours of classifying a major ICT incident, an intermediate report at 72 hours, a final report within a month [1].

Most compliance analysis of these regimes concentrates on the paperwork: templates, competent authorities, what counts as significant. This paper works the other direction. A notification deadline is the end of a chain that starts with an alert in a queue. If the report is due at hour 24, then detection, investigation, scoping and classification have to fit inside a fraction of those hours — and that is an operational requirement on your SOC, not a legal one on your counsel. Measured against how security operations actually run today, with two-thirds of alerts never investigated and twenty-minute manual investigations behind a many-hour queue, the arithmetic does not work. The regimes assume an investigation capability most organisations do not have. Closing that gap is what this paper is about.

1. Three clocks, one assumption

The three regimes differ in scope and severity thresholds, but their reporting ladders rhyme:

RegimeFirst deadlineSecondFinal
GDPR (personal data breaches)72h to notify the supervisory authority, from awarenessDocumentation duty ongoing
NIS2 (essential / important entities)24h early warning, from awareness of a significant incident72h incident notification, with initial assessment1 month final report
DORA (financial entities)Initial report within hours of classifying a major ICT incident72h intermediate report1 month final report

Look at what the first-deadline column actually demands in content. An early warning or initial report is not a sentence saying something happened. Regulators expect whether the incident is suspected to be malicious, whether it has cross-border impact, an initial view of severity and scope [1]. To say those things honestly at hour 24 — or within hours, under DORA — you must already have investigated: confirmed the alert is real, established which systems and data are touched, formed a view of the attacker's foothold. The shared, unstated assumption of all three regimes is that awareness converts to understanding within hours. That assumption is the whole subject of this paper.

2. Working the clock backwards

Take NIS2's 24 hours and spend it the way an honest incident actually spends it. The clock starts at awareness — but awareness itself starts late. The alert that first evidences the incident does not announce itself as the one that matters; it lands in a queue among hundreds or thousands of others, of which most SOCs investigate a small fraction. In the representative mid-size operation we modelled in The Response Gap, a ten-person team covers about 11% of a 1,500-alert day [2]. If the critical alert sits in the uninvestigated 89%, the 24-hour clock does not start late. Far worse: it starts on time, at the moment your systems became aware, while your understanding starts days later. Median dwell time is 14 days [3]. A regulator asking why notification came on day 15 of a 14-day-old incident is not a hypothetical scenario; it is the base case.

Now assume the alert is picked up promptly. A manual investigation runs about 20 minutes when it is simple [2]. Incident-grade scoping is not simple: it means querying identity systems, endpoints, network logs and cloud consoles, correlating what comes back, widening to every touched account and host, and writing conclusions someone can sign. Done by hand, across teams and time zones, that is a working day if things go well. Add drafting, internal review, legal sign-off — and the 24 hours are spent before anyone dared to classify. Under DORA's classification-triggered initial report, the squeeze is tighter still: the deadline is measured in single-digit hours from classification, so the investigation that supports classification is the entire game [1].

The conclusion from working backwards is plain. The reporting deadlines are met or missed in the SOC, hours or days before the report is written. A compliance programme that invests in templates and escalation matrices while leaving alert coverage at 11% has bought stationery for a letter it will not be able to write in time.

3. Response speed is now a compliance control

The reframing this paper argues for is that investigation capacity belongs in the compliance architecture, alongside the register of processing activities and the incident response plan. Concretely, three operational capabilities map directly onto regulatory obligations.

  • Coverage maps to awareness. If alerts go uninvestigated, your organisation is generating awareness it cannot act on — the worst position under any of the three regimes, since the clock runs while understanding does not. 100% alert investigation converts 'aware' from a liability into a controlled state.
  • Investigation speed maps to the first deadline. Scoping in minutes rather than days is what makes a 24-hour early warning, or a DORA initial report, something you write from evidence rather than guesswork.
  • Documentation maps to the final report and to audit. NIS2's one-month report and DORA's final report demand a reconstruction of what happened and what was done. If every investigation step, query and conclusion is recorded as it happens, the final report is an export. If not, it is archaeology.

There is a defensive-liability angle worth naming, with the caveat that we are technologists, not lawyers, and your counsel should shape the position. Regulators across regimes distinguish between organisations that were breached despite sound operations and organisations whose operations were the breach. An evidenced ability to investigate every alert and scope incidents in minutes is the kind of demonstrable diligence that changes those conversations — and its absence, once these regimes mature, will be conspicuous.

4. Meeting the clock: what the operation needs

The capability the deadlines assume has a specific shape, and it is the shape our Response Gap paper's five requirements describe. It must investigate everything, continuously, because awareness can start with any alert at any hour — a 24/7 obligation no shift pattern meets economically. It must scope automatically, pulling and correlating the evidence around a confirmed finding without waiting for a human to compose each query. It must document as it goes, producing the audit-ready trail the final report needs. It must act under governance — pre-authorised containment for low-risk actions, human approval for consequential ones — because regulators expect a response, not only a notification. And it must run where your data lives, since for many entities in scope the telemetry itself is regulated.

Human teams supply judgment, sign-off and the conversations with authorities. What they cannot supply, at any defensible cost, is minute-scale investigation of every alert at all hours. That layer is either automated or absent.

5. Where CounterShadow fits

AMI, CounterShadow's AI responder, investigates every incoming alert end to end in about eight minutes: verdict, severity, scope, and either containment or a gated approval, per your rules [2]. Three of its properties bear directly on the clocks. Coverage: 100% of automatable alerts investigated around the clock, so awareness and understanding start together. Speed: scoping in minutes gives the 24-hour and hour-scale deadlines room to breathe, with the human hours spent on decisions rather than evidence-gathering. Documentation: every investigation produces a full report, evidence pack and step-by-step timeline as a by-product of the work — the raw material of an NIS2 or DORA report, generated before anyone asks. Deployment options run from SaaS through private cloud to fully self-hosted and air-gapped, and every action is logged for audit.

Model what full coverage does to your own incident timeline at countershadow.com/roi, and put your compliance and SOC leads in the same room when you read the results. The deadline belongs to both of them.

Conclusion

For twenty years, response speed was an internal virtue: good teams were fast, stretched teams were slow, and the difference stayed inside the building. NIS2, DORA and GDPR moved it outside. Speed is now measured against statutory clocks that start at awareness and do not pause for staffing, weekends or queue depth. Read your own operation against those clocks honestly: how much of the alert stream gets investigated, how long scoping really takes, what your 3am capability is. If the answers cannot carry a 24-hour early warning written from evidence, the gap is operational, and it closes the way this series has argued throughout — by putting machine-speed investigation under every alert, with humans governing rather than queuing.

References

  1. Regulation (EU) 2016/679 (GDPR) art. 33; Directive (EU) 2022/2555 (NIS2) art. 23 reporting ladder (24h early warning / 72h notification / 1-month final report); Regulation (EU) 2022/2554 (DORA) art. 19 major-incident reporting (initial report on an hours-scale after classification, 72h intermediate, 1-month final), as detailed in current regulatory implementation guidance. Verify current national transposition and technical standards with counsel.
  2. CounterShadow ROI model, countershadow.com/roi. Modelled scenario: 1,500 alerts/day, ten analysts, ~20-minute manual investigations, ~11% coverage; AMI ~8-minute end-to-end investigation.
  3. Mandiant / Google Cloud, M-Trends 2026: 14-day global median dwell time.

© 2026 CounterShadow. This paper is general information, not legal advice; obtain counsel on your entity's obligations. It may be shared freely in unmodified form.

More research

Further papers

View all whitepapers
AI Governance04 Aug 2026

Trusting the Machine

When it is safe to let AI act in your SOC — and when it is not. An honest paper from a vendor with skin in the game.

Read paper · 7 min
Managed Services03 Aug 2026

The Analyst-Shaped Hole in MSSP Margins

Why managed security economics stopped working, and what AI responders change for multi-tenant operations

Read paper · 7 min
Incident Response28 Jul 2026

When the Attacker Is an Agent

Incident response was designed for human adversaries. The adversary has changed.

Read paper · 8 min