RES-02Resilience and Response
Breach notification within statutory time
Reportable incidents are assessed and notified to regulators and affected people within the applicable deadlines.
Why it exists
The clock starts at awareness, not at certainty.
What usually proves it
Assessment records, notification evidence, timing.
Smaller organizations
Know your deadlines before you need them.
Mapped to
- Partially addressedSOC 2 Trust Services Criteria · CC7.5 — Communication of incidents without statutory deadlines.
- Partially addressedISO/IEC 27001 Annex A · A.5.24 — Reporting without statutory timing.
- Fully addressedNIST Cybersecurity Framework · RS.CO-02
- Partially addressedPCI DSS · 12.10.1 — Notification to brands and acquirers.
- Fully addressedHIPAA Security Rule · 164.404
- Fully addressedGDPR · Art. 33, 34
- Fully addressedEU AI Act · Art. 73
- Deliberately absentNIST AI Risk Management Framework — No notification obligation; the framework is voluntary guidance.