RES-02Resilience and Response

Breach notification within statutory time

Reportable incidents are assessed and notified to regulators and affected people within the applicable deadlines.

Why it exists

The clock starts at awareness, not at certainty.

What usually proves it

Assessment records, notification evidence, timing.

Smaller organizations

Know your deadlines before you need them.

Mapped to

  • Partially addressedSOC 2 Trust Services Criteria · CC7.5 — Communication of incidents without statutory deadlines.
  • Partially addressedISO/IEC 27001 Annex A · A.5.24 — Reporting without statutory timing.
  • Fully addressedNIST Cybersecurity Framework · RS.CO-02
  • Partially addressedPCI DSS · 12.10.1 — Notification to brands and acquirers.
  • Fully addressedHIPAA Security Rule · 164.404
  • Fully addressedGDPR · Art. 33, 34
  • Fully addressedEU AI Act · Art. 73
  • Deliberately absentNIST AI Risk Management Framework — No notification obligation; the framework is voluntary guidance.