Blog Post

DORA, NIS2 and the Four-Hour Clock Reshaping GRC

August 11, 2026

Table of Contents

A GRC program that produces documents quarterly cannot file a regulatory notification in four hours. The sentence carries the whole modernization argument, and the four-hour figure is not rhetorical. Under DORA, an EU financial entity classifying an incident as major has four hours to send an initial notification, then twenty-four hours for an initial report, seventy-two for an intermediate one and a month for the final.

NIS2 runs its own cascade of twenty-four hours, seventy-two hours and one month, and GDPR adds a seventy-two hour clock where personal data is involved. One incident at one organization can start all of them. Regulators did not ask for better documentation, they specified a response speed that an annual assessment cycle cannot produce.

Several Clocks From One Incident

The obligations overlap in subject and diverge in timing, recipient and threshold, which is what makes them operationally difficult rather than merely numerous.

The Clocks Start on Awareness

Deadlines run from the moment the organization becomes aware of an incident rather than from the point an investigation concludes, so the first notification goes out on partial information by design. The twenty-four hours also run continuously rather than in business hours, which makes round-the-clock notification capability a practical requirement rather than a maturity aspiration. An early warning submitted with an incomplete picture is expected, and the later stage exists to correct it.

Missing a Deadline Is Its Own Violation

Late notification is a separate finding from whatever the incident was, which changes the calculus around uncertainty. Over-reporting in good faith carries no penalty while missing a clock does, so the rational response to an ambiguous event is to start the process and stand it down later. Programs treating notification as a decision to be finalized rather than a process to be started tend to discover this the expensive way. Incident handling and reporting sit close together here, and the obstacles in incident reporting recur across regimes rather than being specific to one.

The Obligation Cannot Be Outsourced

Engaging a managed security provider transfers the work and not the duty, since the entity remains responsible for timely reporting. The same principle appears in third-party provisions, where contracting with a provider does not delegate regulatory accountability, and what DORA means for enterprises covers the scope side of that question.

Why This Breaks the Annual Cycle

Assessment-driven GRC produces a defensible position once or twice a year. Nothing about that model answers a question in four hours, and two specific dependencies are the reason.

Classification Has to Be Pre-Decided

Deciding whether an incident is significant or major cannot take twenty hours of the twenty-four available. Thresholds, criteria and the person authorized to apply them have to be settled in advance, including who decides when that person is unavailable. Programs holding a classification discussion during the incident are spending the notification window on a question that had a knowable answer beforehand.

One Record Feeding Several Formats

Filing three notifications from three separately assembled accounts produces inconsistencies a supervisor will notice, particularly where the same incident is described with different impact figures. A single continuously updated incident record, with each notification drawn from it, keeps the facts aligned across regimes. Maintaining that record inside the risk register rather than in an email thread is what makes the audit trail reconstructable afterward.

Accountability Moved to Named People

Both regimes attach consequences to individuals rather than only to entities, which is the change that alters board behavior.

  • Management Approval: Supervisors examine whether the management body approved and oversees the risk measures, not whether they exist.
  • Financial Ceilings: Essential entities face administrative fines reaching at least ten million euros or two percent of worldwide turnover.
  • Personal Consequences: Temporary management bans are available for essential entities, which no insurance policy addresses.

Important entities sit below that ceiling at seven million euros or one and two-fifths percent of turnover, and the difference in exposure is smaller than the difference in attention it receives. Documented evidence that a named body reviewed and approved the measures is what satisfies the first item, which makes board oversight a filing matter rather than a governance preference.

Continuity Became a First-Class Concern

Earlier regulation concentrated on confidentiality, and the current generation concentrates on whether the service keeps running. Digital operational resilience is the name of the regulation rather than a theme within it, and all-hazards risk measures explicitly include business continuity alongside incident handling and supply chain security.

Modeled likelihood of an outage exceeding successive duration thresholds from eight hours through forty-eight hours
Modeling how likely an outage is to exceed a working day, or two, answers the continuity question in the terms resilience regulation uses.

Duration Is the Unit Regulators Reason In

Recovery objectives stated as policy targets say what the organization intends. Modeled duration distributions say what is likely, which is a different and more useful claim when a supervisor asks whether the objective is achievable. Testing requirements point the same direction, since a threat-led exercise measures real recovery rather than documented intent. Quantification supports the same argument, and using quantification for NIS2 compliance covers how modeled figures answer supervisory questions.

Thresholds Need Numbers Attached

Significance criteria are specified in implementing rules and still require the organization to know its own scale, since the same incident can be significant at one entity and not at another. Classification therefore depends on quantities the program should already hold.

Modeled likelihood of a data incident exceeding successive proportions of total records held
Knowing the likely scale of a records incident in advance turns a classification decision into a lookup rather than an argument.

Record volumes, outage durations and financial impact bands all appear in significance tests, and an organization able to state its modeled distributions can classify quickly. One unable to state them spends the early hours estimating. Materiality work already covers this ground for disclosure purposes, and determining cyber materiality uses the same figures a NIS2 significance test needs.

What Modernization Requires

Three changes carry most of the difference between a program that meets these obligations and one that documents an intention to.

  • Pre-Agreed Decisions: Classification criteria, notification authority and escalation paths settled before an incident rather than during one.
  • Continuous Evidence: Registers, control status and incident records maintained as operations rather than assembled for audits.
  • Quantified Scale: Modeled duration, record volume and financial impact available on demand so classification is a lookup.

None of these is a tooling purchase, though tooling helps with the second. The change is that outputs become continuous rather than periodic, which is the same transition continuous control monitoring represents on the control side. Programs already running quantification inside GRC hold the third item and often have not connected it to notification.

Where Programs Are Behind

Supervision has moved from guidance toward active review, with national authorities across several member states conducting examinations rather than issuing further clarification. Three weaknesses recur.

Notification capability is untested, so nobody knows whether the chain functions outside business hours or when a key person is unavailable. Registers are stale, because they were built for a filing and not maintained afterward. Classification criteria exist as a policy statement rather than as thresholds someone can apply under pressure. Testing the chain end to end is cheap relative to the penalty, and it is the item most often deferred. Turning an assessment into scheduled work is what converting assessments into action plans addresses. Preparing across regimes together rather than sequentially is what NIS2 accountability ends up requiring in practice.

Regulation Specified an Operating Model

The current generation of cyber regulation is less concerned with whether an organization holds the right policies and more concerned with whether it can answer specific questions within specific windows. Four hours, twenty-four hours, seventy-two hours and one month are operating requirements rather than documentation requirements, and no annual cycle satisfies them. Kovrr's cybersecurity GRC approach keeps the register, control status and modeled impact current, so classification and notification draw on figures that already exist.

To see modeled duration, record volume and financial impact maintained as a live position rather than an annual exercise, book a demo with our cyber risk experts.

Shalom Bublil

Kovrr Co-founder & Chief Product Officer

DORA and NIS2 FAQs

Speak to an Expert
No items found.