These frameworks don't leave the specifics to you

GDPR, HIPAA, PCI-DSS, NIS2 and DORA, each with its own trigger, its own requirements and its own clock.

Each of these has its own trigger, and if one applies it applies unambiguously. What it then asks for is written as requirements rather than principles: named authentication controls, named logging intervals, named notification windows.

  • What each one asks
  • Every clock starts from a moment you have to be able to name

What each one asks

FrameworkWhat it asks that the others don'tNotification clock
GDPRRights and disclosure records, with erasure that carries through to processors.72 hours to the supervisory authority
HIPAAUnique user identification, automatic logoff, and transmission security.60 days from discovery
PCI-DSSMulti-factor authentication on every entry into the cardholder data environment, and logging reviewed daily.Immediate, under card brand rules and the acquirer contract
NIS2Access control policy with multi-factor authentication, and supply chain obligations passed down to you.24 hours early warning, 72 hours incident notification, one month to the final report
DORAIncident classification, and a four-hour notification clock once an incident is classified as major.4 hours from classification as major, 24 hours from becoming aware

Every clock starts from a moment you have to be able to name

Awareness, discovery, classification. Each of those is a point in time you have to evidence, and the difference between a 24-hour clock and a 72-hour one is academic if you cannot say when it started. DLP timestamps the detection, so that moment is a record rather than a reconstruction.

Tell us which framework you're being measured against.

Send us the framework, the audit date and what you already run. We'll come back with the mapping for your environment and the evidence Akku produces for each control.