Komplyo blog
Incidents and vulnerabilities
A single incident can fall under several notification deadlines: 72 hours under the GDPR, 24 hours for the NIS2 early warning, 24 hours under the CRA for a vulnerability under active exploitation. These articles set out the triggers, the recipients and the expected content of each notification, along with the coordinated vulnerability disclosure policy.
Get the security policy template
An information security policy template in .docx format, structured around NIST CSF 2.0 and ISO 27001. Delivered by email, usable as a documentation baseline.