The 36-Hour, 72-Hour, and 30-Day Incident Reporting Clocks

Justin Kirsch | | 12 min read
Cyber incident reporting deadlines for financial institutions, showing the 36 hour, 72 hour and 30 day regulatory clocks

The three federal cyber incident reporting rules that reach almost every financial institution are written in the same shape. Something happens, you reach a particular state of mind about it, and from that moment you have a fixed window to tell your regulator. The deadline is the part everyone remembers. The state of mind is the part that decides whether you were ever going to make it.

Three federal regimes sit across the industry, one for depositories, one for credit unions, and one for non-depository lenders, and they do not agree on any of it. Banks get 36 hours. Credit unions get 72. Mortgage companies and other non-depository lenders get 30 days, but only past a threshold, and their clock starts on a definition of knowledge so broad that it can begin before anyone in management has heard the word "incident."

None of these clocks measure how long you have to fix the problem. They measure how long you have to report it, starting from a moment that is often only identifiable in hindsight. That is the gap this article is about.

$6.3M
Average cost of a data breach at a financial services organization, against a global all-industry average of $4.99 million
Source: IBM, Cost of a Data Breach Report 2026, published July 29, 2026

Three Regulators, Three Clocks, Three Different Starting Guns

Which rule applies to you is decided by your charter, not by the incident. A credit union, a community bank, and a mortgage company can be hit by the same phishing campaign on the same afternoon through the same shared vendor and owe three different reports on three different schedules.

Banks and thrifts fall under the interagency Computer-Security Incident Notification Rule, issued jointly by the Office of the Comptroller of the Currency, the Federal Reserve, and the Federal Deposit Insurance Corporation. The Federal Reserve's supervisory letter on the rule states plainly that "the final rule takes effect on April 1, 2022, with a compliance date of May 1, 2022." It has been in force for four years.

Computer-Security Incident Notification Rule

The OCC must receive this notification from the banking organization as soon as possible and no later than 36 hours after the banking organization determines that a notification incident has occurred.

12 CFR Part 53 (OCC). Parallel provisions: 12 CFR Part 225 subpart N (Federal Reserve), 12 CFR Part 304 subpart C (FDIC).

A "notification incident" is not any security event. The rule reserves it for a computer-security incident that has materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, the institution's ability to carry out banking operations or to deliver products and services to a material portion of its customer base. That materiality qualifier is doing real work. Most alerts never reach it. The ones that do tend to arrive on a bad day, when the people who would make that call are already busy.

Federally insured credit unions answer to a different rule with a different number, and it arrived more recently.

NCUA cyber incident reporting requirement

The NCUA must receive this notification as soon as possible but no later than 72 hours after a federally insured credit union reasonably believes that it has experienced a reportable cyber incident or, if reporting pursuant to paragraph (c)(1)(i)(C) of this section, within 72 hours of being notified by a third-party, whichever is sooner.

12 CFR 748.1(c). In effect since September 1, 2023.

Read the last four words again. Whichever is sooner. A credit union's clock can be started by somebody else. If a core processor, a payments partner, or a managed service provider tells you that you have been caught up in their incident, you have 72 hours from their notice, regardless of what your own team has managed to confirm.

Mortgage companies and other non-depository lenders sit under the Federal Trade Commission's Safeguards Rule, which added a breach notification requirement that the FTC's own guidance confirms took effect on Monday, May 13, 2024.

FTC Safeguards Rule, notification events

Upon discovery of a notification event as described in paragraph (j)(2) of this section, if the notification event involves the information of at least 500 consumers, you must notify the Federal Trade Commission as soon as possible, and no later than 30 days after discovery of the event.

16 CFR 314.4(j).

Thirty days sounds generous next to 36 hours. It is not, because of how the same rule defines discovery. We will come back to that, because it is the single most misread sentence in any of these three regimes.

Institution type Rule Deadline What starts the clock
Banks and thrifts 12 CFR 53, 225 subpart N, 304 subpart C 36 hours You determine a notification incident has occurred
Federally insured credit unions 12 CFR 748.1(c) 72 hours You reasonably believe you had a reportable cyber incident, or a third party tells you, whichever is sooner
Mortgage companies and other non-depository lenders 16 CFR 314.4(j) 30 days You discover a notification event affecting at least 500 consumers
Three column comparison of United States cyber incident reporting deadlines for financial institutions. Banks and thrifts have 36 hours under 12 CFR 53, 225 subpart N and 304 subpart C, starting when the institution determines a notification incident occurred, in force since May 2022. Credit unions have 72 hours under 12 CFR 748.1(c), starting when the credit union reasonably believes a reportable cyber incident occurred or when a third party tells them, whichever is sooner, in force since September 2023. Mortgage and non-depository lenders have 30 days under 16 CFR 314.4(j), starting on discovery where knowledge of any employee counts as the institution knowing, with a threshold of 500 or more consumers, in force since May 2024.
Three regulators, three deadlines, and three different definitions of the moment the clock starts.

The Word That Starts Your Clock

Compliance programs tend to memorize the numbers and skip the verbs. The verbs are where these three rules genuinely diverge, and they set very different expectations about how much certainty you are allowed to wait for.

Determines
The banking standard. It implies a conclusion reached, which sounds like it gives you room to investigate. It does not give you room to avoid investigating. A determination you decline to make is not a determination you never had to make.
Reasonably believes
The credit union standard, and a deliberately lower bar than determination. Belief precedes proof. A credit union waiting for forensic confirmation before starting its 72 hours has likely been in breach of the deadline for some time already.
Discovers
The FTC standard, and the broadest of the three, because the rule defines discovery by reference to organizational knowledge rather than to any judgment call by management.

The practical consequence is that a credit union's obligation can attach earlier than a bank's on identical facts, even though the credit union appears to get twice as long. Reasonable belief sits below proof, so a credit union waiting on certainty is waiting past its own trigger. And in all three cases the institution is being asked to timestamp a mental state, then defend that timestamp to an examiner who is reading the same audit logs you are.

These rules do not ask when you were breached. They ask when you knew. Those are different dates, and for most of what happens inside a tenant, the logs are the most complete record of what anyone was in a position to know.

The Clock Can Start Without Anyone Briefing You

Here is the provision that catches mortgage companies, and it is worth quoting in full because paraphrasing it tends to soften it.

Knowledge is imputed across the whole organization

Under 16 CFR 314.4(j)(2), a notification event "shall be treated as discovered as of the first day on which such event is known to you." The rule then states that you "shall be deemed to have knowledge of a notification event if such event is known to any person, other than the person committing the breach, who is your employee, officer, or other agent."

Any employee. Not the chief information security officer, not the qualified individual named under the Safeguards Rule, not the incident response team.

Two conditions still have to be met before the FTC deadline attaches at all. The event has to be a notification event, meaning unencrypted customer information was acquired without authorization, and it has to involve at least 500 consumers. Neither is established by somebody noticing something strange. But once those conditions are met, the date the 30 days runs from is not the day the institution finished confirming them. It is the first day the event was known to anyone on that very broad list, whether or not the observation ever reached someone with the authority to act on it.

What happened

On a Tuesday, a processor mentions to a colleague that a borrower replied to an email she never sent. Nobody escalates it. On Friday of the following week, the same mailbox is used to redirect wire instructions, and the incident becomes obvious to everyone. Loan files in that mailbox contain customer information.

Where the argument will happen

Whether a clock ran from that first Tuesday depends on facts nobody has established yet: whether unencrypted customer information was actually acquired without authorization, and whether it reached at least 500 consumers. If it did, the institution is arguing about the Tuesday, not the Friday, because that is the day the rule's knowledge test points at. That argument gets made from mailbox audit records, if they still exist.

This is why a reporting obligation is not really a policy problem. You cannot write a procedure that makes an organization notice things. Every one of these three clocks starts at a moment of knowing, and knowing is a detection capability. A written incident response plan tells your team what to do once the clock is running. It does nothing about the days you spent not knowing it had started.

Find out what your tenant would be able to tell an examiner

ABT's free Security Grade reviews your Microsoft 365 tenant against the controls that decide whether you can reconstruct an incident timeline: audit log coverage and retention, alerting, privileged access, and identity protection. No agents to install.

The Provision That Reaches Your Vendors

The banking rule does not stop at banks. It places a separate obligation on the companies that serve them, and this provision gets far less attention than the 36 hours.

Bank service provider notification

A bank service provider is required to notify at least one bank-designated point of contact at each affected banking organization customer as soon as possible when the bank service provider determines that it has experienced a computer-security incident that has materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, covered services provided to such banking organization for four or more hours.

12 CFR Part 53.

Read what the four hours is attached to. It is a threshold on the duration of the disruption, the test for whether the notification obligation is triggered at all. It is not a four hour deadline to send the notice. The timing standard for the notice itself is "as soon as possible."

Two things follow for a bank. First, some of your incident awareness is supposed to arrive from your vendors, which means the "bank-designated point of contact" in your service agreements needs to be a monitored destination rather than a mailbox belonging to someone who left in 2023. Second, a vendor notice can be the event that forces your own determination, and for credit unions a third party notice starts the 72 hours outright under the "whichever is sooner" language.

That makes vendor incident notification a live part of your own reporting posture rather than a procurement detail. It belongs in the same review as your technology due diligence on fintech vendors.

What Microsoft 365 Can Tell You, and What It Cannot

Whether a notification obligation was triggered, and on what date, is a legal determination the institution makes with its counsel and compliance function. No log makes that call. What logs do is supply the factual record the determination rests on, and the record an examiner will read afterward. In most institutions that record lives in Microsoft 365: sign-in logs, mailbox audit records, file access events, and the alerting that either fired or did not.

Which means retention is not a storage question. Unless you have deliberately sent this data somewhere else, tenant retention is the practical horizon on how far back the native record goes, and it is set by licensing.

Tier 1 Cloud Solution Provider (CSP) Audit retention is a licensing decision

Microsoft Purview Audit (Standard) retains most audit records for 180 days by default, raised from the previous 90 day default. Audit (Premium) retains Microsoft Entra ID, Exchange, SharePoint, and OneDrive records for one year, and records can be kept up to 10 years with the 10-Year Audit Log Retention add-on. Audit records generated by non-E5 users and by guest users are retained for 180 days.

Source: Microsoft Learn, Microsoft Purview audit log retention policies and Audit solutions overview.
Bar chart comparing reporting deadlines against Microsoft 365 audit retention. The bank reporting deadline is 36 hours, the credit union deadline is 72 hours, and the FTC Safeguards deadline is 30 days. Microsoft Purview Audit Standard retains records for 180 days by default. Microsoft Purview Audit Premium retains Microsoft Entra ID, Exchange, SharePoint and OneDrive records for one year, and up to 10 years with the add-on license. A callout reads that the deadline is measured in hours while the evidence is measured in months, and that if the record ages out before anyone notices you cannot show when the clock started.
The reporting window is measured in hours. The record that speaks to it is measured in months, and how many months is a licensing decision.

Put that next to a 30 day reporting clock that can start on a day nobody logged, and the risk is easy to state. An institution that discovers in month seven that the first suspicious activity happened in month one may have no audit record left to speak to either date. The retention settings behind your audit log are the difference between a documented timeline and an assertion.

The detection side matters just as much as the record. Microsoft Defender XDR correlates signals across identity, endpoint, email, and cloud applications into a single incident with a timeline, which is the artifact your team reasons from when it asks how early this was visible. Microsoft Sentinel extends the same evidence into longer retention and custom detections. Microsoft Entra ID risk detections surface the compromised sign-in that often precedes everything else, and periodic access reviews in Microsoft Entra ID reduce the number of accounts that can quietly become the entry point.

None of this is exotic. It is standard Microsoft 365 capability, and most institutions already own more of it than they have configured. The gap is usually not the license. It is that nobody is watching the output at 2 a.m. on a Saturday, which is when the clock is least likely to be noticed starting.

IBM's 2026 research found that detection and escalation, together with lost business, made up 63 percent of total breach costs, and that organizations using AI and automation in security operations saved an average of $1.93 million per breach. The cost is concentrated in the part of the incident that happens before anyone is confident about what they are looking at.

What to Fix Before You Need It

None of the following requires a new regulation to justify it. Each one shortens the distance between an event happening and somebody knowing it happened.

Write down which rule applies to you, by name and citation. Institutions with multiple charters or subsidiaries can owe more than one report on different clocks for a single event.
Name who can make the call, and their backup. The determination is a decision a specific person makes. If that person is on a plane, the clock does not pause.
Check your audit retention against your licensing. Confirm what your tenant actually keeps and for how long, including for guest and non-E5 accounts, before you need to reconstruct anything.
Verify the vendor notification contact in every material agreement. For a credit union, a third party notice starts the 72 hours on its own. For a bank, it is often the information that forces the determination. Either way, a notice nobody reads is worth nothing to you.
Give front line staff one obvious way to report something odd. Under the FTC standard their knowledge is already your knowledge. The only question is whether it reaches anyone.
Rehearse the timeline reconstruction, not just the response. Pick a past alert and try to establish the earliest moment it was knowable, using only what your tenant retains today.

Reporting obligations may also run in parallel under other authorities depending on the facts, including suspicious activity reporting and applicable state breach notification laws, each on its own separate timeline. Counsel should map those alongside the prudential clock rather than after it. Mortgage companies working through the wider Safeguards Rule obligations will find the FTC Safeguards Rule requirements mapped to Microsoft 365 a useful companion to this one.

The takeaway

Every one of these deadlines is measured from a moment of knowing, not from the moment of compromise. Institutions do not usually miss these clocks because the deadline was too short. They miss them because the clock had been running for a while before anyone realized it started, and because the records that would have shown otherwise had already aged out of the tenant.

The clock starts when you know. Guardian MxDR shortens how long that takes.

ABT manages Microsoft 365 tenants for more than 750 credit unions, banks, and mortgage companies. Guardian MxDR provides 24/7 monitoring and response across Microsoft Defender, Microsoft Sentinel, and Microsoft Entra ID, so suspicious activity is reviewed and escalated by people who are awake. Part of that work is making retention a deliberate decision against the licensing you hold, rather than whatever the default happens to be. The reporting determination stays yours to make with counsel. We work on the part that decides how early you are able to make it.

Frequently Asked Questions

Under the interagency Computer-Security Incident Notification Rule, a banking organization must notify its primary federal regulator as soon as possible and no later than 36 hours after it determines that a notification incident has occurred. The rule appears at 12 CFR Part 53 for the OCC, with parallel provisions for the Federal Reserve and the FDIC. It took effect on April 1, 2022, with a compliance date of May 1, 2022.

Under 12 CFR 748.1(c), a federally insured credit union must notify the NCUA as soon as possible but no later than 72 hours after it reasonably believes it has experienced a reportable cyber incident, or within 72 hours of being notified by a third party, whichever is sooner. The requirement has been in effect since September 1, 2023. Because the standard is reasonable belief rather than confirmation, the obligation can attach before a forensic investigation concludes.

Under 16 CFR 314.4(j), a covered financial institution that discovers a notification event involving the information of at least 500 consumers must notify the Federal Trade Commission as soon as possible and no later than 30 days after discovery. The requirement took effect on May 13, 2024. The rule treats an event as discovered on the first day it is known to the institution, and knowledge is imputed if the event is known to any employee, officer, or agent other than the person committing the breach.

No. The four hour reference in 12 CFR Part 53 is a threshold on the duration of the service disruption, not a deadline for sending notice. It applies to bank service providers rather than to banking organizations, and it determines whether the provider's notification obligation is triggered at all. When the obligation is triggered, the provider must notify a bank-designated point of contact at each affected banking organization customer as soon as possible.

Microsoft Purview Audit (Standard) retains most audit records for 180 days by default, raised from a previous default of 90 days. Audit (Premium) retains Microsoft Entra ID, Exchange, SharePoint, and OneDrive audit records for one year, and retention can extend to 10 years with the 10-Year Audit Log Retention add-on license. Audit records for non-E5 users and guest users are retained for 180 days. Because retention is tied to licensing, the practical limit on reconstructing an incident timeline is often a licensing decision made years earlier.

Yes. For federally insured credit unions, 12 CFR 748.1(c) starts the 72 hour clock on notification by a third party, whichever is sooner. For banks, a service provider notice can be the information that forces a determination that a notification incident has occurred, which then starts the 36 hours. This is why the bank-designated point of contact named in service agreements should be a monitored destination rather than an individual mailbox.


Justin Kirsch

Justin Kirsch

Co-Founder & CEO, Access Business Technologies

Justin Kirsch has built Microsoft cloud environments for regulated lenders and depositories since 1999. As Co-Founder and CEO of Access Business Technologies, the largest Tier-1 Microsoft Cloud Solution Provider primarily dedicated to financial services, he helps more than 750 banks, credit unions, and mortgage companies configure Microsoft 365 so that an incident is detected, escalated, and evidenced inside the window their regulator actually gives them.