TOOL · INCIDENT REPORTING

Reporting clock

Both the CRA and the Swedish Cybersecurity Act run their reporting deadlines from the moment you become aware, not from when you finish investigating. Put that moment in and get the actual dates, in your own timezone, in a form you can paste into a ticket.

Awareness usually starts when the report reaches your organisation, not when it reaches someone who understands it. If a customer emailed support on Friday evening, that is probably your start time.
Only the final report depends on this. Leave it blank until you have one.
Nothing you type here leaves your browser. There is no form submission, no analytics and no network request. Reload the page and it is gone.

What this does not tell you

It calculates dates. It does not decide whether you have a reportable event, and that is the harder question. Under the CRA the trigger is an actively exploited vulnerability, meaning reliable evidence of real-world exploitation rather than a proof of concept or a high severity score, or a severe incident affecting the security of the product. Under the Cybersecurity Act it is a significant incident, judged on operational disruption and impact.

It also does not tell you where to file. For the CRA that is the coordinator CSIRT for your member state plus ENISA, through the Single Reporting Platform. For NIS2 in Sweden it is your sector supervisory authority, with registrations handled by NCSC since 1 July 2026.

Work out your reporting route before you need it. Platform access and the authorisation check that goes with it are not things to be discovering while a 24-hour clock is running.
This is a working aid, not a legal determination. If the useful question is whether you have a reportable event at all, or which regime you sit under, that is the kind of work I do.