GRC Oversight

Live demoFictional sample data. Nothing is saved.

Sign up

18Compliance

Obligations

Jurisdictional legal and regulatory obligations, tracked separately from framework controls — e.g. breach notification deadlines, registration renewals, and disclosure requirements.

Obligations (4)

  • NIS2 incident reporting (24h early warning)

    EUMET

    Significant incidents must be reported to the competent authority within 24 hours of awareness.

    Related control: CC7.4 — Incident response tested

  • CCPA data broker registration renewal

    CaliforniaOPENDue 2027-01-31

    Annual registration renewal with the California Privacy Protection Agency.

  • UK GDPR representative appointment review

    UKIN_PROGRESSDue 2026-08-15

    Annual review of the appointed Article 27 UK representative.

  • SEC cybersecurity incident disclosure (8-K)

    US (Federal)OVERDUEDue 2026-06-01

    Material cybersecurity incidents must be disclosed within 4 business days of determination.

    Related control: CC7.4 — Incident response tested