Operating in Production: On-Call, Incident Command, and Reporting Clocks Module 4 · Reporting Clocks and Communications

Which Clocks Reach Meridian

Last reviewed · content updated

Advanced

What you'll learn

~22 min
  • Distinguish the covered agency's own reporting clocks, which Meridian's notification only feeds, from Meridian's own sector and contract obligations
  • State each obligation reaching Meridian with its number, its trigger word, and the reason two of them can diverge on the same event
  • Identify the one proposed critical-infrastructure rule that is not yet in force and say why it renders no deadline
ℹLeadership brief

What it is: a map of exactly three paths by which a reporting clock can reach Meridian — a contract flow-down clause (an obligation the prime passes down, so it reaches a company that never signed with the government), direct sector regulation, and a vendor’s own federal authorization — since Meridian answers to none of these bodies as an agency would.

What it buys: a reporting-obligation profile counsel can maintain and the clock desk can consult in the first ten minutes of an incident, instead of a debate about who Meridian owes a report to.

What to fund: a standing, counsel-reviewed profile of which regimes currently apply, updated when a contract changes — not re-derived at 3am by whoever is on call.

Before the detail — Artifact: the profile itself, accepted only when counsel has approved every row’s applicability, source, trigger, owner, and review date, and cited by the record’s determination entries. Status of what follows: binding where a clause is in the contract or a sector standard applies; one row is proposed and not yet binding at all.

Prompt first: draft the profile, not the applicability argument

Here is our counsel-approved reporting-obligation profile [paste:
regime, applicability, governing source, trigger owner, and filing
owner for each row] and the cited source excerpts [paste].
Do not add or remove a regime, decide whether a clause is present, or
change applicability. For each applicable row, complete only:
- number and unit
- exact trigger family: determination | discovery | materiality |
evaluation | awareness | payment | identification | other
- the authority's exact trigger phrase
- source locator
- owners copied from the approved profile
Mark an absent field MISSING. If applicability is absent or ambiguous,
write NEEDS-COUNSEL-REVIEW and compute no deadline.

The assistant checks completeness, not applicability. Federal Delivery 4.4 (a separate training in this series) owns clause discovery — whether a contract carries the 72-hour clause at all; this lesson adds only the number, trigger word, and divergence.

Meridian is not an agency

The numbered M-25-04 clocks 4.1 quoted belong to the covered agency, not Meridian; 4.1 also introduced contractor, utility, privacy, securities, and cloud-provider obligations. Meridian is a contractor and a utility, not an agency, and no statute addressed to agencies binds it directly. Clocks reach Meridian only three ways: a clause a contract puts there, a sector regulator governing Meridian’s own operations regardless of any federal relationship, and a vendor whose own federal authorization carries its own duties. Two swimlanes follow from that split, and confusing them is the error this lesson exists to prevent.

Swimlane one: the covered agency’s clocks, fed by Meridian’s notification

Meridian’s state-federal interconnect contract connects it to a federal energy-coordination system serving a military installation. The covered agency — not Meridian — must notify CISA and OMB within one hour of its major-incident determination (fisma-major-cisa-1h), report to the named Congressional committees and Inspector General within seven days of that same determination (fisma-major-congress), and escalate an uncharacterized event after 72 hours from investigation opening (fisma-uncharacterized-72h).

Meridian does not own those agency-side trigger events. Under the M-17-12 flow-down clause (M-17-12 — the federal government’s 2017 policy on agency breach response, still in force) carried by this contract, Meridian must report a suspected or confirmed breach “as soon as possible and without unreasonable delay,” construct a timeline of user activity, identify the initial attack vector, and permit forensic inspection. That duty has no number of its own — “as soon as possible” is not 72 hours or seven days.

Your unnumbered obligation is timed by someone else’s numbered one: the agency’s one-hour clock to its own regulator starts running the moment the agency determines the incident is major, whether or not Meridian’s notification has arrived yet. Never write that Meridian reports to Congress — it does not. Meridian’s notification is the fact the agency needs in order to make the determination that starts its own clock, and a slow flow-down notice becomes contract risk the day the agency’s own audit asks when Meridian actually told it.

Swimlane two: Meridian’s own clocks

Independent of any agency relationship, Meridian’s own operations carry direct sector-regulatory and contract clocks:

  • Discovery, only if the clause is present. DFARS 252.204-7012 (the Defense Department’s contract clause) requires a report within 72 hours of discovering a cyber incident — but only on the contracts that carry the clause. No clause, no clock; this is not a duty attached to being a defense contractor in general.
  • Determination, for High and Medium impact systems. The R4 clocks verified in CIP-008-6 — and unchanged in CIP-008-7 — are one hour after determining a Reportable Cyber Security Incident, end of the next calendar day after determining an attempt to compromise, and, if new or changed R4.1 attribute information is determined, an update within seven calendar days of that new determination. This lesson does not claim which version is currently enforceable. Low-impact systems follow CIP-003 Attachment 1 §4: E-ISAC only, with no hour clock in the standard.
  • The event itself, not anyone noticing it. DOE Form OE-417 (the Department of Energy’s electric-emergency incident report) sets a one-hour clock for its most severe criteria and a six-hour clock for others — including the loss of service to more than 50,000 customers for an hour or more — both timed from when the incident occurred, not from when it was detected. A single OE-417 filing also covers NERC’s own submittal requirement: one form, two regulators.
  • Identification, for a California utility. The California Public Utilities Commission’s General Order 166 gives a California electric utility four hours from identifying a major outage to reach customers, essential customers, state and local agencies, and the media — and it requires saying explicitly when no restoration estimate is known yet, rather than going silent.

These regimes expose several windows. A row becomes Meridian’s binding obligation only when its clause, system impact, event criterion, and jurisdiction are confirmed applicable — missing a confirmed one is a direct compliance finding against Meridian itself, not a shared one it can point past.

Through the vendor, and the one pending row

Meridian’s vendor, Castellan Analytics (fictional, pursuing federal cloud authorization), may already have a live RFC-0031 duty, and the scenario does not say which — the date follows the certification path, not the fact of pursuing one: FedRAMP’s RFC-0031 (the federal cloud-authorization program’s incident-communications rules) took effect 2026-07-04 and is mandatory from that date for a provider seeking a 20x certification, and from 2027-01-01 for one obtaining or maintaining a Rev5 certification or a pilot 20x. Pursuing authorization is not an exemption — that was the reading to check. Its PAIN × Class matrix starts when federal-reportability evaluation completes — a distinct trigger instant, neither detection, discovery, nor determination: Class D/N5 is 15 minutes, while the calculator’s Class C/N5 row is one hour, both as published. Availability-only incidents follow the public-status-page path in the next lesson.

One row in the calculator’s table is not a clock at all yet. CIRCIA — the Cyber Incident Reporting for Critical Infrastructure Act — has a 2024-04-04 proposed rule that, as of 2026-08-28, is still the only text that exists; no final rule has been issued. The department responsible published town-hall notices on 2026-02-13 and 2026-05-26 seeking further input on the proposal’s scope, and nothing further. Under the proposal, once effective, the 72-hour window would run from reasonable belief that a covered cyber incident occurred, while the 24-hour window would run from making a ransom payment — but “once effective” is doing all the work in that sentence. The calculator renders this row NOT IN EFFECT with no deadline, because an instrument that binds nobody yet cannot be late. This is the one place in the training checked automatically for the word CIRCIA, so a freshness pass that finds a final rule has exactly one edit site.

Two contrast rows apply only if the maintained profile says they do, never automatically: HIPAA (the health-privacy law) requires notice without unreasonable delay and no later than 60 calendar days after discovery, while the Securities and Exchange Commission’s Item 1.05 — as published here from secondary evidence — uses four business days from the materiality determination, not from anything about the system itself.

Reaching two regulators on the same day with two different numbers is not a mistake if the two numbers ran from two different instants; the profile’s job is to make sure nobody discovers that fact under pressure.

The commercial starting practice is one incident channel and, outside data-breach law, no reporting duty at all. The federal delta, for a contractor like Meridian, is three separate origins, not one clock: a covered agency’s numbered clocks fed by Meridian’s unnumbered flow-down notice, Meridian’s own sector-regulatory clocks running independent of any agency, and a vendor’s federal-authorization clock running on the vendor’s own status. The handoff artifact is the profile itself, maintained by counsel and cited in the record. What is not equivalent: “notify the agency contact as soon as possible” and “report to a federal cybersecurity coordinator within one hour” are two acts triggered by two facts, and meeting one does not excuse the other.

Stop and escalate when a new contract, a new sector classification, or a new vendor certification changes which row in the profile applies — the clock desk updates the profile with counsel before the next incident, not during it, because arguing applicability while a clock is running is how a compliant, on-time notification becomes a late one.

KNOWLEDGE CHECK

Meridian sends its M-17-12 flow-down notification to the covered agency's contact 40 minutes after discovering an incident. Two hours later, the agency determines the incident is major. Has Meridian met the agency's one-hour clock to its federal cybersecurity coordinator?

Practice status — among contractors and utilities operating under a federal interconnect, commercial and federal

PracticeStatusAlso called
single commercial incident channelcommon baselinecentral incident room
counsel-maintained reporting-obligation profilecommon baselineregulatory-applicability matrix
contract flow-down clause tracked and actionedrequired where the clause is in the contract; common baseline as a standing practicesubcontractor flow-down register
direct sector-regulator reporting (grid reliability, energy emergency, state utility commission)required for in-scope utilitiesreliability-standard incident filing
vendor federal-authorization incident pass-throughemerging (the governing rule is still proposed)cloud-provider incident-notification clause
dated watch-row for a proposed but not-yet-final regimeemergingregulatory horizon-scanning line item

Scale: required | common baseline | strong optional | reference-shop (seen only at organizations that publish their own practice) | emerging

Key takeaway

Meridian is not an agency, so no agency reporting statute binds it directly: clocks reach Meridian only through a contract’s flow-down clause, through direct sector regulation of its own operations, or through a vendor’s federal authorization — and a proposed critical-infrastructure rule with no final text yet is not a fourth path at all. The next lesson turns from which clock applies to what happens after it starts: how an update promises the next one.

LEADERSHIP DECISION fund a counsel-reviewed reporting-obligation
profile as a standing artifact, not a one-time
memo revisited only after an incident
PRACTITIONER ACTION route every event through the profile before
drafting any notice; never assume Meridian
owes a report an agency owes instead
SUCCESS MEASURE every notification traced to a named regime,
trigger word, and owner in the profile - zero
"we thought we had to report that" findings
Search lessons