{
  "tool_id": "art-428-cyber-incident-clock",
  "tool_version": "1.0.0",
  "display_name": "Cyber Incident Notification Clock",
  "mcp_name": "compute_cyber_incident_notification_clock",
  "mandate_type": "attestation_mandate",
  "wave": 70,
  "gpu": false,
  "url": "https://ainumbers.co/chaingraph/art-428-cyber-incident-clock.html",
  "description": "Starts three parallel regulatory notification-deadline clocks from one hash-anchored cyber-incident determination timestamp: the 36-hour interagency banking-regulator rule (12 CFR 53/225/304), the 4-business-day SEC Form 8-K Item 1.05 notification (weekends-only business-day arithmetic; no federal holiday calendar is applied, a documented scope limit), and the 72-hour NYDFS 23 NYCRR 500.17(a) notice. Each obligation carries its own decision-tree attestation slot (applicable, deadline, completion state, a §22.11-shaped optional exception for an at-risk or missed deadline) and a stable obligation_id ready to be cited by a future Human-Accountability (BANK-SPEC-HA-1) approval record, without embedding a mutable reference inside its own hashed output. A pending SEC Item 1.05 rescission petition (flagged Apr 2026) is carried as an annotation only; it does not alter the computed deadline. Complementary to tools/incident-response-runbook-builder.html. This tool computes deadlines and attestation slots only; it does not itself transmit, file, or submit any regulatory notification, and it is not legal advice.",
  "input_schema_ref": "chaingraph/art-428-cyber-incident-clock.html#manifest",
  "consumes": [],
  "feeds": [],
  "status": "live",
  "conformance_fixtures": true,
  "compute_capability": "server",
  "compute_images": [{"system":"sha256-source","image_id":"sha256:6bbd5af5d5a8f8a001a6b5e62fde257a5a22943d218e038ce6c4ae78bb142c8e","valid_from":"2026-07-10"},{"system":"risc0","image_id":"sha256:a1a0bc89b5b1febaeda3519f6dbade0fa5ac16beeb143c4e1b01689573567bc6","valid_from":"2026-07-23"}],
  "compute_proof_ready": "ready",
  "export_capability": [
    "json"
  ],
  "compute_proof": {
    "type": "ZkVmReceipt",
    "system": "risc0",
    "receiptFormat": "groth16-bn254",
    "imageId": "sha256:a1a0bc89b5b1febaeda3519f6dbade0fa5ac16beeb143c4e1b01689573567bc6",
    "seal": "CMYCH33Wu2HK866jygv1bdg+VMS9Y6WIcAsmC3xHkyoUkLuNAkFXM2FF3MHK7paAgkokkVvwftTgB4aPBVlJjyFoOCDzPfWW5tqvUMJFaixn2NV0ptzpLMaPSCvgoF4ZDvaK6jx7j8oo5V5K+FuZbIRlnISUIS5EfbqUryA6wyQQOKtq/mbSQfAqTO2W6QWjVR1GB4G3UfyJx0gd9+1+rA+L581JFPPOiRvpFSE5trtn+KSzfKbBU4ppl92LqK2KGW5rF0CYU2ar+qSE6ib2vSXsE+CPcLHxwMk+mztsQp8ac9wcQkzAf3vK+cg3mYmuofo0IPGzLQOifaWySd/pSQ==",
    "journal": {
      "chaingraph_version": "0.4.0",
      "kernel_digest": "sha256:d4f785fe961f2b21635d4c79e97fc6843c9db6d688d81be0b6a7223d1f63ac95",
      "output": {
        "determination_at": null,
        "determination_at_parsed": false,
        "determination_evidence_hash": null,
        "determination_evidence_hash_well_formed": false,
        "determinations": [
          {
            "applicable": false,
            "completed_late": false,
            "deadline_iso": null,
            "exception": null,
            "ha_note": "Not yet an approval record. Once BANK-SPEC-HA-1 (SPEC.md Human Accountability section) lands, a human reviewer/approver MAY create a separate, signed §1 approval record over this artifact's execution_hash + this obligation_id; this kernel does not fabricate or reserve a mutable slot for that record inside its own hashed output.",
            "item_state": "not_applicable",
            "note": "Calendar-hour deadline (36 hours from determination); the rule carries no business-day exception.",
            "notification_completed_at": null,
            "obligation_id": "banking_regulator_36hr",
            "regulator": "OCC (national banks) / FRB (bank holding companies, state member banks) / FDIC (insured state non-member banks): harmonized interagency rule",
            "statute_citation": "12 CFR pt. 53 (OCC) / 12 CFR pt. 225 (FRB, Regulation Y) / 12 CFR pt. 304 (FDIC) — Interagency Computer-Security Incident Notification Requirements"
          },
          {
            "applicable": false,
            "completed_late": false,
            "deadline_iso": null,
            "exception": null,
            "ha_note": "Not yet an approval record. Once BANK-SPEC-HA-1 (SPEC.md Human Accountability section) lands, a human reviewer/approver MAY create a separate, signed §1 approval record over this artifact's execution_hash + this obligation_id; this kernel does not fabricate or reserve a mutable slot for that record inside its own hashed output.",
            "item_state": "not_applicable",
            "note": "Four-business-day deadline; weekends-only business-day arithmetic (see kernel scope-limit note); no SEC-closure holiday calendar is consulted.",
            "notification_completed_at": null,
            "obligation_id": "sec_8k_item_1_05",
            "regulator": "U.S. Securities and Exchange Commission",
            "statute_citation": "17 CFR 249.308 (Form 8-K), Item 1.05 (Material Cybersecurity Incidents); \"business day\" per Exchange Act Rule 0-3(a)"
          },
          {
            "applicable": false,
            "completed_late": false,
            "deadline_iso": null,
            "exception": null,
            "ha_note": "Not yet an approval record. Once BANK-SPEC-HA-1 (SPEC.md Human Accountability section) lands, a human reviewer/approver MAY create a separate, signed §1 approval record over this artifact's execution_hash + this obligation_id; this kernel does not fabricate or reserve a mutable slot for that record inside its own hashed output.",
            "item_state": "not_applicable",
            "note": "Calendar-hour deadline (72 hours from determination).",
            "notification_completed_at": null,
            "obligation_id": "nydfs_72hr_500",
            "regulator": "New York State Department of Financial Services",
            "statute_citation": "23 NYCRR 500.17(a): Notice of Cybersecurity Incident"
          }
        ],
        "evaluated_at": null,
        "incident_id": "",
        "note": "Deterministic notification-deadline clock over a caller-declared incident determination timestamp. Business-day arithmetic (SEC 8-K leg) is weekends-only; no federal/SEC holiday calendar is applied (see kernel header). This tool computes deadlines and attestation slots; it does not itself transmit, file, or submit any regulatory notification, and it is not legal advice."
      }
    }
  }
}
