{
  "tool_id": "art-428-cyber-incident-clock",
  "note": "Business-day arithmetic is weekends-only (documented kernel scope limit); no federal/SEC holiday calendar. Vectors below were computed directly from the shipped kernel.",
  "vectors": [
    {
      "name": "default-inputs",
      "policy_parameters": {},
      "output_payload": {
        "incident_id": "",
        "determination_at": null,
        "determination_at_parsed": false,
        "determination_evidence_hash": null,
        "determination_evidence_hash_well_formed": false,
        "evaluated_at": null,
        "determinations": [
          {
            "obligation_id": "banking_regulator_36hr",
            "regulator": "OCC (national banks) / FRB (bank holding companies, state member banks) / FDIC (insured state non-member banks): harmonized interagency rule",
            "statute_citation": "12 CFR pt. 53 (OCC) / 12 CFR pt. 225 (FRB, Regulation Y) / 12 CFR pt. 304 (FDIC) — Interagency Computer-Security Incident Notification Requirements",
            "applicable": false,
            "deadline_iso": null,
            "notification_completed_at": null,
            "completed_late": false,
            "item_state": "not_applicable",
            "exception": null,
            "ha_note": "Not yet an approval record. Once BANK-SPEC-HA-1 (SPEC.md Human Accountability section) lands, a human reviewer/approver MAY create a separate, signed §1 approval record over this artifact's execution_hash + this obligation_id; this kernel does not fabricate or reserve a mutable slot for that record inside its own hashed output.",
            "note": "Calendar-hour deadline (36 hours from determination); the rule carries no business-day exception."
          },
          {
            "obligation_id": "sec_8k_item_1_05",
            "regulator": "U.S. Securities and Exchange Commission",
            "statute_citation": "17 CFR 249.308 (Form 8-K), Item 1.05 (Material Cybersecurity Incidents); \"business day\" per Exchange Act Rule 0-3(a)",
            "applicable": false,
            "deadline_iso": null,
            "notification_completed_at": null,
            "completed_late": false,
            "item_state": "not_applicable",
            "exception": null,
            "ha_note": "Not yet an approval record. Once BANK-SPEC-HA-1 (SPEC.md Human Accountability section) lands, a human reviewer/approver MAY create a separate, signed §1 approval record over this artifact's execution_hash + this obligation_id; this kernel does not fabricate or reserve a mutable slot for that record inside its own hashed output.",
            "note": "Four-business-day deadline; weekends-only business-day arithmetic (see kernel scope-limit note); no SEC-closure holiday calendar is consulted."
          },
          {
            "obligation_id": "nydfs_72hr_500",
            "regulator": "New York State Department of Financial Services",
            "statute_citation": "23 NYCRR 500.17(a): Notice of Cybersecurity Incident",
            "applicable": false,
            "deadline_iso": null,
            "notification_completed_at": null,
            "completed_late": false,
            "item_state": "not_applicable",
            "exception": null,
            "ha_note": "Not yet an approval record. Once BANK-SPEC-HA-1 (SPEC.md Human Accountability section) lands, a human reviewer/approver MAY create a separate, signed §1 approval record over this artifact's execution_hash + this obligation_id; this kernel does not fabricate or reserve a mutable slot for that record inside its own hashed output.",
            "note": "Calendar-hour deadline (72 hours from determination)."
          }
        ],
        "note": "Deterministic notification-deadline clock over a caller-declared incident determination timestamp. Business-day arithmetic (SEC 8-K leg) is weekends-only; no federal/SEC holiday calendar is applied (see kernel header). This tool computes deadlines and attestation slots; it does not itself transmit, file, or submit any regulatory notification, and it is not legal advice."
      },
      "golden_hash": "81d073e5c7a1b55760a2a6dbc4d058d2ab1367416288b3763e21988230e2b90c"
    },
    {
      "name": "bank-all-applicable-pending",
      "policy_parameters": {
        "incident_id": "INC-2026-0428",
        "determination_at": "2026-07-20T10:00:00Z",
        "determination_evidence_hash": "sha256:1111111111111111111111111111111111111111111111111111111111111111",
        "is_bank_holding_company": true,
        "sec_reporting_company": true,
        "sec_rescission_petition_pending": true,
        "nydfs_covered_entity": true,
        "evaluated_at": "2026-07-20T20:00:00Z"
      },
      "output_payload": {
        "incident_id": "INC-2026-0428",
        "determination_at": "2026-07-20T10:00:00.000Z",
        "determination_at_parsed": true,
        "determination_evidence_hash": "sha256:1111111111111111111111111111111111111111111111111111111111111111",
        "determination_evidence_hash_well_formed": true,
        "evaluated_at": "2026-07-20T20:00:00.000Z",
        "determinations": [
          {
            "obligation_id": "banking_regulator_36hr",
            "regulator": "OCC (national banks) / FRB (bank holding companies, state member banks) / FDIC (insured state non-member banks): harmonized interagency rule",
            "statute_citation": "12 CFR pt. 53 (OCC) / 12 CFR pt. 225 (FRB, Regulation Y) / 12 CFR pt. 304 (FDIC) — Interagency Computer-Security Incident Notification Requirements",
            "applicable": true,
            "deadline_iso": "2026-07-21T22:00:00.000Z",
            "notification_completed_at": null,
            "completed_late": false,
            "item_state": "pending_human",
            "exception": null,
            "ha_note": "Not yet an approval record. Once BANK-SPEC-HA-1 (SPEC.md Human Accountability section) lands, a human reviewer/approver MAY create a separate, signed §1 approval record over this artifact's execution_hash + this obligation_id; this kernel does not fabricate or reserve a mutable slot for that record inside its own hashed output.",
            "note": "Calendar-hour deadline (36 hours from determination); the rule carries no business-day exception."
          },
          {
            "obligation_id": "sec_8k_item_1_05",
            "regulator": "U.S. Securities and Exchange Commission",
            "statute_citation": "17 CFR 249.308 (Form 8-K), Item 1.05 (Material Cybersecurity Incidents); \"business day\" per Exchange Act Rule 0-3(a)",
            "applicable": true,
            "deadline_iso": "2026-07-24T10:00:00.000Z",
            "notification_completed_at": null,
            "completed_late": false,
            "item_state": "pending_human",
            "exception": null,
            "ha_note": "Not yet an approval record. Once BANK-SPEC-HA-1 (SPEC.md Human Accountability section) lands, a human reviewer/approver MAY create a separate, signed §1 approval record over this artifact's execution_hash + this obligation_id; this kernel does not fabricate or reserve a mutable slot for that record inside its own hashed output.",
            "note": "A rescission petition against Item 1.05 was pending as of April 2026. That status does NOT suspend the four-business-day filing clock under the rule as currently in force; this note flags the legal-status context without altering the computed deadline."
          },
          {
            "obligation_id": "nydfs_72hr_500",
            "regulator": "New York State Department of Financial Services",
            "statute_citation": "23 NYCRR 500.17(a): Notice of Cybersecurity Incident",
            "applicable": true,
            "deadline_iso": "2026-07-23T10:00:00.000Z",
            "notification_completed_at": null,
            "completed_late": false,
            "item_state": "pending_human",
            "exception": null,
            "ha_note": "Not yet an approval record. Once BANK-SPEC-HA-1 (SPEC.md Human Accountability section) lands, a human reviewer/approver MAY create a separate, signed §1 approval record over this artifact's execution_hash + this obligation_id; this kernel does not fabricate or reserve a mutable slot for that record inside its own hashed output.",
            "note": "Calendar-hour deadline (72 hours from determination)."
          }
        ],
        "note": "Deterministic notification-deadline clock over a caller-declared incident determination timestamp. Business-day arithmetic (SEC 8-K leg) is weekends-only; no federal/SEC holiday calendar is applied (see kernel header). This tool computes deadlines and attestation slots; it does not itself transmit, file, or submit any regulatory notification, and it is not legal advice."
      },
      "golden_hash": "4dbeb84dba17dedebb9bd5d0e5dc135218029e7aa92e63b46ebc8bdc223869c4"
    },
    {
      "name": "missed-and-late",
      "policy_parameters": {
        "determination_at": "2026-07-16T09:00:00Z",
        "is_national_bank": true,
        "sec_reporting_company": true,
        "nydfs_covered_entity": true,
        "banking_notification_completed_at": "2026-07-18T09:00:00Z",
        "evaluated_at": "2026-07-25T00:00:00Z"
      },
      "output_payload": {
        "incident_id": "",
        "determination_at": "2026-07-16T09:00:00.000Z",
        "determination_at_parsed": true,
        "determination_evidence_hash": null,
        "determination_evidence_hash_well_formed": false,
        "evaluated_at": "2026-07-25T00:00:00.000Z",
        "determinations": [
          {
            "obligation_id": "banking_regulator_36hr",
            "regulator": "OCC (national banks) / FRB (bank holding companies, state member banks) / FDIC (insured state non-member banks): harmonized interagency rule",
            "statute_citation": "12 CFR pt. 53 (OCC) / 12 CFR pt. 225 (FRB, Regulation Y) / 12 CFR pt. 304 (FDIC) — Interagency Computer-Security Incident Notification Requirements",
            "applicable": true,
            "deadline_iso": "2026-07-17T21:00:00.000Z",
            "notification_completed_at": "2026-07-18T09:00:00.000Z",
            "completed_late": true,
            "item_state": "done",
            "exception": {
              "exception_class": "business",
              "exception_detail": {
                "type": "business",
                "code": "NOTIFICATION_FILED_AFTER_DEADLINE",
                "message": "banking_regulator_36hr: notification recorded at 2026-07-18T09:00:00.000Z, after the 2026-07-17T21:00:00.000Z deadline."
              },
              "item_state": "done"
            },
            "ha_note": "Not yet an approval record. Once BANK-SPEC-HA-1 (SPEC.md Human Accountability section) lands, a human reviewer/approver MAY create a separate, signed §1 approval record over this artifact's execution_hash + this obligation_id; this kernel does not fabricate or reserve a mutable slot for that record inside its own hashed output.",
            "note": "Calendar-hour deadline (36 hours from determination); the rule carries no business-day exception."
          },
          {
            "obligation_id": "sec_8k_item_1_05",
            "regulator": "U.S. Securities and Exchange Commission",
            "statute_citation": "17 CFR 249.308 (Form 8-K), Item 1.05 (Material Cybersecurity Incidents); \"business day\" per Exchange Act Rule 0-3(a)",
            "applicable": true,
            "deadline_iso": "2026-07-22T09:00:00.000Z",
            "notification_completed_at": null,
            "completed_late": false,
            "item_state": "pending_human",
            "exception": {
              "exception_class": "business",
              "exception_detail": {
                "type": "business",
                "code": "NOTIFICATION_DEADLINE_MISSED",
                "message": "sec_8k_item_1_05: deadline 2026-07-22T09:00:00.000Z has passed as of 2026-07-25T00:00:00.000Z with no recorded notification."
              },
              "item_state": "pending_human"
            },
            "ha_note": "Not yet an approval record. Once BANK-SPEC-HA-1 (SPEC.md Human Accountability section) lands, a human reviewer/approver MAY create a separate, signed §1 approval record over this artifact's execution_hash + this obligation_id; this kernel does not fabricate or reserve a mutable slot for that record inside its own hashed output.",
            "note": "Four-business-day deadline; weekends-only business-day arithmetic (see kernel scope-limit note); no SEC-closure holiday calendar is consulted."
          },
          {
            "obligation_id": "nydfs_72hr_500",
            "regulator": "New York State Department of Financial Services",
            "statute_citation": "23 NYCRR 500.17(a): Notice of Cybersecurity Incident",
            "applicable": true,
            "deadline_iso": "2026-07-19T09:00:00.000Z",
            "notification_completed_at": null,
            "completed_late": false,
            "item_state": "pending_human",
            "exception": {
              "exception_class": "business",
              "exception_detail": {
                "type": "business",
                "code": "NOTIFICATION_DEADLINE_MISSED",
                "message": "nydfs_72hr_500: deadline 2026-07-19T09:00:00.000Z has passed as of 2026-07-25T00:00:00.000Z with no recorded notification."
              },
              "item_state": "pending_human"
            },
            "ha_note": "Not yet an approval record. Once BANK-SPEC-HA-1 (SPEC.md Human Accountability section) lands, a human reviewer/approver MAY create a separate, signed §1 approval record over this artifact's execution_hash + this obligation_id; this kernel does not fabricate or reserve a mutable slot for that record inside its own hashed output.",
            "note": "Calendar-hour deadline (72 hours from determination)."
          }
        ],
        "note": "Deterministic notification-deadline clock over a caller-declared incident determination timestamp. Business-day arithmetic (SEC 8-K leg) is weekends-only; no federal/SEC holiday calendar is applied (see kernel header). This tool computes deadlines and attestation slots; it does not itself transmit, file, or submit any regulatory notification, and it is not legal advice."
      },
      "golden_hash": "071bf031cb640e8ebdebc562712684288956b42b80d59f09dfb82642e7a411c7"
    },
    {
      "name": "not-applicable",
      "policy_parameters": {
        "determination_at": "2026-07-20T10:00:00Z"
      },
      "output_payload": {
        "incident_id": "",
        "determination_at": "2026-07-20T10:00:00.000Z",
        "determination_at_parsed": true,
        "determination_evidence_hash": null,
        "determination_evidence_hash_well_formed": false,
        "evaluated_at": null,
        "determinations": [
          {
            "obligation_id": "banking_regulator_36hr",
            "regulator": "OCC (national banks) / FRB (bank holding companies, state member banks) / FDIC (insured state non-member banks): harmonized interagency rule",
            "statute_citation": "12 CFR pt. 53 (OCC) / 12 CFR pt. 225 (FRB, Regulation Y) / 12 CFR pt. 304 (FDIC) — Interagency Computer-Security Incident Notification Requirements",
            "applicable": false,
            "deadline_iso": null,
            "notification_completed_at": null,
            "completed_late": false,
            "item_state": "not_applicable",
            "exception": null,
            "ha_note": "Not yet an approval record. Once BANK-SPEC-HA-1 (SPEC.md Human Accountability section) lands, a human reviewer/approver MAY create a separate, signed §1 approval record over this artifact's execution_hash + this obligation_id; this kernel does not fabricate or reserve a mutable slot for that record inside its own hashed output.",
            "note": "Calendar-hour deadline (36 hours from determination); the rule carries no business-day exception."
          },
          {
            "obligation_id": "sec_8k_item_1_05",
            "regulator": "U.S. Securities and Exchange Commission",
            "statute_citation": "17 CFR 249.308 (Form 8-K), Item 1.05 (Material Cybersecurity Incidents); \"business day\" per Exchange Act Rule 0-3(a)",
            "applicable": false,
            "deadline_iso": null,
            "notification_completed_at": null,
            "completed_late": false,
            "item_state": "not_applicable",
            "exception": null,
            "ha_note": "Not yet an approval record. Once BANK-SPEC-HA-1 (SPEC.md Human Accountability section) lands, a human reviewer/approver MAY create a separate, signed §1 approval record over this artifact's execution_hash + this obligation_id; this kernel does not fabricate or reserve a mutable slot for that record inside its own hashed output.",
            "note": "Four-business-day deadline; weekends-only business-day arithmetic (see kernel scope-limit note); no SEC-closure holiday calendar is consulted."
          },
          {
            "obligation_id": "nydfs_72hr_500",
            "regulator": "New York State Department of Financial Services",
            "statute_citation": "23 NYCRR 500.17(a): Notice of Cybersecurity Incident",
            "applicable": false,
            "deadline_iso": null,
            "notification_completed_at": null,
            "completed_late": false,
            "item_state": "not_applicable",
            "exception": null,
            "ha_note": "Not yet an approval record. Once BANK-SPEC-HA-1 (SPEC.md Human Accountability section) lands, a human reviewer/approver MAY create a separate, signed §1 approval record over this artifact's execution_hash + this obligation_id; this kernel does not fabricate or reserve a mutable slot for that record inside its own hashed output.",
            "note": "Calendar-hour deadline (72 hours from determination)."
          }
        ],
        "note": "Deterministic notification-deadline clock over a caller-declared incident determination timestamp. Business-day arithmetic (SEC 8-K leg) is weekends-only; no federal/SEC holiday calendar is applied (see kernel header). This tool computes deadlines and attestation slots; it does not itself transmit, file, or submit any regulatory notification, and it is not legal advice."
      },
      "golden_hash": "0386c5c3382040c4b126fdddfc0c06d81d34a8d96d0480184474187b949449c1"
    }
  ]
}
