Two preconditions come before the liability tiers, and almost nobody writes about them. 12 CFR 1005.6(a) provides that a consumer may be held liable for an unauthorized electronic fund transfer "only if the financial institution has provided the disclosures required by § 1005.7(b)(1), (2), and (3)", which are the initial disclosures of the consumer's liability, the telephone number and address for reporting, and the institution's business days. It adds that where the transfer involved an access device, "it must be an accepted access device and the financial institution must have provided a means to identify the consumer to whom it was issued."
Read that as written and the order of operations is clear. The tiers below are ceilings on a liability that exists only if both conditions are met. A card that was never accepted, or an institution that never gave the required disclosures, does not produce a $50 question or a $500 question.
The three tiers, in the regulation's own terms. Under 12 CFR 1005.6(b)(1), where the consumer notifies the institution within two business days after learning of the loss or theft of the access device, liability may not exceed the lesser of $50 or the amount of unauthorized transfers occurring before notice. Under (b)(2), where the consumer does not notify within those two business days, liability may not exceed the lesser of $500 or the sum of two components: $50 or the amount of unauthorized transfers occurring within the two business days, whichever is less, plus the amount of transfers occurring after the close of those two business days and before notice, which the institution establishes would not have occurred had it been notified in time. Under (b)(3), a consumer must report an unauthorized transfer appearing on a periodic statement within 60 days of the institution's transmittal of that statement to avoid liability for subsequent transfers, and failing that, liability is limited to the transfers occurring after the 60 days close.
The 60-day rule is the one most often described backwards, and the error runs in the direction that makes people give up. It does not say that reporting late costs you everything. It limits liability to transfers occurring after the window closes. What (b)(3)'s final sentence does add, and what a reassuring summary tends to drop, is that where an access device is involved the consumer may still be liable for the (b)(1) or (b)(2) amounts as applicable. So a late-reporting debit card holder is not automatically at zero, and is also not automatically ruined.
The extension nobody invokes. 12 CFR 1005.6(b)(4) provides that if the consumer's delay in notifying was due to extenuating circumstances, "the institution shall extend the times specified above to a reasonable period." That is written as a duty on the institution rather than as a favor, and a hospital stay, a deployment, or an extended absence is the situation it exists for. It is worth naming explicitly when reporting late.
How notice counts, which decides more cases than the tiers do. Under 1005.6(b)(5) notice is given when the consumer takes steps reasonably necessary to provide the institution with the pertinent information, "whether or not a particular employee or agent of the institution actually receives" it, and it may be given in person, by telephone, or in writing. Written notice counts from the time it is mailed or delivered for transmission. Because the tiers all measure from the moment of notice, establishing when notice happened is worth as much as knowing what the caps are, and a phone call followed by a dated written confirmation does that.
Zero-liability policies are real and are not this. Card networks and many issuers advertise broader protection than the regulation requires. Those promises are voluntary policy, subject to the conditions the issuer sets, and can be changed. They sit on top of the regulation rather than replacing it, which is why the regulation is what to reason from when something goes wrong.