CIRCIA Cyber Incident Reporting Rule (CISA)

Implements the Cyber Incident Reporting for Critical Infrastructure Act of 2022: covered entities in the 16 critical infrastructure sectors report substantial cyber incidents within 72 hours and ransom payments within 24 hours. Final rule expected from CISA in September 2026.

JurisdictionUnited States
CategoryCybersecurity
StatusProposed
Latest development

Analysis

CIRCIA establishes mandatory cyber incident and ransomware payment reporting to CISA for covered entities in critical infrastructure sectors, but as of now the requirements are still proposed, not yet effective, pending issuance of the Final Rule in 2026.CISA CIRCIA OverviewCISA CIRCIA Fact Sheet (PDF)CIRCIA NPRM Federal Register (89 FR 23644)CIRCIA FAQs


Key Requirements (based on statute + NPRM – not yet final)

Important: Until CISA issues the Final Rule and it becomes effective, these are proposed regulatory requirements implementing binding statutory obligations under CIRCIA.CIRCIA FAQsCISA CIRCIA Fact Sheet

  • Mandatory reporting of covered cyber incidents within 72 hours
  • Mandatory reporting of ransomware payments within 24 hours
  • Scope: covered entities in the 16 critical infrastructure sectors
  • Content and format of incident reports
  • Legal protections and use of reported information
  • No current obligations under the NPRM until Final Rule effective

Compliance Challenges

Because the Final Rule is not yet published, organizations are preparing against a backdrop of evolving requirements, leading to several recurrent challenges documented by public commentary and analyses.

  • Uncertainty about scope and definitions
  • Operational challenges meeting 72‑/24‑hour timelines
  • Alignment with existing reporting regimes
  • Resourcing, governance, and data quality

Implementation Best Practices (pre‑Final Rule preparation)

Even though the Final Rule is not yet effective, organizations can adopt best practices aligned with CIRCIA’s proposed requirements and broader federal guidance.

  • Establish an incident reporting playbook aligned with CIRCIA
  • Implement centralized logging, monitoring, and incident classification
  • Ransomware payment governance and decision frameworks
  • Training and exercises
  • Tools and resources
  • Leverage CISA incident reporting portals and tools (including reporting forms and contact channels) and general cyber tools maintained by CISA. CISA “Report an Incident” page [CISA Cybersecurity Tools catalog](https://www.cisa.gov/resources-tools/cy

Recent developments

  • — This industry update says the rule remains unfinished after years of debate, leaving critical infrastructure operators to prepare for the reporting regime. It emphasizes the operational burden of building processes for rapid incident and ransom-payment reporting. (source)
  • — Inside Cybersecurity reported that CISA gained additional time to finalize the mandatory incident-reporting rule after stakeholder feedback. The item indicates the schedule slipped again, showing continued rulemaking uncertainty. (source)
  • — Industry-facing commentary describes organizations preparing for eventual compliance with CIRCIA’s 72-hour incident reporting and 24-hour ransomware payment deadlines. The broader impact is increased readiness planning by critical infrastructure operators ahead of finalization. (source)
  • — CISA is expected to finalize the CIRCIA rule in September 2026, with reporting requirements still described as 72 hours for covered cyber incidents and 24 hours for ransomware payments. The article frames the move as the latest target after prior delays and notes that the rule would affect critical infrastructure organizations. (source)
  • — CISA’s CIRCIA page reiterates the statutory framework: covered entities must report covered cyber incidents no later than 72 hours after reasonably believing an incident occurred. This remains the core policy baseline even as the final implementing rule is still pending. (source)
  • — This update says CISA has again slipped the final-rule timeline, moving from a May 2026 target to September 2026 in the Unified Agenda. It frames the delay as another missed deadline for the long-awaited CIRCIA implementing rule. (source)
  • — The article notes that the final rule remains unresolved more than two years after the proposed rule and that companies are still preparing for mandatory reporting obligations. Industry impact centers on compliance uncertainty and continuing monitoring of CISA’s timeline. (source)
  • — This legal update says CISA had targeted May 2026 but that funding disruptions could further alter the timeline. It also highlights the proposed requirements that covered entities report incidents within 72 hours and ransomware payments within 24 hours. (source)
  • — Reporting from early July says CISA was expected to finalize the CIRCIA rule in the fall of 2026. It reiterates the core obligations for 16 critical infrastructure sectors and highlights the 72-hour and 24-hour reporting windows. (source)
  • — Nextgov reported that CISA expected to finalize the rule in September 2026, based on a regulatory document published the prior week. The piece underscores that the rule would require critical infrastructure providers to report major cyber incidents directly to CISA. (source)

Related regulations

Put it into practice

Browse all regulations · Compliance deadlines · Latest updates