CIRCIA Cyber Incident Reporting Rule (CISA)
Implements the Cyber Incident Reporting for Critical Infrastructure Act of 2022: covered entities in the 16 critical infrastructure sectors report substantial cyber incidents within 72 hours and ransom payments within 24 hours. Final rule expected from CISA in September 2026.
| Jurisdiction | United States |
|---|---|
| Category | Cybersecurity |
| Status | Proposed |
| Latest development |
Analysis
CIRCIA establishes mandatory cyber incident and ransomware payment reporting to CISA for covered entities in critical infrastructure sectors, but as of now the requirements are still proposed, not yet effective, pending issuance of the Final Rule in 2026.CISA CIRCIA OverviewCISA CIRCIA Fact Sheet (PDF)CIRCIA NPRM Federal Register (89 FR 23644)CIRCIA FAQs
Key Requirements (based on statute + NPRM – not yet final)
Important: Until CISA issues the Final Rule and it becomes effective, these are proposed regulatory requirements implementing binding statutory obligations under CIRCIA.CIRCIA FAQsCISA CIRCIA Fact Sheet
- Mandatory reporting of covered cyber incidents within 72 hours
- CIRCIA requires CISA to issue regulations under which covered entities must report any covered cyber incident to CISA no later than 72 hours after the time the entity reasonably believes the incident occurred. CISA CIRCIA Fact Sheet CISA CIRCIA Overview page Congressional Research Service CIRCIA NPRM In Brief (PDF)
- The NPRM proposes that “covered cyber incidents” include substantial incidents impacting the confidentiality, integrity, or availability of information systems or services, with criteria tailored to critical infrastructure sectors. CIRCIA NPRM Overview (CISA PDF)_508c%20(locked).pdf) Covered Cyber Incident Fact Sheet Federal Register NPRM text (89 FR 23644)
- Mandatory reporting of ransomware payments within 24 hours
- Under CIRCIA and the NPRM, covered entities must report to CISA any ransomware payment within 24 hours of making the payment (or having a third party pay on their behalf). Congressional Research Service CIRCIA NPRM In Brief (PDF) NextGov article summarizing CISA rule expectations CISA CIRCIA Overview page
- Scope: covered entities in the 16 critical infrastructure sectors
- CIRCIA applies to “covered entities” operating in one or more of the 16 critical infrastructure sectors identified in Presidential Policy Directive 21 (PPD‑21). CISA Covered Entity Fact Sheet CISA CIRCIA Overview page PPD‑21 (White House / DHS)
- The NPRM proposes sector‑based and size/impact criteria in 6 CFR § 226.2 to determine whether an entity is covered (for example, certain thresholds for energy, communications, financial services, healthcare, etc.). CISA Covered Entity Fact Sheet CIRCIA NPRM Federal Register text RegInfo.gov Rule Summary (RIN 1670‑AA04)
- Content and format of incident reports
- The NPRM and CISA fact sheets describe proposed requirements that reports include technical incident details (e.g., indicators of compromise), affected systems and services, operational impact, mitigation steps, and contact information, submitted through CISA’s designated reporting channels. CIRCIA NPRM Overview (CISA PDF)_508c%20(locked).pdf) Covered Cyber Incident Fact Sheet Federal Register NPRM text
- Legal protections and use of reported information
- CIRCIA provides liability protections, privilege, and limitations on use/disclosure of reports, including restrictions on FOIA disclosure and use in regulatory actions, to encourage reporting. CISA CIRCIA Fact Sheet CISA CIRCIA Overview page Public Law 117‑103, Division Y (CIRCIA text via govinfo)
- No current obligations under the NPRM until Final Rule effective
- CISA explicitly states that CIRCIA’s regulatory requirements – including reporting obligations – are not effective until the Final Rule goes into effect; the Final Rule will identify its effective date. CIRCIA FAQs CISA CIRCIA Fact Sheet RegInfo.gov timetable (Final Rule scheduled 05/2026)
Compliance Challenges
Because the Final Rule is not yet published, organizations are preparing against a backdrop of evolving requirements, leading to several recurrent challenges documented by public commentary and analyses.
- Uncertainty about scope and definitions
- Organizations report difficulty determining whether they will be “covered entities” and what constitutes a “covered cyber incident” under the proposed criteria. CISA Covered Entity Fact Sheet Covered Cyber Incident Fact Sheet CIRCIA NPRM Overview_508c%20(locked).pdf)
- The Congressional Research Service notes that critical infrastructure companies will need to interpret “substantial cyber incident” and map it to internal detection thresholds, which can be complex in large, segmented environments. CRS CIRCIA NPRM In Brief (PDF) Federal Register NPRM text RegInfo.gov Rule Summary
- Operational challenges meeting 72‑/24‑hour timelines
- Industry commentary highlights the difficulty of triaging, investigating, and validating complex cyber incidents within 72 hours, and gathering sufficient detail for a high‑quality report. NextGov article on CIRCIA rule CRS CIRCIA NPRM analysis CISA CIRCIA Fact Sheet
- The 24‑hour ransomware payment reporting window may be particularly challenging where payment decisions are made under time pressure and involve external negotiators or insurers. CRS CIRCIA NPRM In Brief Federal Register NPRM text CISA CIRCIA Overview page
- Alignment with existing reporting regimes
- Many covered entities (e.g., financial institutions, pipelines, healthcare providers) already have mandatory incident reporting obligations to sector‑specific regulators, creating concerns about duplicative or conflicting requirements. CRS CIRCIA NPRM In Brief CISA CIRCIA Overview page CIRCIA NPRM Overview_508c%20(locked).pdf)
- Public comments referenced in Federal Register notices highlight concerns about harmonization with SEC, state, and sectoral reporting, and the risk of report fatigue. Federal Register NPRM Correction / Comment Extension (89 FR 47471 & 89 FR 37141) RegInfo.gov agenda entry CIRCIA FAQs
- Resourcing, governance, and data quality
- Analyses emphasize that smaller operators in critical infrastructure may struggle to implement 24/7 monitoring, centralized incident management, and reporting governance capable of meeting statutory timelines. CRS CIRCIA NPRM In Brief NextGov article on CIRCIA CISA CIRCIA Fact Sheet
Implementation Best Practices (pre‑Final Rule preparation)
Even though the Final Rule is not yet effective, organizations can adopt best practices aligned with CIRCIA’s proposed requirements and broader federal guidance.
- Establish an incident reporting playbook aligned with CIRCIA
- Develop a CIRCIA‑specific incident response runbook that maps internal severity levels to the NPRM’s “covered cyber incident” criteria and defines steps to prepare a report within the 72‑hour window. Covered Cyber Incident Fact Sheet CIRCIA NPRM Overview (CISA)_508c%20(locked).pdf) CISA Incident Reporting guidance generally
- Integrate CIRCIA requirements into existing incident response plans using frameworks such as NIST SP 800‑61 (Computer Security Incident Handling Guide) and NIST Cybersecurity Framework (CSF). NIST SP 800‑61 Rev. 2 NIST Cybersecurity Framework 2.0 CISA CIRCIA Fact Sheet
- Implement centralized logging, monitoring, and incident classification
- Use SIEM/SOAR platforms and robust logging to detect potential “covered cyber incidents” quickly and support evidence‑based reporting. NIST SP 800‑92 (Guide to Computer Security Log Management) NIST CSF “Detect” function CISA Cybersecurity Best Practices resources
- Establish clear escalation paths so that legal, compliance, and security leadership can decide within hours whether an incident meets CIRCIA thresholds. NIST SP 800‑61 Rev. 2 CISA Cyber Incident Planning resources CISA CIRCIA Overview page
- Ransomware payment governance and decision frameworks
- Create a governance framework for ransomware payment decisions that includes regulatory review, law‑enforcement engagement, and CIRCIA reporting triggers. CISA / FBI / Treasury Ransomware Guidance (StopRansomware.gov) CRS CIRCIA NPRM In Brief (payment reporting) CISA CIRCIA Fact Sheet
- Training and exercises
- Conduct tabletop exercises simulating CIRCIA‑covered incidents to practice producing and submitting reports within statutory timeframes. CISA Tabletop Exercise Packages NIST SP 800‑84 (Guide to Test, Training, and Exercise Programs) CIRCIA NPRM Overview_508c%20(locked).pdf)
- Tools and resources
- Leverage CISA incident reporting portals and tools (including reporting forms and contact channels) and general cyber tools maintained by CISA. CISA “Report an Incident” page [CISA Cybersecurity Tools catalog](https://www.cisa.gov/resources-tools/cy
Recent developments
- — This industry update says the rule remains unfinished after years of debate, leaving critical infrastructure operators to prepare for the reporting regime. It emphasizes the operational burden of building processes for rapid incident and ransom-payment reporting. (source)
- — Inside Cybersecurity reported that CISA gained additional time to finalize the mandatory incident-reporting rule after stakeholder feedback. The item indicates the schedule slipped again, showing continued rulemaking uncertainty. (source)
- — Industry-facing commentary describes organizations preparing for eventual compliance with CIRCIA’s 72-hour incident reporting and 24-hour ransomware payment deadlines. The broader impact is increased readiness planning by critical infrastructure operators ahead of finalization. (source)
- — CISA is expected to finalize the CIRCIA rule in September 2026, with reporting requirements still described as 72 hours for covered cyber incidents and 24 hours for ransomware payments. The article frames the move as the latest target after prior delays and notes that the rule would affect critical infrastructure organizations. (source)
- — CISA’s CIRCIA page reiterates the statutory framework: covered entities must report covered cyber incidents no later than 72 hours after reasonably believing an incident occurred. This remains the core policy baseline even as the final implementing rule is still pending. (source)
- — This update says CISA has again slipped the final-rule timeline, moving from a May 2026 target to September 2026 in the Unified Agenda. It frames the delay as another missed deadline for the long-awaited CIRCIA implementing rule. (source)
- — The article notes that the final rule remains unresolved more than two years after the proposed rule and that companies are still preparing for mandatory reporting obligations. Industry impact centers on compliance uncertainty and continuing monitoring of CISA’s timeline. (source)
- — This legal update says CISA had targeted May 2026 but that funding disruptions could further alter the timeline. It also highlights the proposed requirements that covered entities report incidents within 72 hours and ransomware payments within 24 hours. (source)
- — Reporting from early July says CISA was expected to finalize the CIRCIA rule in the fall of 2026. It reiterates the core obligations for 16 critical infrastructure sectors and highlights the 72-hour and 24-hour reporting windows. (source)
- — Nextgov reported that CISA expected to finalize the rule in September 2026, based on a regulatory document published the prior week. The piece underscores that the rule would require critical infrastructure providers to report major cyber incidents directly to CISA. (source)
Related regulations
- COPPA (Children's Online Privacy Protection Act) — United States, Active
- Cybersecurity Maturity Model Certification — United States, Phased, effective 2025-11-10
- NIST AI Risk Management Framework (AI RMF 1.0) — United States, Active, effective 2023-01-26
- SEC Cybersecurity Disclosure Rules — United States, Active, effective 2023-12-18
- Executive Order 14365 - Ensuring a National Policy Framework for Artificial Intelligence — United States, Active, effective 2025-12-11
- TAKE IT DOWN Act — United States, Active, effective 2026-05-19
- SEC Regulation S-P Amendments (Customer Data Incident Response) — United States, Active, effective 2026-06-03
- HIPAA Security Rule Modernisation (Proposed Rule) — United States, Proposed
Put it into practice
- Generate the policy: CIRCIA policy generator (generatepolicy.com)
- Buy the policy pack: Incident Response Bundle (cyberpolicy.shop)
- Build it yourself: CIRCIA 72/24 Reporting Readiness Pack (ciso.diy)
Browse all regulations · Compliance deadlines · Latest updates