CIRCIA, FAR cyber rules crowd September compliance calendar
The September pileup turns incident response into a contracting problem with clocks running at 24 and 72 hours.
TL;DR
Federal News Network reports that the 2026 Unified Agenda puts the Cybersecurity and Infrastructure Security Agency’s final Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) rule in September: 72-hour incident reports and 24-hour ransomware-payment reports across 16 critical infrastructure sectors. The same agenda targets September for two Federal Acquisition Regulation (FAR) cyber rules, while third-party Cybersecurity Maturity Model Certification (CMMC) assessments are expected to become standard in applicable DoD contracts in November. For primes, contractors and managed service providers, the open issue is whether CISA narrows the 2024 draft’s 300,000-entity scope and clarifies its ambiguous incident trigger.

Federal News Network reports, citing the updated 2026 Unified Agenda, that the Cybersecurity and Infrastructure Security Agency (CISA) expects to issue the final Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) rule in September 2026. If the date holds, the law Congress passed in 2022 stops being a long-running drafting fight and becomes an operations clock: covered entities across 16 critical infrastructure sectors must report covered cyber incidents to CISA within 72 hours and ransomware payments within 24 hours.
The final rule’s most important sentence may be the one defining who and what is covered. CISA’s 2024 draft drew criticism for an estimated 300,000 covered entities, broad sector reach and ambiguity over which cyber incidents trigger reporting. For a hospital, water utility, managed service provider or prime contractor supporting those sectors, that ambiguity is operational. The first hour of an intrusion should not be consumed by counsel and security arguing over whether a federal reporting clock is already running.
September is crowded on the procurement side as well. The Unified Agenda points to final Federal Acquisition Regulation (FAR) rules for cybersecurity requirements on unclassified federal information systems and for cyber threat and incident reporting and information sharing. Those rules have been pending since 2023, and they arrive while the Defense Department continues Cybersecurity Maturity Model Certification (CMMC) implementation. Third-party CMMC assessments are expected to become standard in applicable contracts in November.
DoD is also expected in July to adopt an interim final CMMC rule on the deadline for moving from National Institute of Standards and Technology Special Publication 800-171 Revision 2 to Revision 3, plus an August proposal updating the Defense Federal Acquisition Regulation Supplement safeguarding clause for covered defense information and cyber incident reporting. That gives contractors and contracting offices several overlapping jobs: map which regimes apply, update incident playbooks, assign reporting ownership and rehearse the 24-hour ransomware-payment path before the first real weekend breach.
Published ·Deep Fathom