CIRCIA Final Rule Expected This Month, Scope Still Open
The harder problem isn't the 72-hour incident clock or the 24-hour ransomware window, it's stacking those deadlines on top of DFARS, NERC, TSA, and DOE reporting obligations that already exist and don't line up.
TL;DR
CISA expects to issue the final CIRCIA rule in September 2026, triggering 72-hour incident and 24-hour ransomware-payment reporting for entities across 16 critical infrastructure sectors by late 2026 or early 2027. The proposed rule estimated over 300,000 covered entities, a scope industry has challenged as too broad and untethered from functional criticality. The final rule's treatment of "covered entity" and "substantial cyber incident" threshold language hasn't been disclosed. For defense contractors, energy operators, and others already subject to sector-specific incident-reporting rules, the operational lift isn't CIRCIA alone, it's building a workflow that doesn't produce conflicting narratives or missed deadlines when multiple regulators want different things on different clocks.

The Cybersecurity and Infrastructure Security Agency plans to release its final rule for the Cyber Incident Reporting for Critical Infrastructure Act this month, according to the 2026 Unified Agenda of Federal Regulatory and Deregulatory Actions. If that timeline holds, enforceable reporting deadlines (72 hours for a covered cyber incident, 24 hours for a ransomware payment) arrive by late 2026 or early 2027 across 16 critical infrastructure sectors.
The rule text itself hasn't dropped. But the operational problem is already well-defined, and it isn't the clocks.
CISA held virtual town halls in June to gather stakeholder input on the draft rule. The conversations surfaced the same tensions that have trailed CIRCIA since the 2024 Notice of Proposed Rulemaking: the breadth of the "covered entity" definition, what qualifies as a "substantial cyber incident," and how the new regime interacts with reporting obligations already on the books. On scope, CISA's own estimate put the proposed rule at north of 300,000 covered entities, driven by sector categories and SBA size thresholds rather than any functional assessment of criticality. Industry pushed CISA toward a narrower, function-based approach. Whether that argument lands in the final rule is, at this point, genuinely unknown.
For most organizations, the reporting deadlines themselves aren't the hard part. The hard part is the stack. A defense contractor already has DFARS 72-hour reporting and evidence-preservation requirements. An energy operator may be answerable to NERC, the Energy Department's OE-417 process, and (if pipelines are involved) TSA security directives. Financial services firms sit under federal banking regulators' 36-hour rule, the New York DFS Part 500 72-hour requirement, and the SEC's four-business-day materiality clock for public companies.
None of these regimes use the same definitions, the same thresholds, or the same deadlines. Reporting to an insurer or a sector regulator doesn't automatically satisfy CIRCIA, and a CIRCIA filing doesn't automatically cover the others. During an active incident, the risk is structural: IT works containment, leadership manages operations, and legal triages mandatory notifications, and without coordination, different audiences get different versions of what happened.
The window before the final rule lands is the time to map the full reporting matrix. That means charting every likely obligation (CIRCIA, sector rules, state breach laws, contracts, insurance) and knowing who gets the first call, who decides reportability, and how fast the right people can be reached. Vendor contracts with managed security providers, forensic firms, and outside counsel should require prompt notice and evidence preservation, since those parties often hold the logs and analysis that determine whether something triggers a report. CIRCIA offers protections for reports and materials created for the reporting process, and filing doesn't waive privilege on its own, but those protections are strongest when counsel is involved from the start.
The final rule may tweak definitions and thresholds. It won't change the fact that once an incident is serious, the time to figure out who needs to know (and in what order) is measured in hours.
Published ·Deep Fathom