CISA slips CIRCIA final rule to September 2026
Lawmakers may tolerate the delay, but operators still lack the scope, thresholds and procedures they need to build reporting processes.
TL;DR
The Cybersecurity and Infrastructure Security Agency (CISA) now expects to publish the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) final rule in September 2026, Inside Cybersecurity reports, four months after its May target and after CISA missed the law’s original timeline. Critical infrastructure contractors, primes, CMMC third-party assessors and government customers still lack final scope, thresholds and procedures for 72-hour incident reports and 24-hour ransom-payment reports. Congress has shifted to auditing CISA’s process after the schedule fight was already lost.

Inside Cybersecurity reports that the Cybersecurity and Infrastructure Security Agency (CISA) has moved the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) final rule to September 2026, four months after the May 2026 target it set in September 2025. That is the second miss for a 2022 bipartisan law meant to give the government faster visibility into major incidents while giving covered entities a known reporting playbook. Instead, critical infrastructure operators and the contractors around them remain stuck designing against an April 2024 proposal that lawmakers and industry criticized as too broad and too hard to operate.
Once final, CIRCIA will require covered entities to report covered cyber incidents within 72 hours and ransom payments within 24 hours. The unresolved practical questions are the ones that matter before an incident happens: which entities are covered, which events cross the threshold, and how compliance teams document decisions under time pressure. CISA says multiple funding lapses affected rulemaking and that it held four days of June 2026 town halls with more than 1,200 critical infrastructure stakeholders to collect additional feedback.
Congressional reaction has shifted from schedule discipline to after-the-fact supervision. House Homeland Security Chairman Andrew Garbarino said he supported extensions if they produce a final rule that meets congressional intent and incorporates private-sector input, and said he will review CISA’s ex parte process and whether the agency meaningfully uses that input. Sens. Gary Peters and Mark Warner pressed the same basic line: finish the rule quickly, but make the burden predictable and proportional to the national security need.
The September date sharpens the open question. If the final rule meaningfully absorbs the June town halls, the delay buys something. If it mostly tracks the April 2024 proposal, CISA will have spent two extra schedule slips to arrive at the same fight over scope, thresholds and feasibility, with mandatory implementation pushed deeper into 2026 or into 2027.
Published ·Deep Fathom