CISA targets September for final CIRCIA reporting rule
The voluntary era ends only if CISA defines the trigger clearly enough for incident responders to use under fire.
TL;DR
NextGov reports that the Cybersecurity and Infrastructure Security Agency (CISA) expects to finalize the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) rule in September 2026. Covered critical-infrastructure entities would face 72-hour reporting for substantial cyber incidents and 24-hour reporting for ransomware payments; primes, contractors and Certified Third-Party Assessment Organizations (C3PAOs) around those environments need reporting workflows. The voluntary-only model is ending, four years after Congress acted and after CISA missed its October 2025 final-rule deadline; definitions, penalties and safe harbors now do the real work.

NextGov/FCW reports, citing a regulation document published last week, that the Cybersecurity and Infrastructure Security Agency expects to finalize the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) rule in September 2026. That would move covered critical-infrastructure reporting from a cooperation model to a legal process: substantial cyber incidents to CISA within 72 hours, ransomware payments within 24 hours.
That is the actual shift. CISA has encouraged incident sharing for years, and there is a real public-interest case for faster visibility after SolarWinds and Colonial Pipeline. The government cannot warn other victims, spot cross-sector patterns or deploy help if it learns about the attack only after the first response cycle is over.
Mandatory reporting is not a slogan a security operations team can execute. The final rule has to settle the pieces practitioners care about during the first day of a breach: what CISA treats as a "substantial incident," what happens when an entity misses the 72-hour or 24-hour clock, and what safe harbor or liability protection attaches to a timely report. Those details will decide whether reporting becomes a clean incident-response step or another parallel legal workstream.
GAO had already named harmonizing cyber incident reporting requirements as a Department of Homeland Security implementation challenge in 2024 (https://www.gao.gov/assets/gao-24-106917.pdf). That is where CIRCIA will bite for federal cyber compliance teams. Covered operators get the legal duty; primes, contractors and Certified Third-Party Assessment Organizations (C3PAOs) around those environments get the mapping problem of deciding who is covered, who reports and who supplies facts inside the clock.
CISA published the first procedural notice in April 2024 and missed the October 2025 statutory final-rule deadline. Four years after Congress passed CIRCIA, the voluntary-only era is close to over. The paperwork problem is about to become a clock problem.
Published ·Deep Fathom