Skip to main content

    CIRCIA Final Rule 2026: Four Years of "Not Yet" Is Nearly Up

    Angela McAdoo
    Post by Angela McAdoo
    September 10, 2026
    CIRCIA Final Rule 2026: Four Years of "Not Yet" Is Nearly Up

    Every few months, a client asks whether they need to worry about CIRCIA, and for four years running we have been able to say no, not yet; we'll tell you when. It was a comfortable answer. It is about to stop being true.

    CISA's regulatory agenda now puts the final rule for the Cyber Incident Reporting for Critical Infrastructure Act in September 2026. It hasn't appeared in the Federal Register as we write this, and the agency has moved the date more than once, so don't set your watch by it. But in June, CISA sat through four days of town halls with better than a thousand organizations on the line. That is what an agency does when it is finishing something, not when it is shelving it.

    What the law asks of you

    CIRCIA became law in March 2022, and on its own it obliges you to do nothing whatsoever. What it did was hand CISA an assignment: write the regulations that make people report. Those regulations are what we’ve all been waiting on.

    Two numbers sit in the middle of it. Seventy-two (72) hours to report a serious cyber incident, counted not from the day your investigation wraps up but from the moment you have reason to believe something happened. Twenty-four (24) hours to report a ransom payment. Congress wrote both figures into the statute itself, so no amount of lobbying during a comment period is going to stretch them.

    Until the final rule takes effect on a date it will name for itself, you owe CISA nothing. You are not behind. You are simply not going to get much notice.

    Why it has dragged on

    Worth a paragraph, because it explains why the fine print is still soft.

    CISA published the proposed version in April 2024 and got an earful. Too broad. Too expensive. Too hard to square with everything people already report for HIPAA, for TSA, for the electric grid, for the Pentagon, for fifty different state breach laws. Congress had asked for a final rule by October 2025. CISA missed that, promised May 2026 instead, and said it would try to shrink the thing. Then the Department of Homeland Security ran out of money in the spring, the town halls scheduled for March evaporated, and everything slid to June. Now the agenda says September.

    So read the proposal as a sketch rather than a photograph. CISA has said plainly that it is rethinking how many organizations get pulled in. Learn the shape of the rule. Don’t memorize its paragraph numbers.

    "Surely we’re too small for this"

    We hear that more than anything else, and usually from someone who is not too small for this.

    CISA's own fact sheet walks you through the question, and the first step never asks how big you are. It asks what you do. There are sixteen criteria, and meeting a single one puts you inside: a water system serving more than 3,300 people, a town of 50,000, a school district with a thousand students, a hospital with a hundred beds or a critical access hospital, anyone already reporting incidents under the Pentagon's DFARS clause, anyone selling IT to the federal government or touching election infrastructure.

    Nine people running a rural water district are covered. The 60-bed hospital in a county seat is covered. The machine shop with a defense contract has been living under a version of this since 2017 and may never have noticed.

    If none of the sixteen fits you, the test asks a second question. Are you in one of the sixteen critical infrastructure sectors, and are you bigger than the Small Business Administration's size standard for your industry? Two yes’s and you're covered. That second door is where the small-business exemption lives, and it is also the part most likely to look different when the final rule arrives.

    The hard part isn’t the paperwork

    Filling out CISA's form will take an afternoon. Having something honest to put in it is the real work.

    The report wants to know what happened and when, which systems were affected, how the intruder got in, what they did once inside, and what they took. All of it within three days, and the clock starts when you merely suspect.

    You can’t go back and collect evidence you never kept. If your firewall holds a week of logs and your endpoint agent rolls over at thirty days and the intrusion began in June, your report will be a page full of the word "unknown," filed with a federal agency, with your name at the bottom of it.

    Here is the test we like. Pick a server, any server. Can you say who signed into it three weeks ago? Most people can’t, and it is much better to find that out now.

    Four things worth doing before the rule lands

    Not a program. Not a project plan. Four things.

    Decide in writing whether you're covered: One page. Name the criterion, or name the sector and the size standard. Sign it and date it. When the final rule moves the lines, you revise a page instead of starting from nothing. If the answer turns out to be no, that page is still worth keeping.

    Go look at your logs before you buy anything: Not detection. Not a dashboard. Retention. What do you keep, from which systems, and for how long? Nearly everyone has decent coverage of laptops and almost nothing usable from their email tenant or their identity provider, which is exactly where the interesting part of a break-in happens.

    Put names next to the jobs: Who decides an incident is reportable? Who writes it up? Who calls the insurer, the lawyer, the board? "We’d figure it out" is a plan you will be carrying out at two in the morning with forty hours left on the clock.

    Take stock of what you already report: The proposal spares you a duplicate filing when you are already telling another federal agency substantially the same thing on substantially the same schedule. If you live under HIPAA or TSA or NERC or DFARS, that exception could matter a great deal to you. Work out where you stand while there is no clock running.

    In the meantime

    CISA takes voluntary reports today, at cisa.gov/report, with no obligation attached and nothing much to lose. If something goes wrong this autumn, walking through it voluntarily makes a decent rehearsal, and it is easier to meet the agency before you need them than during.

    We're watching the Federal Register. When the rule publishes, we'll write up what actually changed, in plain English, inside a week. And if you'd rather not spend the autumn wondering whether any of this applies to you, call us, and we'll work it out together.

    Find Out Where You Stand — Before the Rule Does

    Most organizations assume they're too small for CIRCIA. Many are wrong. This worksheet walks you through the same three-step screening we use with clients: sector membership, the SBA size test, and the sector-based criteria where size doesn't matter at all.

    Fifteen minutes of checkboxes gets you a working determination — Covered, Probably Covered, or Likely Not Covered — plus a readiness check on whether you could actually hit the 72-hour clock if you had to.

    FAQ

    CIRCIA Final Rule 2026

    What is CIRCIA?

    CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) is a federal law passed in March 2022 that requires certain organizations to report cyber incidents and ransom payments to CISA. The law itself doesn't create obligations yet; it directed CISA to write the implementing regulations, which are still pending final publication. 

    When does CIRCIA final rule take effect?

    CISA's regulatory agenda lists September 2026 as the target for the final rule, though the agency has moved this date multiple times before. The rule had not appeared in the Federal Register as of this writing, so the effective date remains unconfirmed. 

    How long do I have to report a cyber incident under CIRCIA?

    Once the final rule takes effect, covered entities will have 72 hours to report a substantial cyber incident, counted from the moment there is a reason to believe an incident occurred, not from when the investigation concludes. Ransom payments must be reported within 24 hours. 

    Angela McAdoo
    Post by Angela McAdoo
    September 10, 2026
    Cybersecurity Leader | CISSP | Security Operations, Incident Response & Compliance.