CISA's Mandatory Cyber Incident Reporting Rule Reaches Its Third Deadline This Month
The CIRCIA final rule, already past two missed deadlines, is due from CISA this September, and this time the 72-hour and 24-hour reporting clocks are statutory and won't bend.
CISA is now in the window it set for itself to publish the final rule implementing the Cyber Incident Reporting for Critical Infrastructure Act of 2022, commonly called CIRCIA. The agency has missed two prior target dates. Whether September holds is the live question.
<cite index="19-7">Signed into law in March 2022, CIRCIA represents the most significant expansion of CISA's regulatory authority to date, directing the agency to mandate that covered critical infrastructure entities report substantial cyber incidents within 72 hours and ransomware payments within 24 hours.</cite> That framing comes from regulated-industry advisories, and it's fair on its face, no prior U.S. framework applied mandatory, cross-sector incident-reporting requirements at this scale.
<cite index="19-8,19-9">CISA published a Notice of Proposed Rulemaking in April 2024, outlining sector-based and size-based criteria across 16 critical infrastructure sectors. After receiving extensive public feedback regarding regulatory burdens and definitional clarity, CISA missed its initial October 2025 statutory deadline and revised its target to May 2026.</cite> Then DHS appropriations lapsed. <cite index="21-9,21-10">Town hall sessions originally scheduled for March and April 2026 were postponed due to a lapse in Department of Homeland Security appropriations. CISA rescheduled the meetings for June 15 through 18, 2026, and more than 1,200 stakeholders participated across four days of sessions.</cite>
<cite index="27-4">According to the latest Unified Agenda of Federal Regulatory and Deregulatory Actions, published on reginfo.gov and reported by Nextgov/FCW, CISA now expects to finalize the rule implementing CIRCIA in September 2026.</cite> That's the third official target date. As Federal News Network reported in July, <cite index="12-6,12-7">once the final rule is published and goes into effect, it will represent one of the most far-reaching U.S. cyber regulations ever implemented, applying across 16 critical infrastructure sectors, ranging from electric utilities and water systems to hospitals and chemical facilities.</cite>
The policy stakes here deserve a beat-specific read. The regulated population is enormous. <cite index="22-6">The proposed rule would require prompt reporting of cyber incidents and ransomware payments from an estimated 316,244 affected entities spanning the 16 critical infrastructure sectors, including chemical, communications, energy, financial services, food and agriculture, and healthcare.</cite> Healthcare and chemical facilities are the overlap point with the biodefense portfolio, a ransomware hit on a hospital network or a synthesis firm is simultaneously a cybersecurity incident and a potential biosecurity concern if it degrades diagnostic or inventory systems.
<cite index="21-5">Reporting under CIRCIA is intended to allow CISA to rapidly deploy resources and assistance to victims of cyberattacks, analyze incoming reports across sectors to identify trends, and share that information with network defenders so they can take steps to protect themselves from similar incidents.</cite> That's the stated rationale. The actual analytic value depends heavily on what CISA does with the inbound data, a reporting mandate without a functioning fusion function is overhead, not intelligence.
The timeliness problem is worth flagging. <cite index="27-7,27-8">Congress set a statutory deadline of October 2025, eighteen months after the April 2024 proposed rule. CISA missed it, announcing in September 2025 that the final rule would arrive in May 2026.</cite> May passed. A commentary published this week by Federal News Network noted the practical gap that has opened in the interim: <cite index="25-6,25-7">the hard part isn't the deadline itself, it's everything that has to happen before a company even realizes the clock has started. Too many organizations have treated CIRCIA as something to keep an eye on rather than something to actually build a program around.</cite>
That's a moderate-confidence assessment from the compliance-advisory community, not an empirical finding, and readers should weight it accordingly. What's factual is that the statutory clocks, 72 hours for incidents, 24 hours for ransomware payments, are written into the law itself and can't be softened by agency discretion in the final rule. Whoever missed the rulemaking process is now building programs against a live target.
Sources cited:
- Federal News Network (https://federalnewsnetwork.com/cybersecurity/2026/07/circia-other-big-cyber-rules-expected-to-get-finalized-this-fall/)
- Federal News Network (commentary) (https://federalnewsnetwork.com/commentary/2026/09/beyond-the-town-halls-getting-ready-for-circia-before-the-clock-starts-ticking/)
- Hunton Privacy & Cybersecurity Law Blog (https://www.hunton.com/privacy-and-cybersecurity-law-blog/cisa-plans-to-finalize-cyber-incident-reporting-regulations-in-september-2026)
- Exterro (https://www.exterro.com/resources/cisa-sets-september-2026-target-for-final-cyber-incident-reporting-rules)
- ComplianceHub.Wiki (https://compliancehub.wiki/cisa-circia-final-rule-september-2026-incident-reporting-readiness/)
- PwC (https://www.pwc.com/us/en/services/consulting/cybersecurity-data-tech-risk/library/cyber-incident-reporting.html)
- CISA CIRCIA FAQs (https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/circia/faqs)
This release was originally distributed via ETL Newswire. Visit Federal News Network for the full story, related releases, and contact information.
Visit Federal News Network →