Skip to main content
GuidesBy Jason LeeAugust 27, 20268 min read

CIRCIA Status: When the 72-Hour Reporting Rule Takes Effect

CIRCIA Status: When the 72-Hour Reporting Rule Takes Effect

The direct answer: the CIRCIA rule is not final. As of August 27, 2026, CISA has not published the final rule implementing the Cyber Incident Reporting for Critical Infrastructure Act. The rule missed its statutory October 2025 deadline, slipped past an earlier May 2026 target, and the July 2026 Unified Agenda preview now points to September 2026 for publication. Once it is final and effective, covered entities across the 16 critical infrastructure sectors will owe CISA a report within 72 hours of a substantial cyber incident and within 24 hours of any ransomware payment, with compliance obligations likely beginning in 2027. The proposed covered-entity test reaches most mid-market companies in those sectors, so the right move now is to find out whether you are in scope and build the reporting path before the clock becomes real.

Status verified August 27, 2026. This page is updated when the regulatory status changes.

Where the rule stands

CIRCIA became law in 2022 and handed CISA a rulemaking mandate: define who must report, what counts as a reportable incident, and how the reports work. CISA published the notice of proposed rulemaking on April 4, 2024. The proposal drew roughly 300 comments, and the sustained theme from industry and from lawmakers was that the proposed scope was too broad.

The statute required a final rule by October 2025. That deadline was missed. An OMB agenda target of May 2026 then came and went. In between, CISA ran a round of sector-specific town hall meetings from March 9 through April 2, 2026, with the stated purpose of narrowing the rule's scope. The current signal, from the July 2026 Unified Agenda preview, is a September 2026 publication target.

Honest caveat: this date has slipped three times. September 2026 is the best available projection, not a commitment. What has not changed is the statute itself. CIRCIA is law, the rulemaking is mandatory, and no version of the final rule can remove the two core obligations Congress wrote in.

What the rule will require

Once the final rule is published and takes effect, covered entities will have two reporting duties to CISA:

72-hour incident reports. A covered entity that experiences a substantial cyber incident must report it to CISA within 72 hours. The final rule will set the precise definition of substantial, which is one of the scope questions the town halls addressed.

24-hour ransom payment reports. A covered entity that makes a ransomware payment must report the payment to CISA within 24 hours. This duty applies to the payment itself, which means it can attach even when the underlying incident report is still being assembled.

Compliance obligations begin after the final rule's effective date. If publication lands on the September 2026 target, expect the compliance clock to start in 2027. That is a real planning window, but a short one for organizations that have never rehearsed a 72-hour external reporting motion.

Does CIRCIA apply to my company? A self-check by sector

The proposed rule uses a two-part test. First, are you in one of the 16 critical infrastructure sectors? Second, do you exceed the SBA small-business size standard for your industry, or meet one of the sector-based criteria that pull in certain entities regardless of size? If the answer to both is yes, you are presumptively covered under the proposal. The final rule may narrow this, and the town halls suggest CISA intends to, but no narrowed text had been published as of August 2026. Plan against the proposal, not against hope.

Sector Likely in scope under the proposed rule
HealthcareHospitals and health systems above the SBA size standard for their industry
Financial servicesBanks and credit unions above the size standard
DefenseDefense industrial base contractors, who already track their own CMMC timeline in parallel
Energy and waterElectric and water utilities and pipeline operators
Chemical and manufacturingChemical and manufacturing companies above the size standard
IT and SaaSSome IT and software providers serving critical infrastructure sectors

The practical self-check: identify your sector, look up the SBA size standard for your NAICS code, and compare. Most mid-market firms in these sectors exceed the standard, which is exactly why the proposal drew so much comment. Being small is the main exit from the general test, and the sector-based criteria can still reach smaller entities in some cases. If you sit near the line, treat yourself as covered until the final text says otherwise.

Not sure whether CIRCIA will reach you?

A Z Cyber advisor can walk your sector, size standard, and existing notification duties and brief you on what a 72-hour reporting path would require in your environment.

Talk to an Advisor →

CIRCIA on top of the reports you already owe

The most common misreading of CIRCIA is treating it as a replacement for existing notification duties. It is an addition. One incident at a mid-market company can trigger several reports at once, each with its own trigger, clock, and recipient:

HIPAA breach notification. Healthcare organizations that experience a breach of protected health information owe notification under HIPAA regardless of CIRCIA. The triggers differ: HIPAA turns on unsecured PHI, while CIRCIA will turn on the substantial-incident definition. A ransomware event at a hospital can plausibly trip both.

SEC disclosure. Public companies assess material cyber incidents for disclosure on Form 8-K under the SEC's cyber rules. Materiality to investors is a different question than substantiality to CISA, and the analyses run on separate tracks. Our breakdown of the SEC cyber disclosure requirements covers that regime in full.

NYDFS Part 500. Covered financial services firms in New York already live with a 72-hour notification duty. If that is you, the operational muscle transfers well; our NYDFS 72-hour notification runbook describes the reporting motion CIRCIA will demand from a much wider population.

State breach laws. State notification statutes attach to personal information of state residents and follow their own clocks and thresholds, separate from any federal report.

The harmonization problem is real and CISA has heard it repeatedly through the comment file and the town halls. Do not wait for the agencies to harmonize on your behalf. The workable answer at the company level is a single incident response runbook that maps every notification duty you hold, so the team fighting the incident is not also discovering its legal obligations in real time.

What to do before the final rule drops

None of this requires the final text to start. Four moves are worth making now. Confirm your scope answer using the sector and size-standard check above, and document the conclusion. Inventory every notification duty you already hold, federal, state, and contractual, in one place. Define internally what a substantial incident would look like in your environment, so the escalation decision is not invented at hour one. And rehearse the 72-hour motion once: who decides, who drafts, who submits, and where the facts come from. Companies subject to NYDFS or SEC clocks have a head start here; everyone else is building the muscle for the first time.

Your incident response plan is the natural home for all of it. An advisor can review the plan against the reporting duties you hold today and the CIRCIA duties that are coming, and recommend the specific changes; your team decides what to adopt and owns the plan.

What to watch next

Three dates matter from here. First, September 2026: the current Unified Agenda target for final rule publication. If it slips again, expect the next signal in a subsequent agenda update. Second, the effective date set in the final rule itself, which determines when the 72-hour and 24-hour clocks become enforceable, likely in 2027. Third, the final covered-entity definition: the March and April 2026 town halls were explicitly about narrowing scope, so the published test may differ from the proposal, and your self-check answer should be re-run against the final text the week it lands. This page will be updated when the status changes.

Frequently Asked Questions

Is the CIRCIA rule final yet?

No. As of August 27, 2026, the CIRCIA final rule has not been published. It missed the statutory October 2025 deadline, slipped past an earlier May 2026 target, and the July 2026 Unified Agenda preview now points to September 2026 for publication. The target has moved three times, so treat September 2026 as a projection, not a promise. Until the final rule is published and takes effect, CIRCIA reporting is not yet a binding obligation.

Does CIRCIA apply to my company?

Under the proposed rule, CIRCIA covers entities in any of the 16 critical infrastructure sectors that exceed the SBA small-business size standard for their industry, plus entities that meet sector-based criteria regardless of size. That test captures most mid-market hospitals and health systems, banks and credit unions, defense contractors, electric and water utilities, pipelines, chemical and manufacturing companies, and some IT and SaaS providers serving those sectors. The final rule may narrow this scope, but it had not been published as of August 2026.

What are the CIRCIA reporting deadlines once the rule is final?

Once the final rule takes effect, covered entities must report substantial cyber incidents to CISA within 72 hours and report ransomware payments within 24 hours of making the payment. These are federal reports to CISA and they sit on top of, not in place of, existing obligations such as HIPAA breach notification, SEC disclosure for public companies, NYDFS notification for covered financial firms, and state breach notification laws.

When will CIRCIA compliance be required?

Compliance obligations begin after the final rule's effective date, which is expected to fall in 2027 if the rule publishes on the current September 2026 target. That gives most covered entities a planning window measured in months, not years. The practical work, defining what counts as a substantial incident for your environment, wiring a 72-hour reporting path into your incident response plan, and assigning decision owners, takes longer than most teams expect.

How does CIRCIA relate to HIPAA breach notification and SEC 8-K disclosure?

CIRCIA adds a new federal report to CISA. It does not replace HIPAA breach notification to HHS, the SEC's cyber disclosure rules for public companies, NYDFS Part 500 notification for covered financial services firms, or state breach notification laws. Each regime has its own trigger, clock, and recipient, and one incident can owe several reports at once. Covered entities should map every notification duty they hold into a single incident response runbook before the final rule lands.

Subscribe for Updates

Get cybersecurity insights delivered to your inbox.