Cybersecurity protects your systems. Cybersecurity risk management protects your business.®

The Information Highway

The Information Highway

Font size: +
15 minutes reading time (3025 words)
Featured

CIRCIA Is Almost Here

After more than four years of waiting, the federal government's most far-reaching cybersecurity reporting law is finally close to taking real, enforceable shape. The Cybersecurity and Infrastructure Security Agency (CISA) has told stakeholders it intends to publish the long-delayed final rule for the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) in September 2026 — and once that happens, the clock starts ticking toward mandatory reporting for hundreds of thousands of U.S. businesses.

Jujubes lemon drops tart lollipop brownie

Cupcake Ipsum, 2015
If your organization operates anywhere near critical infrastructure — healthcare, financial services, energy, water, IT and communications, transportation, manufacturing, or dozens of other sectors — this is no longer a "someday" regulation. It's a "start preparing this quarter" regulation. This guide walks through what CIRCIA actually is, who it covers, how it will change the way your business handles a cyberattack, and when you can expect it to become enforceable.

What Is CIRCIA, Exactly? 
CIRCIA, short for the Cyber Incident Reporting for Critical Infrastructure Act, was signed into law in March 2022, largely in response to a string of attacks (Colonial Pipeline among them) that exposed how little visibility the federal government had into cyber incidents hitting the systems Americans depend on every day: power grids, hospitals, water treatment plants, banks, and pipelines.

The law directs CISA to build a mandatory reporting system with two core obligations for "covered entities":

  • •Report a covered cyber incident to CISA within 72 hours of reasonably believing it occurred.
  • •Report a ransom payment within 24 hours of making it.

This is different from the breach notification laws many businesses already know. State breach laws and rules like HIPAA or the SEC's Item 1.05 disclosure requirement are about notifying consumers, patients, or investors. CIRCIA is about giving the federal government — specifically CISA — fast, structured, technical visibility into attacks so it can spot patterns, warn other potential victims, and coordinate a national response. It doesn't replace your existing notification obligations; it stacks on top of them.

Here's the part that's actually news: CIRCIA has been law since 2022, but it has never been enforceable, because CISA still hasn't finished writing the regulations that implement it. CISA missed its original October 2025 statutory deadline to finalize those rules, missed a revised May 2026 target after a government funding lapse delayed public town halls, and is now aiming for September 2026 — which is essentially right now. That single fact is why this topic deserves your attention this month, not next year.

It also helps to understand why Congress felt this law was necessary in the first place. Before CIRCIA, cyber incident reporting to the federal government was almost entirely voluntary and fragmented across dozens of sector-specific rules, informal FBI notifications, and inconsistent state laws. When the 2021 Colonial Pipeline ransomware attack shut down fuel delivery across the East Coast, investigators and policymakers realized the government often learned about attacks on the systems Americans rely on from news coverage — not from the companies involved. CIRCIA was designed to close that gap by making reporting mandatory, standardized, and fast enough that CISA can actually warn other likely targets before an attack spreads sector-wide.
The road from statute to enforceable rule has taken longer than CIRCIA's own deadlines intended — but CISA now says a final rule is imminent.

Who Is Affected by CIRCIA?

CIRCIA uses what's often called a two-track coverage test. Your organization is a "covered entity" if it meets either of the following:

  • •Track 1 — Size-based: You operate in a critical infrastructure sector and exceed U.S. Small Business Administration size standards for your industry (generally 100–1,500 employees, or $2.25 million–$47 million in annual revenue, depending on the sector).
  • •Track 2 — Sector-based: You perform specified functions within one of 16 critical infrastructure sectors, regardless of your size.

Those 16 sectors, as defined by CISA, are: Chemical, Commercial Facilities, Communications, Critical Manufacturing, Dams, Defense Industrial Base, Emergency Services, Energy, Financial Services, Food and Agriculture, Government Facilities, Healthcare and Public Health, Information Technology, Nuclear Reactors/Materials/Waste, Transportation Systems, and Water and Wastewater Systems.

CISA's own regulatory analysis estimates roughly 316,000 entities will fall within scope — and notably, the agency classifies over 310,000 of those as small entities. In other words, CIRCIA is not just a Fortune 500 problem. A 40-person water utility or a small community hospital can be squarely covered under Track 2, even though it would never trigger Track 1's size thresholds.

One detail worth flagging: the reporting trigger is what you reasonably believe happened, not what you've conclusively proven through a completed forensic investigation. That standard was one of the most debated topics at CISA's 2026 town halls — industry groups pushed for a clearer, higher bar so routine security alerts and false positives don't flood CISA with reports, while CISA has signaled it wants the trigger to stay early enough that the agency isn't the last to know. Expect the final rule's exact language here to matter a great deal in practice.

Meeting either track is enough to make an organization a “covered entity” under CIRCIA

 A Note for IT-Dependent Businesses and Their Vendors

Coverage isn't limited to the household-name sectors. The Information Technology sector is explicitly on CISA's list, which means many managed service providers, cloud hosting companies, and software vendors could be directly covered once the size or sector thresholds are met. And even businesses that aren't covered entities themselves can be pulled into the reporting chain indirectly: CIRCIA's definition of a reportable incident includes supply chain compromises, so if an attack on a vendor, contractor, or cloud provider disrupts a covered entity's operations, that downstream impact can itself trigger a 72-hour clock for the affected business. During its 2026 town halls, CISA specifically flagged "treatment of cloud and managed service providers" as one of the most contested open questions in the rule — a strong signal that vendor and supply-chain obligations will get real scrutiny in the final text.

Practically, that means every covered business should expect to start asking its own vendors andIT partners a new question: "How fast will you tell us if you're breached, and what will you give us to file our own CIRCIA report on time?"

How CIRCIA Will Affect Your Business

For most organizations, CIRCIA's biggest impact won't be the reporting form itself — it will be everything upstream of it. Meeting a 72-hour deadline that starts the moment you reasonably believe an incident occurred (not the moment you've fully confirmed it) requires a very different level of readiness than the informal, ad hoc incident response many small and mid-sized businesses rely on today.

What has to be in a report

A CIRCIA report generally needs to describe the systems and networks affected, a timeline of the incident, the tactics and techniques the attacker used, the impact on operations, and any mitigation steps already taken. If new facts emerge afterward, supplemental reports are expected, and CISA is expected to require records be retained for a period of time after the incident. That's a meaningfully more technical and structured submission than a typical breach-notification letter.

Both clocks start the moment you reasonably believe the triggering event occurred — not when an investigation confirms it.

 It layers on top of what you already do

CIRCIA doesn't replace HIPAA breach notification, GLBA safeguards reporting, the SEC's 8-K Item 1.05 cyber disclosure rule, or state breach notification statutes — it adds a parallel federal reporting track alongside them. CISA has acknowledged the overlap is a real burden and is exploring a "substantially similar reporting" exception that would let a report already filed with another federal regulator satisfy CIRCIA in some cases, but that mechanism is still being worked out in the rulemaking. Until it's finalized, businesses should plan to treat CIRCIA as an additional obligation, not a replacement for existing ones.

How CIRCIA compares to rules you may already follow

Most covered entities won't be starting from zero — many already report incidents somewhere. The table below shows how CIRCIA fits alongside a few of the reporting obligations businesses commonly juggle already: 

Rule

Who you notify

Typical deadline

CIRCIA

CISA (federal)

72 hrs (incident) / 24 hrs (ransom payment)*

HIPAA Breach Notification

HHS, affected patients

60 days

SEC Item 1.05 (8-K)

Investors, via SEC filing

4 business days after materiality determination

State breach notification laws

Affected residents, state AG

Varies — often 30–60 days

GLBA Safeguards Rule

FTC (financial institutions)

As soon as possible, generally within 30 days

*CIRCIA's deadlines are the fastest of the group by a wide margin — a large part of why incident response speed, not just legal review, becomes the bottleneck.

There are real teeth behind it 

CIRCIA gives CISA meaningful enforcement tools for non-compliance. If an entity doesn't report as required, CISA can issue a Request for Information with its own 72-hour response window; ignoring that can escalate to a subpoena, and a continued refusal can be referred to the Department of Justice. Knowingly false statements in a report can carry criminal penalties of up to five years in prison (eight if tied to terrorism), and federal contractors face suspension and debarment risk on top of that. On the other hand, the law also includes real protections for businesses that report in good faith: reports generally can't be used against the submitter in most civil litigation, aren't subject to Freedom of Information Act requests, and don't waive attorney-client privilege or other legal protections.

When Does CIRCIA Actually Go Into Effect?

This is the question everyone asks, and the honest answer is: soon, but not instantly. Here's the timeline so far:

  • •March 2022 — CIRCIA is signed into law.
  • •April 2024 — CISA publishes the proposed rule (NPRM) and opens it for public comment.
  • •October 2025 — CIRCIA's original statutory deadline for a final rule passes, unmet.
  • •Early–mid 2026 — CISA retargets May 2026, then delays further after a government funding lapse postpones planned stakeholder town halls.
  • •June 2026 — CISA holds sector-specific virtual town halls, drawing more than 1,200 participants and surfacing contested issues like size thresholds, cloud/MSP treatment, and duplicate-reporting relief.
  • •September 2026 — CISA's current target to publish the final rule.

Here's the nuance that matters most for planning purposes: publishing the final rule is not the same as reporting becoming mandatory that day. The final rule itself will specify its own effective date, and based on how similar federal rules have phased in, most legal and industry analysts expect enforceable reporting obligations to begin sometime between late 2026 and 2027 — likely with a compliance runway of several months after publication. Until that effective date arrives, reporting cyber incidents to CISA under CIRCIA remains voluntary (though CISA continues to encourage it), and none of your other reporting obligations change in the meantime.

It's also worth staying skeptical of any single date, given CIRCIA's track record: this rule has already missed one statutory deadline and one internal target. Treat September 2026 as CISA's current best estimate, not a guarantee — and treat the runway between now and whenever the rule lands as valuable preparation time, not a reason to wait.

How to Prepare Now

Because the exact effective date is still moving, the smartest move for most businesses is to prepare for CIRCIA's substance now rather than waiting for a final date to appear in the Federal Register. A few concrete steps:

  • •Determine your coverage status. Map your organization — and your key vendors — against the two-track test so you know whether you're likely to be a covered entity.
  • •Stress-test your incident response plan against a 72-hour (and 24-hour) clock, not the days-or-weeks timeline many informal plans still assume.
  • •Confirm you have 24/7 monitoring and logging capable of actually detecting an incident quickly enough to start that clock in your favor, not after it's already run out.
  • •Pre-build a reporting template mapped to CIRCIA's likely required fields (affected systems, timeline, indicators of compromise, TTPs, impact, mitigation) so a real incident doesn't start with a blank page.
  • •Review vendor and MSP contracts for breach-notification SLAs — you need your partners to tell you fast enough that you can still meet your own deadline.
  • •Run a tabletop exercise that specifically includes the reporting decision, not just technical containment.
  • •Coordinate CIRCIA planning with your existing HIPAA, GLBA, SEC, or state breach-notification processes so you're not building parallel, conflicting playbooks.

If any of this feels like more than your internal team can take on alone, that's exactly the gap a managed IT and security partner is built to close. LBT Technology Group, LLC. helps businesses assess their CIRCIA exposure, harden detection and monitoring, and build incident response plans that can actually hit a 72-hour deadline under pressure. Reach out to our team for a CIRCIA readiness conversation before the final rule not during your first incident under it.


The Bottom Line

CIRCIA has spent four years as a law without teeth, but that's about to change. With CISA targeting a September 2026 final rule after a long string of delays, the businesses that come out ahead will be the ones that treat the next few months as a planning window rather than a waiting period. Understand whether you're covered, know your 72- and 24-hour obligations, and get your incident response plan ready to move at regulatory speed; because once the final rule publishes, the runway to comply will be shorter than the runway it took to write it.

Frequently Asked Questions

Sources & Further Reading

CIRCIA, other big cyber rules expected to get finalized this fall | Federal News Network

CISA's long-awaited cyber incident reporting rules are among several cybersecurity regulations that are expected to move forward in the coming months.

CISA Advances CIRCIA Reporting Rule Toward 2026 Deadline

CIRCIA remains unfinished as critical infrastructure entities prepare to report cyber incidents in 72 hours and ransom payments in 24 hours.

New Federal Cybersecurity Reporting Rules are on Their Way: FAQs for Businesses About CIRCIA Regulations | Fisher Phillips LLP

A sweeping new federal cybersecurity mandate is on its way, and now is the time for businesses to build the infrastructure you’ll need to comply. The Cybersecurity and Infrastructure Security Agency (CISA) is finalizing draft rules that will require a massive swath of American businesses to report certain cyber incidents, putting more structure and teeth behind the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA). While the agency has been targeting May 2026 for the release of the final rule, recent federal appropriations disruptions could alter that timeline. But the core obligations are not expected to change from the draft rule, and businesses that wait for the ink to dry before preparing will be starting from behind. Here’s a set of FAQs to help you understand what’s about to happen and what you should do.

CISA Reopens Comment Opportunity on Cyber Incident Reporting Requirements: Wiley

The U.S. Department of Homeland Security's (DHS) Cybersecurity and Infrastructure Security Agency (CISA) is working to finalize a rule that would require large segments of industry to rapidly report to the government when they become victims of cybersecurity incidents.
Cybersecurity Threat Advisory 29-26: Qilin explo...

Related Posts

Top Breaches Cost ($) of 2024

HEALTHCARE
FINANCIAL
INDUSTRIAL
TECHNOLOGY
ENERGY
Source: IBM Cost of a Data Breach Report 2024