Skip to content
    Back to Regulatory Radar
    ImportantGuidanceJuly 31, 2026

    CIRCIA Incident Reporting Final Rule Slips Again: CISA Now Targets September 2026

    CISA has again pushed back the final rule implementing the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), which will add 6 CFR Part 226. The statutory deadline of October 4, 2025 (18 months after the April 2024 proposed rule) passed without a final rule, and the regulatory agenda target moved first to May 2026 and now, as of the current Unified Agenda entry, to September 2026. Once final, the rule will require covered critical infrastructure entities to report substantial cyber incidents to CISA within 72 hours and ransom payments within 24 hours.

    CIRCIANIST CSFHealthcareFinTechDefenseSaaS

    Key Analytics

    July 31, 2026
    Event Date
    Time Remaining
    August 24, 2026
    Last Verified
    2
    Frameworks Affected

    Impact Analysis

    The delay is a planning window, not a reprieve; the 72-hour incident and 24-hour ransom payment clocks are set by statute and will apply once the rule takes effect, and CISA's proposed covered-entity definitions reached well beyond obvious operators into healthcare, financial services, IT and managed service providers, and the defense industrial base. Organizations that wait for the final text will be compressing scoping, playbook updates, and contract flow-down work into a short runway. As of August 2026 the September target remains soft; it has already slipped twice, so treat it as directional and build readiness now.

    Recommended Actions

    • Assess whether your organization falls within the covered-entity criteria proposed in the April 2024 NPRM (89 FR 23644)
    • Update incident response playbooks with a 72-hour CISA reporting decision path and a 24-hour ransom payment reporting step
    • Map CIRCIA reporting triggers against existing obligations (SEC 8-K, HIPAA breach notification, state laws) to avoid conflicting timelines
    • Track the Unified Agenda entry for RIN 1670-AA04 and the Federal Register for the final rule and its effective date
    • Brief leadership that reporting obligations begin on the rule's effective date, with limited lead time expected after publication

    Always verify requirements with official regulatory sources.

    Estimated Remediation Effort

    Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.

    A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.

    Analyst estimate
    Moderate45-95 hours
    Key Workstreams
    • Applicability analysis against the proposed covered-entity criteria
    • Playbook updates for the 72-hour incident and 24-hour ransom payment clocks
    • Deconflict CIRCIA triggers with SEC 8-K, HIPAA, and state reporting timelines

    The Cost of Waiting

    Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.

    Start preparing nowModerate · 45-95 hours
    Start cold under pressureSignificant · 110-240 hours

    Roughly 65 to 145 hours avoided by preparing early

    Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.

    Related Events