Services About Insights Schedule Consultation

CISA has been promising this rule for a long time. The 2026 Unified Agenda of Federal Regulatory and Deregulatory Actions, published August 14, puts the CIRCIA final rule at September 2026 — this month, in other words. As of September 23, nothing has appeared in the Federal Register. The rule has already missed the statutory deadline Congress set, October 4, 2025 (eighteen months after the proposed rule was published, per the reginfo timetable for RIN 1670-AA04), and it missed CISA’s own May 2026 target before that. It can land any day, or it can slip again.

Either way, the waiting is not the story. The reporting clocks are written into the statute itself and will not move when the rule finally does: 72 hours to report a covered cyber incident, 24 hours to report a ransom payment. The trigger for the first clock is not a completed forensics report or a signed legal memo. It is reasonable belief. Most mid-market teams we work with have neither a reporting matrix that covers all of their clocks nor a tested escalation path that can get a decision made — with counsel involved — inside that window. That gap is the real compliance risk, and it can be closed now, while publication is still pending.

Two clocks, one trigger

The statute is unusually direct. A covered entity must report a covered cyber incident “not later than 72 hours after the covered entity reasonably believes that the covered cyber incident has occurred” (6 U.S.C. § 681b(a)(1)(A)).

Read the trigger again. The clock starts when someone at your company reasonably believes an incident has occurred — not when root cause is confirmed, not when the board is briefed, not when outside counsel signs off. In practice that moment arrives while the technical picture is still murky. A SOC analyst sees odd authentication traffic on Tuesday; by the time anyone has confirmed what happened, half the 72 hours may already be gone. This is why the escalation path matters more than the incident-response plan document.

Ransom payments get their own, faster clock: reportable not later than 24 hours after the payment is made. And the statute adds a wrinkle that catches companies off guard — the payment is reportable “even if the ransomware attack is not a covered cyber incident” (§ 681b(a)(2)(B)). An incident that falls below the reporting threshold on its own facts can still generate a reporting obligation the moment money moves. Supplemental reports are due promptly as substantial new or different information becomes available (§ 681b(a)(3)), so the first filing is a beginning, not an ending.

Who is actually covered

The proposed rule draws the covered-entity test two ways: an entity is in scope if it is larger than the SBA’s small-business standards for its industry, or if it meets sector-specific criteria CISA defined for each of the 16 critical infrastructure sectors. The small-business exemption is narrower than most executives assume. CRS R48025 summarizes the range: an entity is exempt only if it has fewer than somewhere between 100 and 1,500 employees, or annual profits below somewhere between $2.5 million and $47 million, depending on the industry. A 600-person fintech is not exempt under any reading. The exact line for your NAICS code matters, and it is worth confirming rather than assuming.

The second way in is the one mid-market companies miss. Companies that provide technology, cloud, engineering, logistics, or operations support to critical-infrastructure customers get pulled in even though they would never describe themselves as critical infrastructure — Michael Gruden, a partner at Steptoe LLP, made this point in his September 16 commentary. If your customers include banks, payment processors, or exchanges, your incident is their reporting problem, and CIRCIA reaches you through them. Financial services is one of the 16 sectors. Gruden opens his piece with the image of “infinite companies across 16 critical infrastructure sectors” falling into scope — rhetoric, but directionally right for anyone serving the sector.

The scale, per CISA’s own analysis in the NPRM: an estimated 316,244 covered entities filing an estimated 210,525 reports over the period of analysis, at a total cost of $2.6 billion — $1.4 billion of it falling on industry (NPRM, 89 FR 23644). CISA fielded comments from more than 1,200 stakeholders across four town halls in June 2026 before finalizing (Federal News Network), which tells you how many scope questions were still live.

One incident, four clocks

For financial-services companies, CIRCIA never arrives alone. Gruden’s framing is the right one: federal banking regulators’ 36-hour notification rule, NYDFS Part 500’s 72-hour requirement, and — for public companies — the SEC’s four-business-day disclosure clock once materiality is determined. “None of these rules line up neatly.” The definitions differ (covered cyber incident vs. notification event vs. material), the thresholds differ, and the clocks start on different facts.

What trips teams is the assumption that reporting to your primary regulator covers everything else. It does not. The statute contemplates an exemption for entities that already report a substantially similar incident to another federal agency within a substantially similar timeframe — but that exemption only takes effect once CISA has an agency agreement and sharing mechanism in place with the agency in question under 6 U.S.C. § 681g. Until such an agreement exists and covers your regulator, assume no cross-crediting: filing with your prudential regulator does not satisfy CIRCIA. CISA said in the NPRM that it wants these agreements finalized before the rule’s effective date; watch for them, because they change the calculus more than almost anything else in the final text.

If you have NYDFS obligations, our NYDFS risk-assessment guidance covers how that clock interacts with the rest of the stack. The short version: build one matrix that maps every obligation — CIRCIA, sector rules, state breach laws, customer contracts, cyber insurers — with definitions, triggers, deadlines, and decision-makers side by side. Four clocks cannot be managed from four separate playbooks.

Enforcement without a fine schedule

CIRCIA has no civil-penalty schedule. That surprises people who assume every cyber rule comes with per-violation fines. The enforcement design is compulsion instead (6 U.S.C. § 681d): if CISA has reason to believe a covered entity experienced an unreported incident — “whether through public reporting or other information in the possession of the Federal Government” — the Director engages the entity and requests information about the incident or ransom payment. If CISA cannot obtain what it needs through engagement, it can issue a subpoena. Non-compliance gets referred to the Attorney General for civil action, and CRS notes that information gathered through subpoena can feed regulatory or criminal referrals.

Note what that means operationally: the news article you never sent CISA can become the information request you did receive. CISA can learn about your incident from press coverage, from a customer’s own report, or from law-enforcement involvement. Silence does not keep you off the radar; it just means CISA’s first contact is a demand rather than your filing.

There are real protections on the reporting side. Under 6 U.S.C. § 681e, reports are exempt from disclosure under FOIA, cannot be used in a regulatory action against the reporting entity, and are shielded from evidentiary and discovery use (CRS). But those protections are structural — they hold when counsel is involved early and the report is handled correctly, not retroactively. Alongside them sits a preservation duty: relevant data, including communications with attackers, indicators of compromise, technical and forensic data, and logs, must be retained for two years. For most mid-market teams that is a retention-policy change requiring legal and IT sign-off, not a footnote.

What to do with the window

“The window before the final rule lands is the time to stress-test the incident response process, not after,” as Gruden put it. The work is program work, and none of it depends on the final text:

The policy itself is rarely the hard part. The hard part is proving you can execute the clocks — reasonable belief to decision to filing — inside 72 and 24 hours, with the matrix and escalation path already built. Most mid-market teams have not done this, which is exactly why fractional CISO support for incident-reporting readiness is one of the fastest-growing asks we see. Gruden’s summary is blunt and correct: “Too many organizations have treated CIRCIA as something to keep an eye on rather than something to actually build a program around.”

What to watch

Need a second set of eyes before your SOC 2 audit?

NTD Consulting offers a free 30-minute readiness assessment. No pitch, no pressure — just direct feedback on where your program is likely to get pushed back.

Schedule a 30-Minute Consultation