Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CIRCIA is law, but its mandatory reporting rules are not yet in effect. As of September 28, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) says it is still working on the final rule. The statute sets a framework for reporting covered cyber incidents and ransomware payments, but covered entities will not have to submit CIRCIA reports until that final rule takes effect.

What CIRCIA is—and what it requires

The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) became law on March 15, 2022, as part of the Consolidated Appropriations Act. It directed CISA to create regulations requiring covered entities to report covered cyber incidents and ransomware payments. The law’s goal is to give the federal government timely information to support cybersecurity situational awareness and response. CISA’s CIRCIA overview describes the statute and rulemaking.

The statutory framework calls for a report within 72 hours after an entity reasonably believes a covered cyber incident occurred, and within 24 hours after a ransom payment. These are statutory timeframes, not a signal that reporting has already begun: CISA says mandatory CIRCIA reporting will not be required until its final rule takes effect.

Why federal cyber reporting legislation was pursued

CIRCIA was developed against a fragmented reporting landscape. Before the law, federal agencies and state, local, tribal, and territorial governments had different requirements for different organizations and events. CISA’s 2024 proposed-rule background described dozens of potentially applicable requirements, depending on an entity’s business and where it or its customers operate. It also noted that all 50 states and certain territories had laws requiring reporting or public disclosure for at least some cyber incidents resulting in data breaches. Those rules do not all cover the same incidents or organizations, but the patchwork created a reason to pursue more consistent federal reporting. The Federal Register proposal discusses that context.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the CIRCIA rulemaking reached its current point

  1. March 2022: Congress enacted CIRCIA and directed CISA to develop reporting regulations.
  2. September 2023: The Department of Homeland Security delivered a report on harmonizing cyber incident reporting to the federal government. It was informed by the Cyber Incident Reporting Council, which CIRCIA required DHS to establish and chair.
  3. April 4, 2024: CISA published its notice of proposed rulemaking (NPRM), setting out proposed coverage and implementation details for public comment.
  4. July 3, 2024: The comment period closed after an extension. CISA had also issued a correction on June 3.
  5. 2024–2026: CISA reviewed the proposal and comments. The Unified Agenda records concerns about the proposal’s scope and burden, coordination with other federal reporting requirements, and the need for clearer terms.
  6. As of September 28, 2026: CISA says it is still working on the final rule. It held four public town halls from June 15 through June 18, 2026, and says multiple funding lapses affected its rulemaking activity. CISA’s status page provides the agency’s current account; the Unified Agenda entry summarizes the rulemaking and public comments.

CISA describes the delay directly: “While CISA recognizes the importance of CIRCIA, multiple funding lapses impacted CISA’s ability to conduct rulemaking activity for CIRCIA.” The agency’s statement explains one factor affecting the work; it does not provide a final publication date.

What must happen before CIRCIA reporting starts

CISA must publish a final rule and that rule must take effect. Until then, the proposed rule’s detailed definitions, coverage boundaries, reporting contents, and implementation details should not be treated as settled requirements. The statutory reporting framework exists, but the final rule will establish how it operates in practice. CISA’s current overview states that mandatory reporting will not begin before the rule’s effective date.

Once the rule is effective, CIRCIA also sets information-sharing duties among federal agencies: an agency receiving an incident report must share it with CISA within 24 hours, and CISA must make information received under the law available to appropriate agencies within 24 hours. The statute includes confidentiality and use protections for CIRCIA reports and records created solely to prepare them; that does not make every underlying business record immune from discovery. See the statutory text.

How CIRCIA differs from the SEC cybersecurity disclosure rule

CIRCIA and the Securities and Exchange Commission’s cybersecurity disclosure rule address related risks but serve different purposes. CIRCIA is a government reporting framework for covered entities and covered incidents. The SEC rule requires public-company disclosures to investors, including disclosure of material cybersecurity incidents. Neither regime should be treated as a substitute for the other: CIRCIA’s critical-infrastructure reach includes entities that are not public companies, while its defined sectors do not include every public company.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Feature CIRCIA SEC cybersecurity disclosure rule
Primary recipient CISA and, through statutory sharing, appropriate federal agencies Investors and the market through public-company disclosures
Who and what trigger coverage Covered entities and covered cyber incidents under the final CISA rule; detailed boundaries remain unsettled as of September 28, 2026 SEC registrants, with incident disclosure tied to materiality
Timing Statutory framework: 72 hours for covered incidents and 24 hours for ransom payments, once the final rule takes effect Separate SEC filing requirements; not the CIRCIA reporting clock
Purpose Government situational awareness and response, with statutory protections for CIRCIA reports Investor-facing disclosure

The SEC’s 2023 adopting release says the agency received more than 150 comment letters on its own 2022 proposal, most focused on its proposed incident-disclosure requirement. That figure concerns the SEC proceeding, not the CIRCIA comment period. The SEC’s final rule release explains the distinction and the SEC rulemaking record.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What organizations can do while the final rule is pending

Organizations should not assume CIRCIA’s proposed details are already binding, but they can reduce confusion by mapping obligations that already apply and preparing to adapt when the final rule is published.

Best Value
  • Inventory existing federal, state, and sector-specific incident reporting duties that may apply to the organization, its operations, or its customers.
  • Separate government reporting from investor disclosure and other notification obligations; one filing should not be presumed to satisfy another regime.
  • Document how the organization identifies and escalates incidents, including who can assess whether an incident meets a reporting trigger.
  • Track CISA’s final rule and effective date, then compare the final definitions, covered-entity criteria, and reporting procedures with existing incident-response processes.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.