Skip to main content
CISSP-ISSAP · 20+ Years · #10 OnCon Icon, 2022
Back to BlogCompliance
CIRCIA Is Almost Law: What Critical Infrastructure CEOs Must Do Before the Final Rule Drops

CIRCIA Is Almost Law: What Critical Infrastructure CEOs Must Do Before the Final Rule Drops

CIRCIA's final rule drops September 2026—is your organization ready? Learn what critical infrastructure CEOs must do now to prepare for mandatory federal cyber incident reporting.

September 15, 202610 min readBy Adil Karam

Your regulatory clock is already running. CISA expects to publish the final CIRCIA rule in September 2026, and when the ink dries, covered entities across 16 critical infrastructure sectors will face mandatory federal cyber incident reporting for the first time in U.S. history. The organizations most exposed are not the ones with the most sophisticated threats. They are the hospitals, utilities, water systems, chemical companies, and financial firms that have never built a compliance program around a 72-hour reporting mandate, and whose boards have never formally owned that obligation.

The financial stakes are concrete.

A single healthcare breach averages $9.80 million, more than double the global average of $4.88 million.

Financial-services breaches cost an average of $6.3 million according to IBM's 2026 research.

Those numbers reflect incident costs alone. They do not include the legal fees, regulatory defense costs, and executive accountability exposure that CIRCIA noncompliance will layer on top. For a CEO or board member who assumes cyber reporting is a technical problem handled somewhere below the C-suite, this regulation should reset that assumption immediately.

CIRCIA does not ask whether your organization was prepared. It asks whether you reported correctly and on time. Those are two entirely different questions, and only one of them creates criminal exposure.

The Rule, the Scope, and the Enforcement Teeth

In July 2026, an updated preview of the Unified Agenda of Federal Regulatory and Deregulatory Actions confirmed that CISA plans to issue its final CIRCIA rule in September 2026, representing the most significant expansion of CISA's regulatory authority to date.

The proposed rule would require prompt reporting of cyber incidents and ransomware payments from an estimated 316,244 affected entities spanning the 16 critical infrastructure sectors.

Once the final rule is published and goes into effect, it will represent one of the most far-reaching U.S. cyber regulations ever implemented, applying across 16 critical infrastructure sectors ranging from electric utilities and water systems to hospitals and chemical facilities.

The regulation requires covered entities to report to CISA any covered cyber incident no later than 72 hours from the time the entity reasonably believes the incident occurred.

Ransomware payments must be reported to CISA within 24 hours.

The enforcement architecture is not a warning-letter framework.

The proposed rule creates enforcement mechanisms for CISA to obtain information from a covered entity about a covered cyber incident or ransom payment that the entity failed to report, including issuing a request for information, issuing a subpoena to compel disclosure, making a referral to the U.S. attorney general for a civil enforcement action, and initiating acquisition, suspension, and debarment procedures against entities that do business with the federal government.

The personal liability exposure reaches further still.

Information provided in response to a subpoena can be shared with the Department of Justice and other regulatory agencies for civil or criminal enforcement. That referral pathway cannot be appealed. And if false or fraudulent statements appear anywhere in a CIRCIA report or response, the exposure includes up to five years of imprisonment, and up to eight years if the offense involves terrorism.

The Operational Readiness Gap Most CEOs Do Not See

CIRCIA's clock starts the moment your team suspects something significant happened, not when forensics wrap up or when leadership convenes.

That single fact exposes the central readiness problem for most mid-market critical infrastructure organizations. The 72-hour window is not 72 hours from confirmed breach. It is 72 hours from reasonable belief. Most organizations do not have the triage, escalation, legal review, and reporting workflows in place to act at that speed, particularly for complex incidents that unfold across multiple systems simultaneously.

For a financial services firm with operations in both the United States and the European Union, the combined obligation may require alerting EU national authorities within 24 hours, filing a CIRCIA report with CISA within 72 hours, filing an intermediate NIS2 report within 72 hours, and satisfying sector-specific financial regulator requirements. The incident response team managing a ransomware attack at hour 20 post-discovery is simultaneously preparing four separate regulatory submissions to at least three jurisdictions, while also managing containment and communicating with executive leadership.

The scope is broad enough that many mid-market organizations in these industries will be covered entities under the final rules, and organizations that assumed CIRCIA applies only to large enterprises should verify that assumption against the final regulatory text.

Sector Coverage and Compliance Comparison

The following table maps key CIRCIA obligations against the current readiness posture typical for organizations across the most impacted sectors. CEOs should use this as a board-level conversation starter, not a definitive compliance assessment.

Sector72-Hr Reporting Obligation24-Hr Ransom ObligationExisting Federal Reporting OverlayCommon Readiness Gap
HealthcareYesYesHIPAA 60-day breach windowIR plan not calibrated to 72-hr trigger
Energy / UtilitiesYesYesNERC CIP (electricity)OT/IT incident classification unclear
Financial ServicesYesYesSEC 4-day material disclosureMulti-regulator coordination untested
Water / WastewaterYesYesEPA cybersecurity rulesLimited security staffing for 24/7 triage
Chemical FacilitiesYesYesDHS Chemical Facility regulationsNo formal IR plan in most mid-market firms
TransportationYesYesTSA cybersecurity directivesSubcontractor and supply chain coverage gaps

CIRCIA arguably mandates standards that many covered entities should already have: a Cybersecurity Incident Response Plan, a Cybersecurity Risk Assessment, and a Written Information Security Program.

The gap for most organizations is not awareness. It is program maturity at the speed CIRCIA demands.

Framework Alignment: What Standards Actually Map to CIRCIA

Boards and CEOs do not need to become cybersecurity experts. They do need to confirm that their security programs are built on defensible frameworks that align with CIRCIA's expectations. Three standards are directly relevant.

NIST Cybersecurity Framework 2.0 provides the foundational structure for identifying assets, protecting systems, detecting incidents, responding within defined timeframes, and recovering operations. CIRCIA's reporting obligations map directly to the "Respond" and "Recover" functions. If your organization cannot execute those functions within 72 hours, the framework gaps are visible and measurable.

ISO 27001 gives organizations a certified information security management system that documents controls, management accountability, and incident handling procedures. For organizations facing multi-regulatory environments, ISO 27001 certification creates a documented baseline that regulators across sectors recognize.

CISA's own CIRCIA guidance provides the authoritative source for covered entity definitions, incident reporting scope, and the regulatory docket. Every covered entity should have a designated owner monitoring this page.

CIS Controls, particularly Controls 13 (Incident Response Management) and 17 (Incident Response and Management), provide the operational checklist for building the detection and escalation workflows that make 72-hour reporting achievable.

AI-Enabled Attacks Are Shortening the Detection Window

IBM reported that 62% of AI-driven attacks in its study targeted critical-infrastructure sectors.

Faster, more automated attacks compress the time between initial access and significant impact, which means the 72-hour reporting clock may begin triggering before security teams realize an incident qualifies. Organizations that lack automated detection and alerting will struggle to meet CIRCIA deadlines on incidents that move at machine speed.

Simultaneous Regulatory Obligations Are Multiplying

CIRCIA does not replace existing sector-specific reporting requirements. It adds to them. Publicly traded covered entities may face simultaneous SEC materiality disclosure obligations. Healthcare organizations covered by HIPAA face overlapping timelines with entirely different definitions of a reportable event. Energy companies under NERC CIP must coordinate across multiple frameworks. Boards that treat these obligations as independent workstreams will find them unmanageable in an active incident. The answer is a unified incident response program with pre-mapped decision trees for each regulatory pathway, built before the first incident occurs.

Mid-Market Organizations Face Disproportionate Burden

Large enterprises with mature security programs and dedicated compliance teams will absorb CIRCIA with relative efficiency. Mid-market hospitals, regional utilities, and smaller chemical companies face the same obligations with a fraction of the staffing.

The 72-hour reporting clock creates a real problem for small to mid-market organizations.

This is precisely where a Fractional CISO delivers maximum value: program-level capability without the overhead of a full-time hire.

CIRCIA Readiness Checklist for CEOs and Boards

Use this checklist to assess your organization's exposure before the final rule takes effect. Each unchecked item represents a gap that creates enforcement risk from day one of the rule's effective date.

Coverage Assessment

  • [ ] Confirmed whether your organization meets CIRCIA's sector and size-based covered entity criteria
  • [ ] Reviewed the CISA NPRM's sector-specific definitions against your operational footprint
  • [ ] Identified all subsidiaries, affiliates, and joint ventures that may independently qualify
  • Incident Response Program

  • [ ] Updated Incident Response Plan to include a 72-hour CISA reporting workflow with named owners
  • [ ] Built a separate 24-hour ransomware payment decision and reporting protocol approved by the board
  • [ ] Defined the internal threshold for "reasonably believes a covered cyber incident has occurred"
  • [ ] Conducted a tabletop exercise simulating a ransomware event under CIRCIA timelines
  • Legal and Regulatory Coordination

  • [ ] Mapped overlapping reporting obligations (SEC, HIPAA, NERC CIP, state laws) to a single incident timeline
  • [ ] Confirmed legal counsel's role in reviewing CIRCIA reports before submission
  • [ ] Reviewed cyber insurance policy language for CIRCIA enforcement and regulatory defense coverage
  • Board Governance

  • [ ] Assigned board-level ownership of CIRCIA compliance accountability
  • [ ] Established a quarterly cyber governance reporting cadence to the board
  • [ ] Briefed the full board on CIRCIA enforcement exposure, including subpoena and DOJ referral authority
  • Reporting Infrastructure

  • [ ] Designated a specific individual as the CIRCIA reporting coordinator
  • [ ] Established a relationship with legal counsel experienced in federal cyber regulatory matters
  • [ ] Subscribed to CISA CIRCIA updates at cisa.gov/CIRCIA
  • How I Help

    Most critical infrastructure organizations facing CIRCIA do not need a full-time CISO at $400,000 per year. They need one immediately. That is the problem my Fractional CISO (vCISO) service solves. I embed as your senior security leader, assess your CIRCIA coverage status, build or retrofit your incident response program to meet 72-hour and 24-hour reporting requirements, and present your readiness posture directly to the board in language that executives understand. With 20+ years of experience across regulated sectors, I close the gap between where your program is today and where the regulation requires it to be before enforcement begins.

    For organizations that need to formalize their compliance posture across CIRCIA, HIPAA, NERC CIP, or SEC cybersecurity rules simultaneously, my Compliance Advisory service builds the integrated framework. For boards that want structured cyber governance and independent oversight of management's security reporting, my Board Advisory service provides that independent voice. If your organization is deploying AI tools within critical infrastructure environments, my Secure AI Deployment service addresses the security and governance obligations that come with that exposure. And for organizations with architectural gaps that undermine detection and response capability, my Security Architecture service builds the technical foundation that makes compliant incident response possible.

    See if I should be in the room

    #CIRCIA#Critical Infrastructure#Cyber Incident Reporting#CISA#Regulatory Compliance#Cybersecurity Law
    PDFShare:

    Adil Karam

    Security & AI Governance Advisor

    Helping organizations navigate security leadership and AI governance challenges.

    Ready to Put These Insights Into Action?

    Whether you need secure AI deployment, security leadership, or compliance guidance, we can apply these strategies to your organization.