Skip to main content
CISSP-ISSAP · 20+ Years · #10 OnCon Icon, 2022
Back to BlogCompliance
The CIRCIA Deadline Is Here: What Every Executive Needs to Do Before the Final Rule Hits

The CIRCIA Deadline Is Here: What Every Executive Needs to Do Before the Final Rule Hits

CIRCIA's final rule arrives in 2026. Is your organization ready to report cyber incidents within 72 hours? Here's what executives must do now to avoid costly compliance failures.

September 14, 202611 min readBy Adil Karam

Your company's attorneys are not your first call when a breach happens at 2 a.m. on a Saturday. Your incident response team is. And if you don't have one that's been tested, documented, and mapped to a 72-hour reporting clock, CIRCIA's final rule will find that gap before you do.

CISA is finalizing regulations to implement the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA), with a final rule expected in September 2026.

After years of delays, missed statutory deadlines, and a DHS funding lapse that disrupted planned stakeholder town halls, the rule is in its final stretch.

Once published and in effect, it will represent one of the most far-reaching U.S. cyber regulations ever implemented.

The executives who treat this moment as background noise are the same ones who will spend their first 90 days under the rule managing a compliance violation instead of a business.

The stakes are not abstract.

The federal government intends to impose criminal and civil liability on individuals, including corporate employees reporting on behalf of a covered entity, who interfere with CISA's ability to obtain accurate information.

This is not a checkbox exercise. It is a governance obligation that runs from the boardroom to the security operations center. Organizations without a dedicated security leader have no credible chain of command to execute a compliant response when the clock starts. That is where most mid-market companies sit right now, and that is exactly the problem this post addresses.


What CIRCIA Actually Requires

CIRCIA represents the most significant expansion of CISA's regulatory authority to date, directing the agency to mandate that covered critical infrastructure entities report substantial cyber incidents within 72 hours and ransomware payments within 24 hours.

The core operational challenge lies in the compressed timelines: reporting a substantial cyber incident within 72 hours, or a ransomware payment within 24 hours, requires immediate visibility into complex IT and operational technology environments.

For large-scale organizations, this means incident response workflows can no longer wait for full forensic confirmation or extended leadership deliberations before triggering formal regulatory notification protocols.

The one thing that will not change is the pair of deadlines at the rule's core. The 72-hour and 24-hour clocks are written into the statute itself; no amount of rulemaking can soften them.

Beyond timing, covered entities must provide substantive information when they report.

Covered entities will need to track and retain specific details of incidents, including a timeline, technical indicators, and any information that could help identify the attackers.

The information CISA asks of those entities is wide-ranging and includes a description of security defenses the entity had in place at the time of the incident.

Compliance with CIRCIA is not about filing a form. It is about having the people, processes, and telemetry in place to make a well-informed, accurate report within 72 hours of a breach, under pressure, with legal consequences for getting it wrong.

Who Is Actually Covered: The Mid-Market Blind Spot

This is where most executive teams make their first mistake. They assume CIRCIA covers utilities, hospitals, and defense primes. They are partially right, and dangerously incomplete.

The 16 critical infrastructure sectors are: Chemical, Commercial Facilities, Communications, Critical Manufacturing, Dams, Defense Industrial Base, Emergency Services, Energy, Financial Services, Food and Agriculture, Government Facilities, Healthcare and Public Health, Information Technology, Nuclear Reactors Materials and Waste, Transportation Systems, and Water and Wastewater Systems.

SaaS vendors serving healthcare systems, cloud providers hosting financial data, logistics platforms managing supply chains: none of these companies think of themselves as critical infrastructure. Under this rule, they might be.

A common and dangerous misconception is the assumption that only Fortune 500 and enterprise organizations are covered. Small and mid-market organizations absolutely can be covered entities under CIRCIA.

Size thresholds vary by industry, generally ranging from 100 to 1,500 employees or between $2.25 million and $47 million in annual revenue, depending on the sector.

Clear those thresholds in a covered sector, and you are in scope. But size is only one track.

The second track is sector-based criteria, which can capture entities regardless of size. Under the proposed rule, 16 specific categories of businesses are covered no matter how small, because of the outsized risk their disruption would pose.

CISA has published a Covered Entity Fact Sheet to help organizations self-assess. Use it this week, not after the final rule publishes.

Covered Entity TypeCovered By Size?Covered By Sector?Example
Regional hospital (500 employees)YesYesHealthcare & Public Health
SaaS company serving financial clientsYesPossiblyInformation Technology
Food distributor ($50M revenue)YesYesFood & Agriculture
Regional IT managed service providerYesYesInformation Technology
40-person water utilityNo (SBA exempt)YesWater & Wastewater Systems
Federal contractor (any sector)YesPossiblyDefense Industrial Base

The scope is broad enough that many mid-market organizations in these industries will be covered entities under the final rules, and organizations that assumed CIRCIA applies only to large enterprises should verify that assumption against the final regulatory text.


The Enforcement Reality No One Is Talking About

Some executives assume they can wait and see. That is a solvable misunderstanding. The enforcement architecture under CIRCIA removes the luxury of strategic delay.

CISA can issue subpoenas to compel information from entities that don't report.

In cases of noncompliance with a request for information or a subpoena, CISA reserves the right to refer cases to the attorney general for civil actions or to pursue other punitive measures against the individuals involved, such as contempt of court, penalties, suspension, or disbarment.

The exposure does not stop at the corporate level.

Penalties for providing false statements or representations include fines, imprisonment of up to five years, or, if the offense involves international or domestic terrorism, imprisonment of up to eight years.

For federal contractors, the consequences extend further. CISA can refer noncompliance to the DHS Suspension and Debarment Official, putting a company's ability to do business with the federal government at risk.

This is the conversation your D&O insurer is already having without you. Carriers are adding CIRCIA-specific readiness questions to renewal applications. Organizations that cannot demonstrate a documented 72-hour reporting workflow face premium increases or coverage declination. That is a CFO problem, not just a CISO problem.


Framework Alignment: What "Ready" Actually Looks Like

CIRCIA does not exist in isolation.

The SEC's 2023 cybersecurity disclosure rule, HIPAA's breach notification requirements, TSA's pipeline and aviation sector directives, and various financial sector reporting obligations all exist in a partially overlapping regulatory space.

Harmonizing CIRCIA reporting with existing requirements, so that a single incident does not require simultaneous reports to five different agencies in five different formats, is a significant drafting challenge.

Organizations that have aligned their incident response programs to NIST CSF 2.0, ISO 27001:2022, and CIS Controls v8 have the strongest foundation. Here is how those frameworks map to CIRCIA's operational demands:

Framework Control AreaCIRCIA Requirement SupportedGap for Most Mid-Market Orgs
NIST CSF: Detect (DE)Identify "reasonable belief" trigger pointNo continuous monitoring baseline
NIST CSF: Respond (RS)Execute 72-hour reporting workflowNo documented decision tree
ISO 27001: A.5.26Response to information security incidentsPlans exist but untested
CIS Control 17Incident response and managementIR plan not mapped to CIRCIA thresholds
CIS Control 8Audit log managementRetention schedules don't match CIRCIA requirements

The most practical step is to map existing incident response procedures to CISA's 72-hour, 24-hour, and supplemental-report triggers. A covered organization should maintain an incident decision tree that separates reportable covered cyber incidents from non-reportable events.


Regulatory Layering Is Getting Worse Before It Gets Better

CISA is also empowered to compel information from covered entities about unreported cyber incidents or ransom payments that fall outside its proposed reporting requirements.

This investigative authority, combined with SEC material incident disclosure rules and state breach notification laws, means a single ransomware event can now trigger four or five concurrent reporting obligations with different timelines, different formats, and different agency recipients. Organizations without a security leader who can orchestrate that response will fail at least one of them.

Supply Chain Exposure Is a Covered-Entity Problem

A breach at a third-party vendor can create a reportable incident obligation for a covered entity, even if the covered entity's own systems were not directly compromised.

This has immediate implications for vendor risk management programs. Supplier contracts must now include incident notification obligations aligned to your CIRCIA timelines, not just standard breach notification clauses.

The Scope Debate Is Not Over

CIRCIA attracted more than 260,000 submissions in response to the proposed rule, spanning trade associations, major critical infrastructure operators, cybersecurity vendors, legal practitioners, and foreign governments.

CISA has signaled it will narrow the covered-entity definition in the final rule, but "narrowing" is relative to a starting position that captured an estimated 316,000 entities.

Organizations should treat the proposed rule as the planning baseline, not the final legal text.


Your CIRCIA Readiness Checklist

Execute these steps before the final rule takes effect. Each item maps directly to a violation risk in the first 90 days of enforcement.

Step 1: Determine Coverage Status

  • [ ] Pull your NAICS code and compare it against SBA size standards for your sector
  • [ ] Map your operations against all 16 PPD-21 critical infrastructure sectors
  • [ ] Document your coverage determination with legal sign-off
  • Step 2: Assess Your Incident Response Plan

  • [ ] Confirm your IR plan includes a written 72-hour reporting decision tree
  • [ ] Assign named individuals (not roles) to own the CISA notification workflow
  • [ ] Add a 24-hour ransomware payment reporting protocol to your playbook
  • [ ] Conduct a tabletop exercise that simulates a 2 a.m. ransomware event
  • Step 3: Fix Your Logging and Retention

  • [ ] Confirm log retention meets CIRCIA's evidence preservation requirements
  • [ ] Validate that OT/ICS environments have the same visibility as IT systems
  • [ ] Ensure your SOC or MDR provider can produce the technical indicators CISA will require
  • Step 4: Close the Leadership Gap

  • [ ] Identify who holds accountability for the CIRCIA report decision
  • [ ] Confirm your security leader has authority to engage legal, communications, and the board within the first hour of a qualifying incident
  • [ ] If you have no dedicated security leader, address this before the rule takes effect
  • Step 5: Align Cyber Insurance and Vendor Contracts

  • [ ] Review your policy renewal application for CIRCIA-specific questions
  • [ ] Update vendor agreements to require incident notification within your CIRCIA timelines
  • [ ] Confirm D&O coverage extends to regulatory reporting failures
  • You can also review CISA's official CIRCIA FAQ page and the Federal Register NPRM filing as authoritative planning references.


    How I Help

    With 20+ years of experience leading security programs across critical infrastructure sectors, I step in as your Fractional CISO (vCISO) to build and own exactly what CIRCIA demands: a documented, tested, board-reported security program with the incident response architecture to execute a compliant 72-hour report under real-world conditions. I work directly with your CEO and board to close the leadership gap that makes first-90-day violations most likely, without the cost or delay of a full-time executive hire.

    For organizations that need to formalize their regulatory posture across CIRCIA, SEC, HIPAA, and other overlapping frameworks, my Compliance Advisory service turns that complexity into a unified, auditable program. If your board needs structured education and governance oversight on cybersecurity risk, Board Advisory is the engagement designed for that conversation. For organizations building or scaling technology infrastructure, Security Architecture ensures your environment is built to support the detection and logging CIRCIA requires. And if your organization is deploying AI tools across operations, Secure AI Deployment addresses the governance layer those tools require.

    See if I should be in the room

    #CIRCIA#Incident Response#Critical Infrastructure#Cybersecurity Compliance#CISA#Breach Reporting
    PDFShare:

    Adil Karam

    Security & AI Governance Advisor

    Helping organizations navigate security leadership and AI governance challenges.

    Ready to Put These Insights Into Action?

    Whether you need secure AI deployment, security leadership, or compliance guidance, we can apply these strategies to your organization.