Skip to main content
CISSP-ISSAP · 20+ Years · #10 OnCon Icon, 2022
Back to BlogCompliance
CIRCIA Is Almost Final: What Every C-Suite Leader Must Do Before September's Deadline

CIRCIA Is Almost Final: What Every C-Suite Leader Must Do Before September's Deadline

CIRCIA's final rule means a vendor's breach triggers your 72-hour reporting clock. C-suite leaders must act now before September's deadline to avoid penalties and regulatory exposure.

August 28, 202611 min readBy Adil Karam

Your vendor's systems get breached. Their network, their failure, their incident response team scrambling at midnight. You get a notification email the next morning. Under CIRCIA's final rule, that moment of notification is likely when your 72-hour reporting clock started. The breach is theirs. The reporting obligation, the penalties for missing the deadline, and the regulatory exposure on your balance sheet are yours.

The Cybersecurity and Infrastructure Security Agency expects to issue its final rule for CIRCIA in September 2026.

Every C-suite leader who has not yet run a formal readiness assessment is operating on borrowed time. And if your first action is to ask your IT team whether you even qualify as a covered entity, that delay is already a liability.

The assumption that "we're not critical infrastructure" is one of the most expensive assumptions in compliance today.

For utilities, this includes electric, water, and natural gas operators, as well as the contractors and service providers that support them. Many organizations that have never considered themselves to be in the critical infrastructure sector will find themselves squarely within scope under CIRCIA's broad sector definitions.

A food distributor, a commercial SaaS provider, a chemical supplier, a cloud hosting company:

SaaS vendors serving healthcare systems, cloud providers hosting financial data, logistics platforms managing supply chains; none of these companies think of themselves as critical infrastructure. Under this rule, they might be.

What CIRCIA Actually Requires

CIRCIA was signed into law in March 2022 and directs CISA to develop and implement regulations requiring covered entities to report covered cyber incidents and ransomware payments.

Once the final rule is published and goes into effect, it will represent one of the most far-reaching U.S. cyber regulations ever implemented. The rules apply across 16 critical infrastructure sectors, ranging from electric utilities and water systems to hospitals and chemical facilities. Under the regulations, covered entities must report cyber incidents to CISA within 72 hours and ransomware payments within 24 hours.

CISA estimated that 316,244 entities would be potentially affected, including businesses, government entities, and other organizations.

That is not a niche regulation targeting a narrow slice of the economy. That is a compliance obligation affecting a significant portion of mid-market and enterprise America.

The financial consequences of non-compliance are not ambiguous.

CISA is authorized to compel information from non-reporting entities through subpoena, and penalties for non-compliance can escalate to $500,000 per day.

Beyond civil penalties,

CISA can refer noncompliance to the DHS Suspension and Debarment Official, putting a company's ability to do business with the federal government at risk.

For organizations with federal contracts or grant relationships, that is an existential consequence, not just a line-item fine.

Coverage criteria operate on two tracks.

The first is size-based: any entity operating in a critical infrastructure sector that exceeds the Small Business Administration's small business size standards is covered. Those thresholds vary by industry, generally ranging from 100 to 1,500 employees or between $2.25 million and $47 million in annual revenue, depending on the sector. If you clear those thresholds and you are in a covered sector, you are in scope.

The second track is sector-based criteria, which can capture entities regardless of size. Under the proposed rule, 16 specific categories of businesses are covered no matter how small because of the outsized risk their disruption would pose.

The Supply Chain Provision Changes Everything

This is the provision that should keep every CEO and CFO awake.

A breach at one of your vendors, MSPs, or cloud providers that results in unauthorized access to your systems is a covered incident under CIRCIA.

The reporting obligation does not sit with the vendor. It sits with you.

The 72-hour clock starts when you "reasonably believe" a covered incident has occurred, not when your investigation confirms it. That distinction matters enormously for how quickly your internal escalation processes need to move.

Most organizations' vendor notification processes, legal review cycles, and escalation chains were not built for that speed. The average company does not have real-time visibility into what a third-party vendor is doing on their systems at 2:00 a.m.

The supply chain provision is not just a reporting requirement. It is a forcing function that demands organizations build continuous third-party visibility, enforceable contractual notification SLAs, and 24/7 detection capabilities, because without all three, you cannot even know your clock has started.

CIRCIA compliance intersects directly with your bottom line through cyber insurance. Standard cyber liability policies contain compliance exclusions. If your organization experiences a major cyber incident and fails to notify CISA within the mandatory 72-hour window or fails to satisfy CIRCIA's two-year log-preservation requirements, your insurer can dispute or deny the claim.

That is a direct, measurable financial exposure that belongs in every board risk discussion happening right now.

CIRCIA Coverage and Penalty Exposure at a Glance

RequirementObligationConsequence of Non-Compliance
Substantial cyber incident reportFile with CISA within 72 hours of reasonable beliefUp to $500,000/day in civil penalties
Ransomware payment reportFile with CISA within 24 hoursSame penalty structure; CISA subpoena authority
Supply chain breachCovered entity (YOU) must report, not vendorClock starts at notification, not investigation completion
CISA Request for InformationRespond within 72 hoursEscalation to DOJ subpoena enforcement
False or fraudulent statementsProhibited in all reports and RFI responsesFines plus up to five years imprisonment
Federal contractor statusSuspension and debarment riskLoss of ability to conduct business with federal government

Framework Alignment: What Good Looks Like

CIRCIA readiness does not require building a program from scratch. Organizations that have invested in security architecture aligned to recognized frameworks already have a head start, but that head start only converts to compliance if the right capabilities are verified and tested against CIRCIA's specific triggers.

NIST CSF 2.0, updated in February 2024, organizes security work into six functions: Govern, Identify, Protect, Detect, Respond, and Recover.

The Govern function was added in the 2.0 update to make risk management strategy and oversight an explicit organizational capability.

CIRCIA maps most directly to the Detect and Respond functions. An organization that cannot detect a supply chain compromise in near real-time and escalate to a reportable determination within hours will fail the 72-hour window regardless of how well-documented its policies are.

ISO 27001:2022 Annex A controls around incident management, supplier relationships (A.5.19 through A.5.22), and information security event reporting give organizations a structured baseline.

Compliance frameworks like DORA, ISO 27001, and NIST CSF 2.0 require organizations to document recovery time objectives and recovery point objectives that reflect the impact of downtime or data loss on essential services. When defined and tested, these objectives provide evidence of both resilience and regulatory alignment.

CIS Controls v8 Control 17 (Incident Response Management) and Control 15 (Service Provider Management) are directly relevant. Organizations that have not implemented mature supplier assessment processes against Control 15 will have no way to monitor third-party access in a manner that satisfies CIRCIA's supply chain reporting trigger.

The key insight for executives is this: CIRCIA is not asking organizations to do something entirely new. It is asking them to prove that what they claim to do actually works at the speed the regulation demands. That proof requires testing, not documentation.

AI-Accelerated Threat Detection Becomes Table Stakes

The 72-hour clock only works in your favor if your detection capability is faster than the attacker's dwell time. AI-powered security operations tools are closing the gap between initial compromise and detection, but only for organizations that have invested in them. Companies that still rely on manual log review and weekly security reports will not achieve the "reasonable belief" determination quickly enough to meet the window. This is where Secure AI Deployment intersects with regulatory compliance directly: the same AI governance discipline that ensures responsible model use also accelerates threat detection when applied to security operations.

Board-Level CIRCIA Reporting Becomes a Governance Expectation

Reporting under CIRCIA is intended to allow CISA to rapidly deploy resources and assistance to victims of cyberattacks, analyze incoming reports across sectors to identify trends, and share that information with network defenders so they can take steps to protect themselves from similar incidents.

That public-sector mission translates to a private-sector governance obligation. Boards that receive quarterly security briefings are increasingly asking for specific evidence of incident reporting readiness, not generic assurances. A board advisory function that translates CIRCIA exposure into financial risk language is no longer optional for covered entities.

M&A Due Diligence Now Includes CIRCIA Readiness Scoring

Acquirers and enterprise procurement teams are beginning to score CIRCIA readiness as part of vendor risk assessments and acquisition due diligence. An organization that cannot produce a documented 72-hour incident reporting playbook, evidence of supply chain monitoring capabilities, and a sector classification analysis faces material risk of deal friction, pricing discounts, or procurement disqualification. CIRCIA readiness is becoming a business development asset, not just a compliance checkbox.

Cyber Insurance Underwriting Tightens Around Reporting Capability

Insurers are already conditioning renewals on demonstrable incident response infrastructure. Organizations that cannot show a CIRCIA-specific tabletop exercise, a tested escalation workflow, and mapped vendor notification SLAs will face premium increases, coverage exclusions, or non-renewal at their next policy cycle. The insurance market is not waiting for enforcement to begin.

Your CIRCIA Readiness Checklist

Work through this assessment before September. Every "No" answer is an open exposure.

Scope and Classification

  • [ ] Have you formally mapped your organization to one or more of the 16 critical infrastructure sectors defined under Presidential Policy Directive 21?
  • [ ] Have you applied both the size-based and sector-based covered entity criteria to your current organizational structure?
  • [ ] Have you evaluated whether subsidiaries, affiliates, or acquired entities introduce independent CIRCIA coverage?
  • Supply Chain and Third-Party Visibility

  • [ ] Do your vendor contracts include mandatory breach notification SLAs of less than 24 hours?
  • [ ] Do you have real-time or near real-time visibility into third-party access to your systems?
  • [ ] Have you inventoried every MSP, cloud provider, and software vendor that touches your environment?
  • Detection and Escalation

  • [ ] Does your incident response plan explicitly define the "reasonable belief" trigger that starts the 72-hour clock?
  • [ ] Have you tested that trigger in a tabletop exercise with legal, IT, and executive stakeholders in the room?
  • [ ] Do you have 24/7 monitoring capability sufficient to detect a supply chain compromise during off-hours?
  • Reporting Infrastructure

  • [ ] Have you built or designated a CISA reporting workflow with tested authentication and submission procedures?
  • [ ] Have you established a two-year log retention capability as expected under the proposed rule?
  • [ ] Does your board receive CIRCIA-specific risk reporting at least quarterly?
  • Governance and Accountability

  • [ ] Is there a named senior executive accountable for CIRCIA compliance?
  • [ ] Has legal counsel reviewed your incident classification criteria against CIRCIA's "substantial cyber incident" definition?
  • [ ] Does your cyber insurance policy contain language that could create a coverage exclusion for missed CIRCIA reporting deadlines?
  • A "No" on more than three of these items indicates material exposure that requires immediate attention, not a Q1 planning cycle.

    How I Help

    Most organizations have not yet determined whether they fall within CIRCIA's covered entity definitions, and the supply chain provisions mean the answer is almost certainly yes for any mid-market or enterprise company operating in or supporting one of the 16 sectors. That gap will not close on its own, and it will not close in time if you wait until the final rule is published to start.

    My Fractional CISO (vCISO) service is purpose-built for exactly this moment. I run a CIRCIA scope assessment that produces a formal covered entity determination, maps your existing controls against the 72-hour reporting requirements, and identifies the precise gaps in your detection, escalation, and supply chain visibility capabilities. I then build your incident reporting playbook, design and facilitate a CIRCIA-specific tabletop exercise with your legal, IT, and procurement teams, and present your board with a readiness roadmap that translates regulatory exposure into financial risk language they can act on. You get senior security leadership quarterbacking your readiness program right now, without a nine-month CISO hiring cycle standing between you and enforcement.

    For organizations that need ongoing regulatory alignment across CIRCIA and other federal frameworks, my compliance services provide continuous program management. If your board needs structured security briefings that address CIRCIA alongside broader enterprise risk, my board advisory engagement delivers that governance layer. And for organizations evaluating AI tooling to accelerate their detection and response capabilities, Secure AI Deployment ensures those investments are governed and effective before enforcement begins.

    The one thing that will not change is the pair of deadlines at the rule's core. The 72-hour and 24-hour clocks are written into the statute itself; no amount of rulemaking can soften them.

    September is not a planning horizon. It is a deadline.

    See if I should be in the room

    #CIRCIA#Cybersecurity Compliance#Incident Reporting#C-Suite Leadership#CISA#Regulatory Deadlines
    PDFShare:

    Adil Karam

    Security & AI Governance Advisor

    Helping organizations navigate security leadership and AI governance challenges.

    Ready to Put These Insights Into Action?

    Whether you need secure AI deployment, security leadership, or compliance guidance, we can apply these strategies to your organization.