Skip to main content
CISSP-ISSAP · 20+ Years · #10 OnCon Icon, 2022
Back to BlogBoard Advisory
CIRCIA Is Here: What the Final Mandatory Incident Reporting Rule Means for Your Board

CIRCIA Is Here: What the Final Mandatory Incident Reporting Rule Means for Your Board

CIRCIA's final rule is coming—and it's broader than SEC cyber rules. Here's what board members need to know about mandatory incident reporting, deadlines, and criminal penalties.

September 7, 202610 min readBy Adil Karam

Your board has probably spent the last two years focused on SEC cyber disclosure rules. That focus made sense in 2023. It is no longer sufficient. With CISA's final rule under the Cyber Incident Reporting for Critical Infrastructure Act expected to publish this month,

the Cybersecurity and Infrastructure Security Agency is set to issue one of the most far-reaching U.S. cyber regulations ever implemented.

The voluntary era of incident sharing is over. What replaces it carries criminal penalties, DOJ referral authority, and a clock that starts ticking before your forensic team finishes its first call.

Most boards that govern critical infrastructure companies have not internalized what this shift actually means for them personally. It means that the question of whether and when to report a cyber incident is no longer a discretionary risk management judgment. It is a legal obligation with an enforcement mechanism, and the board owns the governance structure that either enables compliance or exposes the organization to compounding liability across multiple regulators simultaneously.

What CIRCIA Actually Requires

CISA has been finalizing regulations to implement CIRCIA, with a final rule expected in September 2026. The rule will require covered critical infrastructure entities to report covered cyber incidents to CISA within 72 hours and ransom payments within 24 hours.

The proposed rule would require prompt reporting from an estimated 316,244 affected entities spanning the 16 critical infrastructure sectors, including chemical, communications, energy, financial services, food and agriculture, healthcare, and infrastructure.

If your company operates in any of these sectors and exceeds the SBA size threshold, you are almost certainly a covered entity.

Two specific mechanics matter enormously to boards. First,

the 72-hour reporting clock is measured from when an entity "reasonably believes" a covered incident has occurred, not from when an investigation confirms it.

That distinction collapses the timeline your legal and security teams believed they had. Second,

covered entities must report any ransom payment resulting from a ransomware attack to CISA within 24 hours, a requirement designed to assist authorities in tracking and analyzing ransomware trends and patterns.

That 24-hour window means the board's most sensitive crisis decision, whether to pay, becomes visible to a federal agency almost in real time.

CIRCIA does not give boards a grace period for deliberation. The clock starts the moment your organization reasonably believes something significant happened, and the reporting obligation follows the belief, not the confirmation.

The Enforcement Teeth Boards Are Not Discussing

This is not a framework with soft guidance and voluntary compliance.

CIRCIA creates enforcement mechanisms for CISA to obtain information from a covered entity that failed to report, including issuing a request for information, issuing a subpoena to compel disclosure, making a referral to the U.S. attorney general for a civil enforcement action, and initiating acquisition, suspension, and debarment procedures against entities that do business with the federal government.

If a covered entity fails to comply with a subpoena, CISA could refer the matter to the attorney general to bring a civil action to enforce the subpoena, and a U.S. district court may order compliance and punish noncompliance as contempt of court.

For boards that govern federal contractors, the exposure extends further:

CISA can refer noncompliance to the DHS Suspension and Debarment Official, putting a company's ability to do business with the federal government at risk.

The federal government intends to impose criminal and civil liability on individuals, including corporate employees reporting on behalf of a covered entity, who interfere with CISA's ability to obtain accurate information.

Directors who authorize or condone a deliberate failure to report face personal, not just institutional, exposure.

CIRCIA compliance also protects organizations from steep penalties, which can escalate to $500,000 per day for non-compliance.

The Multi-Regulator Collision Course

The most underappreciated board-level risk is not CIRCIA in isolation. It is CIRCIA colliding with every other disclosure obligation your organization already carries. Consider the timeline arithmetic a covered, publicly traded healthcare company now faces during an active incident:

Regulatory RegimeReporting TriggerDeadlineRegulator
CIRCIAReasonable belief incident occurred72 hoursCISA
CIRCIA (Ransomware)Ransom payment made24 hoursCISA
SEC Form 8-KMateriality determination4 business daysSEC
Banking AgenciesDetermination of notification incident36 hoursOCC / Fed / FDIC
HIPAA Breach NotificationDiscovery of breach60 daysHHS OCR
GDPRAwareness of personal data breach72 hoursSupervisory Authority

The SEC's cybersecurity disclosure rule, HIPAA's breach notification requirements, TSA's pipeline and aviation sector directives, and various financial sector reporting obligations all exist in a partially overlapping regulatory space. Harmonizing CIRCIA reporting with existing requirements, so that a single incident does not require simultaneous reports to five different agencies in five different formats, is a significant challenge.

To the extent that state privacy or insurance laws excuse or permit entities to delay notification of cyber incidents, the SEC will still require entities to timely disclose such incidents in Form 8-K.

The regulators are not coordinating for you. That coordination is your problem, and it must be solved before the incident, not during it.

Framework Alignment: Where CIRCIA Sits in Your Governance Architecture

Boards seeking a structured approach to CIRCIA compliance should map their existing governance posture against established frameworks before the rule takes effect.

NIST Cybersecurity Framework 2.0 introduced "Govern" as a core function, explicitly elevating incident response oversight to the board level. CIRCIA operationalizes that governance requirement with legal weight. Your incident response plan must address detection thresholds, escalation paths to the board, and authorized reporting spokespersons.

ISO 27001:2022 Annex A Control 5.25 (Assessment and decision on information security events) and Control 5.26 (Response to information security incidents) directly support CIRCIA's triggering mechanism. Organizations with certified ISMS programs should audit their classification criteria against CIRCIA's "covered incident" definition now.

CIS Controls v8, specifically Controls 17 (Incident Response Management) and 13 (Network Monitoring and Defense), provide the operational foundation for meeting the 72-hour clock. The control gaps most likely to cause a reporting failure are detection latency and unclear escalation authority.

The board's governance question is not whether these frameworks exist inside the organization. It is whether the incident response governance chain, from the security operations center to the general counsel to the board chair, has a single, documented, pre-authorized decision tree that accounts for all applicable reporting obligations simultaneously.

Emerging Dimensions Boards Must Track in the Next 90 Days

The Ransomware Payment Governance Problem

When ransomware strikes, the board typically convenes an emergency session and faces a binary choice under extreme time pressure. Under CIRCIA, that decision now has a 24-hour federal disclosure consequence attached to it. Boards that have not pre-established a ransomware payment policy, including OFAC sanctions screening protocols for threat actor attribution, will be making a governance decision and a federal disclosure decision at the same moment, under duress, without a framework. That is an unacceptable risk posture.

Interaction With Cyber Insurance Coverage

Standard cyber policy language covers regulatory defense in connection with data breach notification laws, but whether that language extends to CIRCIA enforcement is not always clear. The regulatory defense provisions of many policies were written before CIRCIA's rulemaking was finalized. Covered entities should ask specifically whether their policy covers legal costs and regulatory defense in connection with CIRCIA reporting obligations and CISA enforcement.

Information Sharing Protections and Their Limits

CISA has confirmed that CIRCIA reports are protected from civil litigation use and from Freedom of Information Act disclosure. However, the interaction between CIRCIA reports and subsequent law enforcement investigations, SEC disclosure obligations for public companies, and state data breach notification requirements has not been fully litigated.

Boards governing publicly traded companies cannot treat CIRCIA's confidentiality protections as a shield against SEC disclosure obligations. The two regimes serve different purposes and operate independently.

The Scale of Industry Impact

CIRCIA produced more than 260,000 comment submissions in response to the proposed rule, spanning trade associations, major critical infrastructure operators, cybersecurity vendors, legal practitioners, and foreign governments.

That volume signals the breadth of affected industries.

The estimated total cost to industry is $2.6 billion over 11 years, with $1.4 billion in direct reporting costs.

The organizations that build the governance infrastructure now will absorb this cost as a known compliance line item. Those that wait will absorb it as emergency remediation plus enforcement response.

Board Readiness Checklist: 90-Day Action Plan

Use this checklist in your next board meeting or audit committee session. Every "No" answer represents a material governance gap.

Readiness QuestionStatus
Has the board confirmed the organization is a covered entity under CIRCIA's sector and size criteria?Yes / No
Does the incident response plan include a named, board-authorized reporting decision owner?Yes / No
Does the IR plan include a unified disclosure decision tree that accounts for CIRCIA, SEC, HIPAA, GDPR, and banking rules simultaneously?Yes / No
Has the board reviewed and approved a ransomware payment policy that includes OFAC screening and pre-authorized reporting thresholds?Yes / No
Has legal counsel confirmed current cyber insurance covers CIRCIA-related regulatory defense costs?Yes / No
Has the organization mapped its NIST CSF 2.0 "Govern" function against CIRCIA's triggering and reporting requirements?Yes / No
Has the board received a presentation on CIRCIA that quantifies the financial exposure of non-compliance in dollar terms?Yes / No
Has a tabletop exercise simulated a covered incident under the 72-hour CIRCIA clock, the SEC 4-business-day clock, and any applicable sector-specific timelines simultaneously?Yes / No

If your board cannot answer "Yes" to at least six of these eight questions before the final rule goes into effect, your organization is operationally unprepared for compliance. Preparation is not a security team problem. It is a governance problem, and it sits squarely on the board's agenda.

For deeper context on CIRCIA's regulatory framework and timeline, CISA's official CIRCIA resource page is the authoritative source. For enforcement mechanism detail, review CISA's NPRM Overview_508c%20(locked).pdf) and the Congressional Research Service's CIRCIA brief.

How I Help

Most boards have no incident reporting decision tree that accounts for CIRCIA, SEC, HIPAA, and sector-specific obligations simultaneously. Through my Board Advisory service, I build that governance framework from scratch: I map your organization's full regulatory disclosure matrix, quantify the financial exposure of non-compliance in terms your CFO and audit committee can act on, and deliver a board-ready presentation that explains exactly what changed, who is liable, and what the 90-day remediation plan looks like. I run the cross-functional tabletop exercise that tests your leadership team before your first reportable incident, not after. Directors leave that session with a signed, board-approved disclosure decision tree and a clear understanding of personal exposure.

For organizations that need the underlying compliance infrastructure built alongside the board-level governance, my Compliance service delivers the incident classification criteria, regulatory overlap mapping, and documented procedures that make the 72-hour clock achievable. My vCISO service provides ongoing security leadership to sustain that posture between incidents. If your organization is also managing AI-driven systems across critical infrastructure, my Secure AI Deployment service ensures those systems are accounted for in your incident scope and reporting obligations. And for organizations that need a full architectural assessment of detection and escalation capabilities, my Security Architecture service identifies the control gaps most likely to cause a reporting failure under time pressure.

See if I should be in the room

#CIRCIA#Incident Reporting#Critical Infrastructure#CISA#Board Governance#Cyber Compliance
PDFShare:

Adil Karam

Security & AI Governance Advisor

Helping organizations navigate security leadership and AI governance challenges.

Ready to Put These Insights Into Action?

Whether you need secure AI deployment, security leadership, or compliance guidance, we can apply these strategies to your organization.