The Cybersecurity and Infrastructure Security Agency (CISA) plans to release its final rule for the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) this September. If that happens, infinite companies across 16 critical infrastructure sectors will suddenly be looking at enforceable reporting deadlines by late 2026 or early 2027.
On paper, the rule is simple enough: 72 hours to report a covered cyber incident, 24 hours to report a ransomware payment. The hard part isn’t the deadline itself — it’s everything that has to happen before a company even realizes the clock has started.
Too many organizations have treated CIRCIA as something to keep an eye on rather than something to actually build a program around. That’s a harder position to defend the closer we get to a final rule. Well before it shows up in the Federal Register, a company should already know who gets the first call when security spots something, who decides whether it’s reportable, and who’s responsible for pulling together every other notification that might also be required.
What came out of CISA’s June sessions
CISA held virtual town halls in June, and industry mostly raised the same issues that have been floating around since the proposed rule dropped: How broadly “covered entity” is defined, what actually counts as a “substantial cyber incident,” how much information CISA might ask for, and how all of this overlaps with reporting rules that already exist.
The scope question is the big one. Under the proposed rule, CISA itself estimated over 300,000 entities could end up covered — largely because the criteria lean on sector categories and Small Business Administration size thresholds rather than anything more targeted.
Industry has been pushing back, asking CISA to think about this in more functional terms — less “How many employees do you have?” and more “How important is what you do to a critical service or supply chain?” Whether that argument moves the needle in the final rule is genuinely unclear. But no company should assume it’ll land outside the scope just because it doesn’t think of itself as critical infrastructure. Plenty of businesses that provide tech, operations support, logistics, cloud services, engineering, or communications to a critical infrastructure customer will get pulled in anyway.
The ransomware payment deadline is its own headache. Realistically, a company weighing whether to pay is usually in the middle of chaos — an active operational crisis, an insurer on the line, forensic advisers digging in, law enforcement involved, executives asking questions, maybe customers too. There needs to be a fast, clear path for that information to reach legal and the people who actually make the call.
The real problem isn’t CIRCIA — it’s everything around it
For most companies, CIRCIA won’t be the hard part on its own. The hard part is CIRCIA stacked on top of whatever reporting obligations already exist.
Take a defense contractor already working through the Defense Federal Acquisition Regulation Supplement (DFARS) reporting — also 72 hours, plus evidence preservation duties — while gearing up for CMMC. Or an energy company juggling the North American Electric Reliability Corporation (NERC), the Energy Department’s form OE-417 process, and — if pipelines are involved — Transportation Security Administration directives. Sometimes the very first notification due isn’t a CIRCIA report at all; it’s a call to TSA or DOE.
Financial services has its own tangle: federal banking regulators’ 36-hour rule, New York Department of Financial Services’ 72-hour requirement under Part 500, and for public companies, the Securities and Exchange Commission’s four-business-day disclosure clock once materiality is determined.
None of these rules line up neatly — different definitions, different deadlines, different thresholds. Reporting to a regulator or an insurer doesn’t automatically satisfy CIRCIA, and vice versa. That’s exactly where companies stumble: IT is typically laser-focused on incident containment, business leadership is worried about staying operational, and legal is trying to determine what mandatory notifications must be provided and by when. Without coordination, different people end up telling different versions of the same story to different audiences, thereby perpetuating misrepresentations and increasing legal risk.
What in-house counsel should be doing now
The window before the final rule lands is the time to stress-test the incident response process, not after.
Build a reporting matrix. Map out likely obligations, deadlines, decision-makers, and who gets notified — CIRCIA, sector rules, state breach laws, contracts, insurance requirements, all of it.
Test the escalation path. A security operations center (SOC) analyst might spot trouble long before legal or leadership grasps what it means. Know what triggers escalation, who makes the call, and how fast the right people can actually get in a room.
Get vendor contracts in shape. Managed security providers, forensic vendors, and outside cybersecurity counsel often hold the logs, technical analytics or Justice Department enforcement perspectives needed to figure out whether something’s reportable. Contracts should require prompt notice, evidence preservation and cooperation.
Think about privilege early. CIRCIA does offer real protections for reports and materials created for the reporting process, and filing a report doesn’t waive privilege on its own — but those protections work best when counsel is involved from the start and the investigation is run in an organized way.
The final rule may tweak some details. What won’t change is the operational reality: Once a serious incident hits, there’s very little time to figure out what happened, lock down the evidence, and decide who needs to know first.
Michael Gruden is a partner at Steptoe LLP, where he leads the firm’s Cybersecurity & Incident Response practice. A former Pentagon IT acquisition branch chief, he sits on the CMMC Appeals Board and chairs the American Bar Association Science & Technology Section’s Homeland Security Committee.
Copyright
© 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.
