The Cyber Incident Reporting for Critical Infrastructure Act, signed into law back in 2022, is still waiting on its final implementing rule — CISA has now pushed the expected publication date to September 2026, the latest in a string of delays from an original statutory deadline of October 2025. But the delay is about timing, not substance; the core obligation the rule will impose is essentially settled.
Once effective, covered entities across 16 critical infrastructure sectors will be required to report a “covered cyber incident” to CISA within 72 hours of discovering it, and any ransomware payment within 24 hours of making it. The scope is broader than the phrase “critical infrastructure” might suggest — estimates put the number of affected businesses above 300,000, covering not just power utilities and hospitals but many mid-size companies that happen to fall within a covered sector or exceed a small-business size threshold.
The rule is also explicitly designed to interact with existing reporting obligations businesses may already have — SEC breach disclosure rules, state breach notification laws, sector-specific requirements like DFARS for defense contractors — and part of what's held up the final rule is CISA's effort to harmonize those overlapping requirements rather than simply stacking a new one on top.
The practical guidance from firms tracking this closely is consistent: don't wait for the ink to dry. Businesses that might fall within scope should be building incident detection and reporting workflows now, using the proposed rule as a planning baseline, because a 72-hour reporting clock is not a reasonable timeframe to build a reporting process from scratch after an actual incident occurs.
This article is general information, not legal advice. Consult a qualified attorney for guidance specific to your situation.
Sources
- ComplianceHub.Wiki, "CIRCIA Slips Again: CISA Now Targets September 2026"
- Fisher Phillips, "New Federal Cybersecurity Reporting Rules are on Their Way"
- PwC, "New proposed regulations for cyber incident reporting"