CIRCIA's 72-Hour Breach Reporting Rule Is Now Expected in September 2026
Dr. Abeer Alshammari · Published 7/29/2026
Executive View
CISA has again delayed the CIRCIA final rule, now targeting September 2026 against an original October 2025 statutory deadline. Once final, more than 300,000 entities across 16 critical infrastructure sectors will need to report covered cyber incidents to CISA within 72 hours and ransom payments within 24 hours. Decision required: US critical-infrastructure organizations should confirm their incident-reporting playbooks can meet a 72-hour clock today, rather than waiting for the rule to finalize.
The rule is not yet final. CISA has delayed it multiple times past its original October 2025 statutory deadline and now targets September 2026. CyberAbeer will update this article when the rule is actually finalized.
What happened
The Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), passed in 2022, requires CISA to issue regulations mandating that covered entities report significant cyber incidents within 72 hours and ransom payments within 24 hours. CISA's own Unified Agenda of Federal Regulatory Actions now targets September 2026 to finalize the implementing rule, having missed its original October 2025 statutory deadline.
Why it matters
This is the US federal government's first comprehensive, cross-sector mandatory cyber incident reporting regime. CISA has estimated the rule will apply to more than 300,000 entities across 16 critical infrastructure sectors -- from electric utilities and water systems to hospitals and chemical facilities -- a scope far broader than sector-specific reporting rules that exist today.
Who is affected
Organizations operating in any of the 16 critical infrastructure sectors as defined by US policy (energy, water, healthcare, financial services, chemical, and others), including subsidiaries and contractors of US entities operating internationally.
Governance impact
The rule's purpose is to let CISA rapidly deploy resources to victims, analyze incident trends across sectors, and warn other potential targets faster. For covered organizations, it converts incident reporting from a discretionary or sector-specific obligation into a hard, cross-sector regulatory deadline with real timing pressure.
What executives and security teams should do
- Determine now whether your organization falls within one of the 16 covered critical infrastructure sectors -- do not wait for the final rule to check
- Stress-test your incident response playbook specifically against a 72-hour reporting clock, including the internal chain from detection to legal/compliance sign-off
- Confirm ransom-payment decision authority and reporting responsibility are assigned, given the separate 24-hour ransom-payment reporting requirement
- Track CISA's Unified Agenda for the actual finalization date rather than planning around September 2026 as fixed -- this deadline has already slipped multiple times
What executives should know
Even before the rule is final, the direction is clear: mandatory, fast, cross-sector incident reporting is coming for US critical infrastructure. Organizations that build 72-hour-capable reporting processes now avoid a compressed scramble once the rule is finalized.
The decision this forces is not about the rule's final text -- it's about whether incident-reporting ownership and escalation timing already exist in your organization independent of any regulation. A 72-hour external reporting clock is unforgiving of an undefined internal escalation chain; that internal clock should be tested now, not after the rule finalizes.
CIRCIA is US-domestic regulation and does not directly bind GCC-based organizations. It is included here as a regulatory bellwether: GCC critical-infrastructure regulators have generally followed similar mandatory-reporting trends with a lag, and GCC subsidiaries of US-regulated entities may be indirectly affected.
Sources
CISA CIRCIA program page; Federal News Network; Fisher Phillips and ComplianceHub.Wiki regulatory analysis.