# CISA Harmonizes Incident Reporting

CISA is expected to issue the final Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) rule in fall 2026, with National Cyber Director Sean Cairncross emphasizing alignment with existing incident-reporting requirements. The rule affects covered entities across 16 critical infrastructure sectors, with anticipated reporting deadlines of 72 hours for cyber incidents and 24 hours for ransomware payments. Although the signal identifies no specific solicitation or award, the rule could affect contractors that support covered entities and handle incident-response or reporting functions.

- Contractors serving critical infrastructure organizations should assess how their incident-response capabilities support the anticipated reporting timelines and their clients’ existing reporting obligations.
- Procurement and security teams should distinguish between requirements applicable to covered entities and any obligations that may flow to contractors through their specific roles or contract terms.
- The expected fall 2026 final rule may clarify how CIRCIA reporting aligns with existing requirements; the signal identifies no specific procurement opportunity, contract value, or contact.

**Jurisdictions:** federal
**Industries:** Information Technology
**Topics:** Cybersecurity, Regulatory Compliance
**Published:** September 30, 2026

### Government Entities
- Cybersecurity and Infrastructure Security Agency (CISA)
- Office of the National Cyber Director (ONCD)

### Key Quotes
> There is a lot of attention going into moving this forward and providing clarity to industry and harmonizing the reporting structure, which I think will go a long way.
> — Sean Cairncross, National Cyber Director

### Sources
- [
        White House cyber leader says CIRCIA will harmonize incident reporting - Federal News Network](https://federalnewsnetwork.com/cybersecurity/2026/09/white-house-cyber-leader-says-circia-will-harmonize-incident-reporting) - Federal News Network