# CISA Advances CIRCIA Reporting Rule

CISA submitted the final rule implementing the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) to the Office of Information and Regulatory Affairs on October 1, 2026, starting interagency review before Federal Register publication. The rule may be published in early 2027; its effective date will be specified in the rule and is expected to be at least 60 days after publication. It establishes reporting timeframes of 72 hours for covered cyber incidents and 24 hours for ransomware payments, making its final scope and timing relevant to critical-infrastructure organizations and contractors that support them.

- Covered organizations should assess whether they may fall within CIRCIA’s scope and identify incident-response processes that would support the stated reporting timeframes; the rule is not yet published or effective.
- Contractors serving potentially covered entities can review how incident escalation, customer notification, and reporting responsibilities are handled in their existing agreements and response procedures.
- The final rule’s publication and specified effective date will determine when any applicable requirements take effect; the signal anticipates publication in early 2027 but does not provide a confirmed date.

**Jurisdictions:** federal
**Industries:** Public Safety
**Topics:** Cybersecurity, Regulatory Compliance
**Published:** October 09, 2026

### Government Entities
- Cybersecurity and Infrastructure Security Agency (CISA)
- Office of Information and Regulatory Affairs (OIRA)

### Sources
- [CISA Submits Final CIRCIA Rule for OMB Review | Inside Privacy](https://www.insideprivacy.com/critical-infrastructure/cisa-submits-final-circia-rule-for-omb-review) - Inside Privacy