CISA submits Final CIRCIA Rule to OIRA for interagency review
The rule will impose rapid cyber‑incident reporting obligations on critical‑infrastructure operators, shaping their security and compliance programs.
ADTP Regulatory Watch· October 9, 2026· Cybersecurity and Infrastructure Security Agency (CISA)
ImpactLow 35
Type📋 Proposed Regulation
Statusannouncednot law
JurisdictionUS
What happened
On October 1, 2026, CISA submitted a draft of the Final Rule implementing the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) to OIRA. CIRCIA will require covered critical‑infrastructure entities to report cybersecurity incidents within 72 hours and ransomware payments within 24 hours. The rule’s effective date has not been set, but it is expected to be at least 60 days after Federal Register publication.
Why it matters for trust and compliance
Its status is announced. It is not law yet. Track it, but do not treat it as an obligation.
The rule will impose rapid cyber‑incident reporting obligations on critical‑infrastructure operators, shaping their security and compliance programs.
Who is affected
controller
Recommended actions
Map the security requirements to existing controls and close gaps.
Check breach-notification procedures and timelines against the requirement.