REGULATORY WATCH BRIEF Low 35 📋 Proposed Regulation announced

CISA submits Final CIRCIA Rule to OIRA for interagency review

The rule will impose rapid cyber‑incident reporting obligations on critical‑infrastructure operators, shaping their security and compliance programs.

ImpactLow 35
Type📋 Proposed Regulation
Statusannounced not law
JurisdictionUS

What happened

On October 1, 2026, CISA submitted a draft of the Final Rule implementing the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) to OIRA. CIRCIA will require covered critical‑infrastructure entities to report cybersecurity incidents within 72 hours and ransomware payments within 24 hours. The rule’s effective date has not been set, but it is expected to be at least 60 days after Federal Register publication.

Why it matters for trust and compliance

  • Its status is announced. It is not law yet. Track it, but do not treat it as an obligation.
  • The rule will impose rapid cyber‑incident reporting obligations on critical‑infrastructure operators, shaping their security and compliance programs.

Who is affected

controller

Recommended actions

  1. Map the security requirements to existing controls and close gaps.
  2. Check breach-notification procedures and timelines against the requirement.