CISA Submitted Final CIRCIA Cybersecurity Rule for Review
The federal rule mandates prompt incident reporting for 300,000 organizations to harmonize cyber defense protocols.
Updated on Oct. 2, 2026 in Cybersecurity

Live Poll
Should the government mandate standardized cyber incident reporting for all critical infrastructure sectors?
CISA has submitted the final Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) rule to the Office of Management and Budget for regulatory oversight. The move marks a milestone in a process mandated by Congress in 2022 to standardize how critical infrastructure operators report cyber threats and ransom payments.
Why it matters
This rule aims to reduce the burden of regulatory fragmentation, as 70% of existing federal cybersecurity mandates currently contain overlapping requirements. By consolidating these reporting obligations, the government seeks to provide clarity to the roughly 300,000 organizations now subject to the act.
The proposal requires firms to report substantial cyber incidents within 72 hours and ransom payments within 24 hours. Additionally, organizations must now maintain two years of incident data, replacing previous standards like the 90-day retention period mandated under DFARS.
The players
CISA
The Cybersecurity and Infrastructure Security Agency acts as the primary federal lead for protecting critical U.S. physical and cyber infrastructure.
GAO
The Government Accountability Office serves as a non-partisan auditing agency that investigates federal spending and policy efficacy.
DHS
The Department of Homeland Security coordinates national efforts to secure domestic infrastructure and manage disaster response.
The details
The CIRCIA rule establishes a unified framework for identifying and reporting cyber compromises across the United States. It requires organizations to retain detailed logs of network activity, a shift meant to support federal forensics and threat analysis. CISA (Cybersecurity and Infrastructure Security Agency) arrived at this final version after conducting extensive stakeholder town halls to address concerns regarding the operational feasibility of these windows.
Timeline
2022: Congress mandated the creation of the CIRCIA rule.
May 2026: CISA shifted its internal target date for the rule.
June 2026: DHS held stakeholder town halls on the proposal.
July 2026: GAO published a report identifying regulatory overlap.
October 1, 2026: CISA submitted the final rule to the Office of Management and Budget.
The Tech Race
This move represents the culmination of a four-year legislative and administrative effort to codify mandatory reporting under the Cyber Incident Reporting for Critical Infrastructure Act. The agency is now racing to align these requirements against the findings of the 2026 GAO audit, which highlighted significant regulatory redundancy.
Approximately 300,000 organizations will be required to overhaul their data retention workflows to meet the two-year storage mandate. Once finalized, these entities must prepare to report incidents within the strict 72-hour and 24-hour windows established by the rule.
The takeaway
The federal push for a unified reporting standard is a critical shift toward systemic visibility in cybersecurity. Stakeholders should monitor the Office of Management and Budget for the final rule publication, which will trigger the formal clock for compliance enforcement.
What happens next
The rule is expected to be finalized before the end of 2026.
Further reading
For more on evolving national security mandates, visit our Cybersecurity section.
Live Poll
Should the government mandate standardized cyber incident reporting for all critical infrastructure sectors?









