Skip to content
RiskTemplates · The Daily Brief Saturday, August 22, 2026
Wire SEC's Tricolor Fraud Case: The Double-Pledging Controls Lenders Missed AUG 20

Feature Incident Response

CIRCIA Is Still Proposed: Preparing for the Future 72-Hour Rule

CIRCIA is still in rulemaking. No final rule or current 72-hour duty existed on August 17, 2026; the 2024 document remains a proposal.

By Rebecca Leung · June 5, 2026 ·
Table of Contents

TL;DR

  • No CIRCIA final rule exists as of August 17, 2026. CISA says mandatory CIRCIA incident and ransom-payment reporting will begin only after a final rule takes effect.
  • The 72-hour incident and 24-hour ransom-payment clocks are statutory requirements being implemented through rulemaking; the detailed coverage, trigger, content, and submission mechanics in the 2024 document remain proposed.
  • The banking agencies’ existing 36-hour notification rule is already operative. Do not replace that analysis with a future CIRCIA workflow.
  • Prepare now, but keep proposal controls visibly conditional so responders do not mistake a planning playbook for a live legal duty.

The Status Check That Comes First

CIRCIA—the Cyber Incident Reporting for Critical Infrastructure Act of 2022—created a federal framework for covered critical-infrastructure entities to report covered cyber incidents and ransom payments to CISA. But Congress left key operating details to CISA’s final rule, including the covered-entity definition and the meaning of a covered cyber incident.

CISA published a notice of proposed rulemaking on April 4, 2024. In 2026, it sought more stakeholder input through town halls on the scope and burden of that proposal. CISA’s current CIRCIA page states plainly that covered-incident and ransom-payment reporting will not be required until the final rule goes into effect.

That means three labels matter:

  1. Enacted statute: Congress established the reporting framework and 72-hour/24-hour architecture.
  2. Proposed implementation: CISA’s 2024 NPRM supplies proposed coverage, definitions, content, and procedures.
  3. Future operative requirement: Mandatory reporting begins only under an effective final rule.

Calling the NPRM a final rule collapses those stages and can produce bad operational decisions during an incident.

What the Proposal Would Require

Under the 2024 CIRCIA NPRM, a covered entity would generally have to:

  • report a covered cyber incident to CISA within 72 hours after it reasonably believes the incident occurred;
  • report a ransom payment within 24 hours after making the payment; and
  • submit supplemental reports when substantial new or different information becomes available, subject to the final rule’s terms.

These are not generic breach-notification clocks. The proposal turns on defined concepts—covered entity, covered cyber incident, and reasonable belief—that must be applied to facts. The final rule may change the proposal’s tests, exceptions, and required data fields.

A sound playbook therefore says “evaluate under the final CIRCIA rule when effective”, not “file every cyber event within 72 hours.”

Coverage Is Not Settled Yet

Financial services is one of the critical-infrastructure sectors, but that fact alone does not answer whether a particular bank, credit union, payments company, investment firm, or fintech will be a covered entity.

The NPRM proposed a combination of broad sector criteria, a small-business-size screen, exceptions, and sector-specific conditions. Those details drew substantial comments and were among the issues CISA continued to discuss in 2026. Until the final rule is published, firms should maintain a provisional assessment rather than a final legal conclusion.

A defensible provisional memo should record:

  • the legal entity being assessed;
  • its critical-infrastructure sector and relevant services;
  • the proposed size or category criterion that may apply;
  • any proposed exception relied on;
  • the source and retrieval date; and
  • an explicit revalidation trigger for publication of the final rule.

The Existing 36-Hour Bank Rule Is Different—and Live

The OCC, Federal Reserve, and FDIC computer-security incident notification rule is already in force. Under the OCC’s implementing bulletin, an OCC-supervised bank must notify the OCC as soon as possible and no later than 36 hours after determining that a computer-security incident rises to the level of a notification incident. Parallel rules apply to banking organizations supervised by the Federal Reserve and FDIC.

The proposed CIRCIA and existing bank rules differ in ways responders must preserve:

FrameworkCurrent statusRecipientClock described by the rule or proposalCore trigger concept
Banking agencies’ computer-security notification ruleEffectivePrimary federal banking regulatorAs soon as possible and no later than 36 hoursBank determines a qualifying notification incident occurred
CIRCIAProposed implementation; not yet mandatoryCISAProposed 72 hoursCovered entity reasonably believes a covered cyber incident occurred
CIRCIA ransom-payment reportProposed implementation; not yet mandatoryCISAProposed 24 hours after paymentCovered entity makes a ransom payment following a ransomware attack

A single event may eventually require multiple reports. The correct method is a parallel trigger analysis—not choosing the shortest clock and assuming it satisfies every regime.

Build a Conditional Notification Matrix

A useful incident matrix separates legal status from operational readiness.

For each regime, capture:

  • status: effective, proposed, stayed, or guidance only;
  • covered entity: which legal entity carries the duty;
  • trigger: exact legal threshold;
  • clock start: the event that starts time;
  • recipient and channel: regulator and filing route;
  • required content: known facts, impact, timing, and updates;
  • decision owner: person authorized to classify and file; and
  • evidence: ticket, incident log, legal memo, and submission confirmation.

For CIRCIA, populate proposed fields but add a hard banner: “NOT A CURRENT FILING DUTY—REVALIDATE AGAINST FINAL RULE.” That avoids two opposite failures: doing no preparation, or filing and communicating as though proposed text were law.

Five Preparation Steps That Are Safe Today

1. Preserve decision timestamps

Both the existing bank rule and proposed CIRCIA framework depend on institutional knowledge and judgment. Your incident log should record when facts became known, who evaluated them, what threshold was considered, and why the team reached its conclusion.

2. Map evidence owners

Identify where the proposed CIRCIA data would come from: security operations, infrastructure, fraud, legal, communications, vendor management, and finance for ransom-payment facts. Do not wait for an event to discover that no team owns a required field.

Use a common incident fact record, but maintain distinct determination worksheets for the banking rule, future CIRCIA, securities disclosure, contractual notices, and state requirements. Shared facts do not mean shared legal triggers.

4. Test a third-party outage or compromise

The proposal addresses supply-chain compromise, and the FFIEC expects institutions to test critical third-party disruption. A tabletop should force the team to answer who obtains facts from the vendor, when the bank makes its own regulatory determination, and how uncertain facts are documented.

5. Add a regulatory-change trigger

Assign an owner to monitor the CISA FAQs and Federal Register. Publication of a final rule should trigger legal review, coverage reassessment, playbook revision, training, and a new tabletop—not a silent link update.

So What?

CIRCIA preparation is necessary. Pretending the final rule already exists is not.

The practical objective is an incident program that can activate quickly once CISA finalizes the rule, while continuing to meet current obligations today. Keep the 36-hour banking rule operational. Build a conditional CIRCIA module. Document every trigger decision. Revalidate the module against the final text before anyone treats it as a filing instruction.

The Incident Response & Breach Notification Kit provides a structure for trigger matrices, escalation roles, and evidence logs. Any template still needs entity-specific legal review and a final-rule update before CIRCIA reporting becomes mandatory.


Primary sources: CISA CIRCIA status page | CISA CIRCIA FAQs | 2024 CIRCIA NPRM | 2026 CIRCIA town-hall notice | OCC Bulletin 2021-55

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Has CISA issued the CIRCIA final rule?
No. As of August 17, 2026, CIRCIA remains in rulemaking. CISA's current guidance says covered cyber-incident and ransom-payment reports will not be required until the final rule takes effect. CISA held additional town halls in 2026 to obtain input on the 2024 proposed rule.
Are the 72-hour and 24-hour CIRCIA reports mandatory today?
Not yet. The statute directs CISA to implement reporting through regulation, and the 2024 NPRM proposed reports within 72 hours after a covered entity reasonably believes a covered cyber incident occurred and within 24 hours after a ransom payment. Those CIRCIA duties await an effective final rule. Existing sector-specific duties, including the banking agencies' 36-hour notification rule, remain in force.
Will CIRCIA apply to every bank and fintech?
The final coverage test is not settled. The 2024 NPRM proposed sector-based and size-based criteria, exclusions, and additional category-specific tests. Financial services is a critical-infrastructure sector, but a firm should not label itself covered or exempt based only on the proposal. Preserve a documented provisional assessment and repeat it against the final text.
How is proposed CIRCIA reporting different from the banking agencies' 36-hour rule?
They have different legal triggers, recipients, and clocks. The existing rule requires a banking organization to notify its primary federal regulator as soon as possible and no later than 36 hours after determining that a computer-security incident rises to the level of a notification incident. The proposed CIRCIA rule would require a covered entity to report a covered cyber incident to CISA within 72 hours after reasonably believing it occurred. One event may trigger both, but neither analysis substitutes for the other.
What should an institution do before a CIRCIA final rule exists?
Treat CIRCIA as a monitored change, not a current filing obligation. Build a provisional applicability memo, map proposed data fields to evidence sources, identify an accountable filing team, preserve decision timestamps, and tabletop simultaneous 36-hour and future 72-hour analyses. Keep labels such as 'proposed' and 'not yet effective' in every playbook.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Incident Response & Breach Notification Kit

Step-by-step incident response playbooks and breach notification templates for all 50 states.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.