Feature Incident Response
CIRCIA Is Still Proposed: Preparing for the Future 72-Hour Rule
CIRCIA is still in rulemaking. No final rule or current 72-hour duty existed on August 17, 2026; the 2024 document remains a proposal.
Table of Contents
TL;DR
- No CIRCIA final rule exists as of August 17, 2026. CISA says mandatory CIRCIA incident and ransom-payment reporting will begin only after a final rule takes effect.
- The 72-hour incident and 24-hour ransom-payment clocks are statutory requirements being implemented through rulemaking; the detailed coverage, trigger, content, and submission mechanics in the 2024 document remain proposed.
- The banking agencies’ existing 36-hour notification rule is already operative. Do not replace that analysis with a future CIRCIA workflow.
- Prepare now, but keep proposal controls visibly conditional so responders do not mistake a planning playbook for a live legal duty.
The Status Check That Comes First
CIRCIA—the Cyber Incident Reporting for Critical Infrastructure Act of 2022—created a federal framework for covered critical-infrastructure entities to report covered cyber incidents and ransom payments to CISA. But Congress left key operating details to CISA’s final rule, including the covered-entity definition and the meaning of a covered cyber incident.
CISA published a notice of proposed rulemaking on April 4, 2024. In 2026, it sought more stakeholder input through town halls on the scope and burden of that proposal. CISA’s current CIRCIA page states plainly that covered-incident and ransom-payment reporting will not be required until the final rule goes into effect.
That means three labels matter:
- Enacted statute: Congress established the reporting framework and 72-hour/24-hour architecture.
- Proposed implementation: CISA’s 2024 NPRM supplies proposed coverage, definitions, content, and procedures.
- Future operative requirement: Mandatory reporting begins only under an effective final rule.
Calling the NPRM a final rule collapses those stages and can produce bad operational decisions during an incident.
What the Proposal Would Require
Under the 2024 CIRCIA NPRM, a covered entity would generally have to:
- report a covered cyber incident to CISA within 72 hours after it reasonably believes the incident occurred;
- report a ransom payment within 24 hours after making the payment; and
- submit supplemental reports when substantial new or different information becomes available, subject to the final rule’s terms.
These are not generic breach-notification clocks. The proposal turns on defined concepts—covered entity, covered cyber incident, and reasonable belief—that must be applied to facts. The final rule may change the proposal’s tests, exceptions, and required data fields.
A sound playbook therefore says “evaluate under the final CIRCIA rule when effective”, not “file every cyber event within 72 hours.”
Coverage Is Not Settled Yet
Financial services is one of the critical-infrastructure sectors, but that fact alone does not answer whether a particular bank, credit union, payments company, investment firm, or fintech will be a covered entity.
The NPRM proposed a combination of broad sector criteria, a small-business-size screen, exceptions, and sector-specific conditions. Those details drew substantial comments and were among the issues CISA continued to discuss in 2026. Until the final rule is published, firms should maintain a provisional assessment rather than a final legal conclusion.
A defensible provisional memo should record:
- the legal entity being assessed;
- its critical-infrastructure sector and relevant services;
- the proposed size or category criterion that may apply;
- any proposed exception relied on;
- the source and retrieval date; and
- an explicit revalidation trigger for publication of the final rule.
The Existing 36-Hour Bank Rule Is Different—and Live
The OCC, Federal Reserve, and FDIC computer-security incident notification rule is already in force. Under the OCC’s implementing bulletin, an OCC-supervised bank must notify the OCC as soon as possible and no later than 36 hours after determining that a computer-security incident rises to the level of a notification incident. Parallel rules apply to banking organizations supervised by the Federal Reserve and FDIC.
The proposed CIRCIA and existing bank rules differ in ways responders must preserve:
| Framework | Current status | Recipient | Clock described by the rule or proposal | Core trigger concept |
|---|---|---|---|---|
| Banking agencies’ computer-security notification rule | Effective | Primary federal banking regulator | As soon as possible and no later than 36 hours | Bank determines a qualifying notification incident occurred |
| CIRCIA | Proposed implementation; not yet mandatory | CISA | Proposed 72 hours | Covered entity reasonably believes a covered cyber incident occurred |
| CIRCIA ransom-payment report | Proposed implementation; not yet mandatory | CISA | Proposed 24 hours after payment | Covered entity makes a ransom payment following a ransomware attack |
A single event may eventually require multiple reports. The correct method is a parallel trigger analysis—not choosing the shortest clock and assuming it satisfies every regime.
Build a Conditional Notification Matrix
A useful incident matrix separates legal status from operational readiness.
For each regime, capture:
- status: effective, proposed, stayed, or guidance only;
- covered entity: which legal entity carries the duty;
- trigger: exact legal threshold;
- clock start: the event that starts time;
- recipient and channel: regulator and filing route;
- required content: known facts, impact, timing, and updates;
- decision owner: person authorized to classify and file; and
- evidence: ticket, incident log, legal memo, and submission confirmation.
For CIRCIA, populate proposed fields but add a hard banner: “NOT A CURRENT FILING DUTY—REVALIDATE AGAINST FINAL RULE.” That avoids two opposite failures: doing no preparation, or filing and communicating as though proposed text were law.
Five Preparation Steps That Are Safe Today
1. Preserve decision timestamps
Both the existing bank rule and proposed CIRCIA framework depend on institutional knowledge and judgment. Your incident log should record when facts became known, who evaluated them, what threshold was considered, and why the team reached its conclusion.
2. Map evidence owners
Identify where the proposed CIRCIA data would come from: security operations, infrastructure, fraud, legal, communications, vendor management, and finance for ransom-payment facts. Do not wait for an event to discover that no team owns a required field.
3. Create one intake, separate legal analyses
Use a common incident fact record, but maintain distinct determination worksheets for the banking rule, future CIRCIA, securities disclosure, contractual notices, and state requirements. Shared facts do not mean shared legal triggers.
4. Test a third-party outage or compromise
The proposal addresses supply-chain compromise, and the FFIEC expects institutions to test critical third-party disruption. A tabletop should force the team to answer who obtains facts from the vendor, when the bank makes its own regulatory determination, and how uncertain facts are documented.
5. Add a regulatory-change trigger
Assign an owner to monitor the CISA FAQs and Federal Register. Publication of a final rule should trigger legal review, coverage reassessment, playbook revision, training, and a new tabletop—not a silent link update.
So What?
CIRCIA preparation is necessary. Pretending the final rule already exists is not.
The practical objective is an incident program that can activate quickly once CISA finalizes the rule, while continuing to meet current obligations today. Keep the 36-hour banking rule operational. Build a conditional CIRCIA module. Document every trigger decision. Revalidate the module against the final text before anyone treats it as a filing instruction.
The Incident Response & Breach Notification Kit provides a structure for trigger matrices, escalation roles, and evidence logs. Any template still needs entity-specific legal review and a final-rule update before CIRCIA reporting becomes mandatory.
Primary sources: CISA CIRCIA status page | CISA CIRCIA FAQs | 2024 CIRCIA NPRM | 2026 CIRCIA town-hall notice | OCC Bulletin 2021-55
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Incident Response & Breach Notification Kit
Step-by-step incident response playbooks and breach notification templates for all 50 states.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Has CISA issued the CIRCIA final rule?
Are the 72-hour and 24-hour CIRCIA reports mandatory today?
Will CIRCIA apply to every bank and fintech?
How is proposed CIRCIA reporting different from the banking agencies' 36-hour rule?
What should an institution do before a CIRCIA final rule exists?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Incident Response & Breach Notification Kit
Step-by-step incident response playbooks and breach notification templates for all 50 states.
◆ Keep reading
Related posts.
Incident Response
CIRCIA Status in August 2026: No Final Rule and No Current 72-Hour Duty
CIRCIA remains in rulemaking. Separate its proposed 72- and 24-hour reports from the banking agencies' existing 36-hour notification rule.
Aug 1, 2026
Incident Response
The SEC's Four-Day Clock: How to Make a Cyber Incident Materiality Call Under Item 1.05
The four-day filing clock under SEC Item 1.05 starts at materiality determination — not discovery. Here's how companies structure that determination, what enforcement looks like two years in, and how to avoid the two failure modes that are generating penalties.
Jul 29, 2026
Incident Response
After the Incident: Turn Lessons Learned Into Control Changes That Stay Closed
Strengthen an incident response plan by converting lessons learned into owned control changes, effectiveness tests, and defensible closure evidence.
Jul 26, 2026