Feature Incident Response
Cyber Incident Notification: Bank, SEC, State, and Future CIRCIA Clocks
Sequence live bank, SEC, and state notification analyses while keeping CIRCIA's future 72-hour workflow conditional on an effective final rule.
Table of Contents
August 17, 2026 correction: The CIRCIA 72-hour and ransom-payment clocks are future-state only. No CIRCIA final rule was in force. The bank 36-hour rule, SEC rules, and applicable state or sector duties must be analyzed under their own current text.
TL;DR
- Use one incident fact record but a separate trigger memo and deadline for each regime.
- The banking agencies’ 36-hour clock runs after determination of a notification incident.
- SEC Form 8-K Item 1.05 generally runs four business days after a public company determines materiality.
- State breach and sector rules vary; do not assign one universal 72-hour clock.
- Keep CIRCIA conditional until CISA’s final rule is effective.
Why Sequencing Fails
Incident teams often put “36h / 72h / four days” on a slide and assume they have a notification process. The hard question is not the arithmetic. It is identifying the legally relevant event that starts each clock and preserving the evidence behind that determination.
A reliable workflow separates:
- awareness of a technical event;
- escalation into legal, risk, and executive review;
- regime-specific determination;
- deadline calculation;
- submission and approval; and
- supplemental or continuing duties.
Current Federal Banking Rule: 36 Hours
The interagency final rule requires a covered banking organization to notify its primary federal regulator as soon as possible and no later than 36 hours after determining that a computer-security incident rises to the level of a notification incident.
The 36 hours do not automatically run from the first security alert. The institution must nevertheless escalate promptly enough to make the required determination. Preserve:
- first alert and validation time;
- when potential notification-incident facts emerged;
- escalation to the accountable decision-maker;
- determination time;
- rationale and approver; and
- notification time and method.
The OCC’s Bulletin 2021-55 provides an official agency reference for OCC-supervised institutions.
SEC Form 8-K: Materiality Determination
For a domestic public company, Form 8-K Item 1.05 generally requires disclosure within four business days after the registrant determines that a cybersecurity incident is material. The SEC rule requires the materiality determination without unreasonable delay after discovery.
Track the evidence considered in the materiality decision, including operational, financial, legal, customer, strategic, and reputational consequences where relevant. Do not wait for a perfectly quantified loss if qualitative facts can be material.
A national-security or public-safety delay is available only through the process in the rule. It is not a general law-enforcement exception the company can invoke on its own.
State and Sector Rules: Build a Matrix
State breach-notification duties differ in covered information, harm tests, regulator and consumer recipients, outside dates, law-enforcement delay, content, and supplemental notices. Sector rules such as NYDFS Part 500 add their own triggers and clocks.
The matrix should include:
| Field | Example content |
|---|---|
| Jurisdiction and citation | Exact statute, rule, or regulator page |
| Covered entity and data | Legal-entity and information scope |
| Trigger | Discovery, determination, likelihood of harm, or other event |
| Recipient | Consumer, attorney general, regulator, credit bureau, other |
| Clock | Promptness standard or outside deadline |
| Delay | Conditions and approval evidence |
| Follow-up | Supplemental facts, certification, payment explanation, updates |
Have counsel validate the matrix and review it on a defined cadence.
Future CIRCIA: Keep It Conditional
CISA’s CIRCIA status page says covered entities will not be required to report until the final rule goes into effect. The 2024 NPRM proposes detailed coverage and procedures for the statutory 72-hour covered-incident and 24-hour ransom-payment architecture.
Do not place CIRCIA in the “live filings” column. Use this status:
| CIRCIA item | Current treatment |
|---|---|
| Coverage | Provisional assessment under NPRM; revalidate against final rule |
| 72-hour incident workflow | Tabletop and data mapping only |
| 24-hour ransom-payment workflow | Tabletop and data mapping only |
| Submission form | Do not represent as final |
| Effective date | Unknown until final agency action |
A Sequencing Workflow
Phase 1: Stabilize and open the fact record
Do not delay containment to draft a notice. At the same time, open a timestamped record with affected systems, service impact, data, customers, legal entities, vendors, recovery, and ransom facts.
Phase 2: Route separate trigger analyses
Assign named decision-makers for bank notification, SEC materiality, state breach, sector rules, contracts, insurance, and future CIRCIA. Each owner should see the same facts but answer a different legal question.
Phase 3: Record determination times
The deadline register should show both the event time and the legal determination time. A generic “incident began” field cannot support every calculation.
Phase 4: Draft from verified facts
Separate confirmed facts, reasonable assessments, unknowns, and planned follow-up. Reconcile regulator, customer, insurer, counterparty, and public statements to avoid unsupported inconsistency.
Phase 5: Track updates
Some regimes or commitments require supplemental information. Keep the matter open until legal, regulatory, contractual, and governance follow-up is complete.
Tabletop Test
Use a scenario where a critical provider fails, transaction processing is intermittent, customer impact grows over six hours, data access is uncertain, and a listed parent may face material consequences.
Require the team to produce:
- a bank-rule determination memo;
- an SEC materiality decision record;
- a state and sector matrix extract;
- a contractual-notice log;
- a clearly labeled future CIRCIA analysis; and
- an executive timeline showing the different clock starts.
The exercise fails if the team announces that “the 72-hour CIRCIA deadline” is live.
So What?
There is no universal cyber-notification clock. The control is disciplined trigger analysis using a shared fact base.
Keep current bank, SEC, state, sector, contract, and insurance workflows live. Prepare for CIRCIA, but activate it only after final text establishes coverage, procedures, and effective timing.
The Incident Response & Breach Notification Kit can support the trigger matrix and evidence log. Legal owners must maintain the current citations.
Primary sources: Federal banking agencies’ 36-hour rule announcement | OCC Bulletin 2021-55 | SEC Form 8-K | CISA CIRCIA status | 2024 CIRCIA NPRM
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Incident Response & Breach Notification Kit
Step-by-step incident response playbooks and breach notification templates for all 50 states.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Is CIRCIA a current reporting clock?
What is the current federal bank notification clock?
When does a public company file Form 8-K Item 1.05?
Can one master timer manage all notices?
What should an incident commander track?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Incident Response & Breach Notification Kit
Step-by-step incident response playbooks and breach notification templates for all 50 states.
◆ Keep reading
Related posts.
Incident Response
CIRCIA Status in August 2026: No Final Rule and No Current 72-Hour Duty
CIRCIA remains in rulemaking. Separate its proposed 72- and 24-hour reports from the banking agencies' existing 36-hour notification rule.
Aug 1, 2026
Incident Response
The SEC's Four-Day Clock: How to Make a Cyber Incident Materiality Call Under Item 1.05
The four-day filing clock under SEC Item 1.05 starts at materiality determination — not discovery. Here's how companies structure that determination, what enforcement looks like two years in, and how to avoid the two failure modes that are generating penalties.
Jul 29, 2026
Incident Response
After the Incident: Turn Lessons Learned Into Control Changes That Stay Closed
Strengthen an incident response plan by converting lessons learned into owned control changes, effectiveness tests, and defensible closure evidence.
Jul 26, 2026