Skip to content
RiskTemplates · The Daily Brief Friday, September 11, 2026
Wire SEC's $3.02M Doximity Insider Trading Judgment: The MNPI Control Test SEP 10

Feature Incident Response

CISA's CIRCIA Is Finalizing This Month. Here's What the New 72-Hour Reporting Clock Means for Your Financial Services Incident Response Program.

CISA's CIRCIA final rule — requiring 72-hour cyber incident reporting to CISA and 24-hour ransomware payment disclosure — is expected to publish in September 2026. For financial services firms, it creates a fifth notification obligation running parallel to OCC/FDIC, SEC, NYDFS, and state breach notification clocks. Here's what your IR program needs to add before the effective date.

By Rebecca Leung · September 8, 2026 ·
Table of Contents

TL;DR

  • CISA’s CIRCIA final rule is expected to publish in September 2026, creating a mandatory 72-hour cyber incident reporting obligation to CISA for covered critical infrastructure entities — including financial services firms exceeding SBA size thresholds.
  • CIRCIA also requires a 24-hour report to CISA for any ransomware payment, separate from the incident report, and is the first U.S. federal law mandating disclosure of ransom payments.
  • For financial services firms, CIRCIA adds a fifth notification track running alongside OCC/FDIC 36-hour, SEC 4-day, NYDFS 72-hour, and state breach notification clocks — each going to a different agency with different triggers and different content.
  • The effective date will be set in the final rule, but preparation shouldn’t wait: your IR runbook, incident classification criteria, and notification workflows need CISA added as a distinct track before the first incident after the rule takes effect.

Your incident response runbook already has at least three notification tracks. If you’re an OCC-supervised entity or bank partner, there’s a 36-hour clock ticking to your primary federal regulator. If you’re a public company, there’s a four-day clock to the SEC via Form 8-K. If you’re NYDFS-licensed, there’s a 72-hour clock to NYDFS. And underneath all of it, there are 50 different state breach notification laws with timelines ranging from 30 to 90 days.

CIRCIA adds a sixth — a mandatory report to CISA, the Cybersecurity and Infrastructure Security Agency, within 72 hours of a “substantial” cyber incident. And a separate 24-hour report if you pay ransom.

These aren’t hypothetical future obligations. The Cyber Incident Reporting for Critical Infrastructure Act of 2022 has been moving toward a final rule since Congress passed it. After a statutory October 2025 deadline came and went, CISA targeted May 2026, then September 2026. The final rule is either newly published or days from publication as this goes out.

If you’re a financial services firm and CIRCIA isn’t in your IR runbook yet, you’re behind.

What CIRCIA Is and Why It Matters Differently for Financial Services

Congress passed CIRCIA in March 2022, requiring CISA to develop rules mandating that organizations in “critical infrastructure” sectors report significant cyber incidents to CISA. The theory: the federal government sees only a fraction of the cyber incidents hitting critical infrastructure because voluntary reporting is inconsistent. Mandatory reporting gives CISA visibility to identify patterns, coordinate response, and push threat intelligence back to industry.

CISA’s proposed rule — which gave the framework for the final rule — estimated 316,244 entities would be covered, spanning all 16 designated critical infrastructure sectors. Financial Services is Sector 7.

That’s a large tent. And unlike some sector-specific cyber rules (OCC, NYDFS, FDIC) that apply only to supervised entities, CIRCIA’s scope is defined by sector membership and size — not by holding a particular license or charter.

The practical implication: some financial services firms that aren’t bank-supervised, aren’t NYDFS-licensed, and don’t file with the SEC may still be covered under CIRCIA. Fintechs operating payment processing infrastructure. Crypto exchanges with significant transaction volumes. Credit unions that fall under NCUA. Insurance companies that aren’t bank-supervised. If you’re in financial services and above the SBA size threshold, CIRCIA applies to you.

Are You a “Covered Entity”?

The CIRCIA covered entity analysis is a two-part test.

First: Does your organization operate in one of CISA’s 16 designated critical infrastructure sectors? For financial services, this includes banking, securities, insurance, and payments infrastructure. If you process payments, extend credit, hold deposits, trade securities, or provide financial data that other financial institutions depend on, you’re likely in the Financial Services Sector.

Second: Do you exceed the SBA small business size standard for your industry? The SBA size standard for financial services entities is generally set by revenue, assets, or employee count depending on the NAICS code. The exception is narrower than most fintechs assume — many Series B and later-stage fintechs will exceed the threshold regardless of whether they think of themselves as “large” companies.

Don’t assume you’re exempt without running the analysis. CISA has been clear that the small-business exception is a floor, not a default.

What Triggers the 72-Hour Clock

CIRCIA requires reporting of “covered cyber incidents,” which CISA defines as “substantial” cyber incidents. The CISA Covered Cyber Incident Fact Sheet describes a substantial incident as one that:

  • Causes substantial loss of confidentiality, integrity, or availability — data exfiltration of personal information, financial data, or intellectual property affecting a material volume of records
  • Creates serious impacts to safety or operational resilience
  • Disrupts business or industrial operations for more than a de minimis period or number of users
  • Involves unauthorized access through a cloud provider, managed service provider, third-party data host, or supply-chain compromise

That last category is significant for financial services. If your core banking platform goes down because a cloud provider is breached, or your payment processor is compromised through a supply chain attack, CIRCIA’s threshold may be met even if your own systems weren’t directly penetrated.

The critical timing detail: the 72-hour clock starts from “reasonable belief” that a substantial incident occurred — not from confirmation, not from a materiality determination, not from the moment you notify your primary regulator. For contrast, the SEC’s Item 1.05 Form 8-K clock starts when the company “determines” the incident is material — a later, more deliberate trigger. CIRCIA’s clock is earlier.

This matters for your IR procedures. If your current runbook says “notify regulators after we’ve confirmed the scope,” you may already be late on the CIRCIA clock when you get to that step.

The Notification Pile-Up: Running Multiple Clocks at Once

When a significant cyber incident hits a financial services firm, the current notification landscape looks like this:

RequirementWho ReportsNotify WhomClock StartsApproximate Trigger
OCC/FDIC 36-hourBank-supervised entitiesPrimary federal banking regulator36 hoursNotification incident (4+ hour critical disruption)
SEC Item 1.05 Form 8-KSEC-registered public companiesSEC (via EDGAR)4 business daysDetermined material
NYDFS 72-hourNYDFS licenseesNYDFS Superintendent72 hoursCybersecurity event affecting NYDFS license
FTC Safeguards 30-dayNon-bank financial institutionsFTC + customers30 daysBreach of customer information
CIRCIA (new)Critical infrastructure covered entitiesCISA72 hours from reasonable beliefSubstantial cyber incident
State breach notificationVaries by stateState AG and/or consumers30–90 daysPII exposure (varies by state)

This is not a choose-one situation. A mid-sized federally supervised bank that is also NYDFS-licensed and publicly traded could face OCC/FDIC, NYDFS, SEC, CIRCIA, and state breach notification obligations simultaneously — running parallel clocks to five different reporting destinations.

Most IR programs weren’t built with this many tracks. As the earlier OCC/FDIC 36-hour notification post covered, bank-supervised entities already struggle to manage the primary regulator notification within the 36-hour window while simultaneously containing the incident. Adding a CISA notification track — with different content requirements and a different definition of what triggers reporting — compounds the operational challenge.

The practitioner reality: when your IR team is managing a live incident, they won’t stop to figure out whether CIRCIA applies. That analysis needs to happen during tabletop exercises and runbook design — before the incident, not during it.

The Ransomware Payment Rule Nobody Has Fully Internalized

CIRCIA’s ransomware payment reporting requirement gets less attention than the 72-hour incident report, but it may be operationally harder to manage.

The requirement: any covered entity that makes a ransom payment must report that payment to CISA within 24 hours. This is separate from and in addition to any incident report. It applies even if the ransomware attack itself doesn’t rise to “substantial” under CIRCIA’s incident definition.

CIRCIA is the first U.S. federal law mandating disclosure of ransomware payments. Before CIRCIA, reporting was voluntary (except under certain OFAC sanctions screening obligations). Paying ransom and telling no one was legal — and common. CIRCIA changes that.

The 24-hour clock on a ransomware payment is aggressive. If your organization makes a payment on a Friday evening to restore operations before Monday’s business hours, the CISA report is due Saturday evening. That requires designating someone with authority to file the report, knowing where and how to file, and having a decision-making chain that doesn’t require waiting for the CEO to return from a flight.

What Your IR Program Needs Before the Effective Date

CISA’s final rule will set an effective date. That date — plus any compliance runway built into the rule — is when penalties can begin. But the work of updating your IR program doesn’t wait for enforceability.

The gaps most financial services IR programs need to close before CIRCIA takes effect:

1. Add CISA as a notification recipient. Your runbook probably identifies your primary federal banking regulator, NYDFS (if applicable), and the SEC as notification targets. Add CISA and CISA’s Incident Reporting Form as a distinct track with its own timing trigger and content checklist.

2. Update your incident severity classification to flag CIRCIA-triggering events. Not every incident triggers CIRCIA — you’re looking for “substantial” events. Your severity tiers need criteria that map to CIRCIA’s definition, so your incident commander knows in the first hour whether CIRCIA applies.

3. Build a ransomware payment decision tree. If your organization faces a ransomware demand and makes a payment, the 24-hour CISA report is mandatory. That decision tree needs to include: CISA notification, OFAC sanctions screening (mandatory before any payment), FBI notification (strongly recommended), and your primary regulator.

4. Brief your board and executive team. NYDFS has been explicit that the board owns cybersecurity governance. CIRCIA adds a material external reporting obligation that the board should understand — including the ransomware payment requirement, which has direct board-level implications.

5. Run a tabletop exercise that tests all notification tracks simultaneously. If your last tabletop scenario only tracked one notification clock, run it again with the full current landscape. Find out where your IR team’s bottlenecks are before the first real incident after CIRCIA takes effect.

So What?

CIRCIA’s final rule isn’t coming as a surprise to anyone paying attention. CISA has been publishing the timeline, the proposed rule, and the content requirements for years. What’s catching financial services firms short isn’t the regulation itself — it’s the assumption that their existing IR program already handles it.

It doesn’t. CIRCIA creates a new notification recipient (CISA), a new timing trigger (72 hours from “reasonable belief”), a new payment disclosure requirement (24 hours for ransom payments), and a new definition of what constitutes a reportable event that doesn’t map cleanly onto the definitions your existing program uses.

The firms that will struggle after the effective date are the ones that treat CIRCIA as just “another line in the notification matrix.” It’s a separate track, with different timing, different content, and a different agency relationship than anything already in your IR runbook.

The Incident Response & Breach Notification Kit includes an all-50-states notification matrix and multi-agency notification playbook — the kind of pre-built framework that makes adding CIRCIA as a new track an update, not a rebuild. If your IR program is still a document you haven’t tested, that’s the more fundamental problem to solve before September’s final rule lands.

The FTC Safeguards Rule’s 30-day breach notification requirement is another parallel obligation that non-bank fintechs frequently underestimate until it’s too late. The pattern repeats: new notification requirement, different agency, different clock, inadequate existing program design to handle it.

The CIRCIA final rule is one more reason to have an IR program that was built to run multiple notification tracks simultaneously — because that’s the reality of what financial services cyber incident response now requires.


Sources: CISA CIRCIA FAQs | CISA Covered Cyber Incident Fact Sheet | Hunton: CISA Plans to Finalize CIRCIA in September 2026 | Federal News Network: CIRCIA Expected to Finalize This Fall | ComplianceHub: CIRCIA Readiness Guide

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Is CIRCIA reporting in addition to — or instead of — existing bank notification requirements?
In addition to. CIRCIA creates a new reporting obligation to CISA that runs parallel to every existing requirement. It doesn't replace the OCC/FDIC 36-hour bank notification, the SEC's Item 1.05 four-day Form 8-K filing, NYDFS's 72-hour notification, or state breach notification laws. Financial services firms covered by multiple regulators will run all of those clocks simultaneously, reporting to different agencies on different timelines with different content requirements.
What makes an entity a 'covered entity' under CIRCIA?
A covered entity is any organization that operates in one of CISA's 16 designated critical infrastructure sectors — Financial Services is one of them — and that exceeds the SBA small business size standard for its industry. Most banks, credit unions, broker-dealers, payment processors, and established fintechs will meet the size threshold. The small-business exception is narrow, and SBA size standards for financial services typically use revenue and/or employee thresholds rather than asset size.
What exactly is a 'covered cyber incident' that starts the 72-hour clock?
CISA defines a covered cyber incident as a 'substantial cyber incident' — one that causes substantial loss of confidentiality, integrity, or availability; creates serious impacts to safety or operational resilience; disrupts business or industrial operations; or involves unauthorized access tied to a cloud provider, managed service provider, third-party data host, or supply-chain compromise. The 72-hour clock starts from the moment you 'reasonably believe' a substantial incident has occurred — not from when you confirm it, not from when you notify your primary regulator.
What does the CIRCIA ransomware payment requirement actually require?
Any covered entity that makes a ransom payment — whether to recover data, restore operations, or prevent publication of stolen data — must report that payment to CISA within 24 hours. This is separate from and in addition to the 72-hour incident report. It applies even if you're not separately reporting a broader incident. CIRCIA is the first U.S. federal law to require mandatory disclosure of ransomware payments themselves, not just the underlying incident.
How does CIRCIA's 72-hour clock differ from the OCC/FDIC 36-hour notification requirement?
They're parallel obligations that go to different agencies. The OCC/FDIC 36-hour rule applies to bank-supervised entities and requires notification to your primary federal banking regulator within 36 hours of a 'notification incident' — broadly, any incident that has materially disrupted or is likely to disrupt critical banking operations for four or more hours. CIRCIA's 72-hour clock goes to CISA, covers a broader definition of critical infrastructure, and has different content requirements. An event that triggers one may or may not trigger the other. Your IR runbook needs both as distinct tracks.
When does CIRCIA's reporting requirement actually become enforceable?
The final rule will specify an effective date, and the rule may provide a separate compliance runway beyond that date. CIRCIA's reporting requirements are not enforceable until the final rule's effective date passes. A September 2026 publication will almost certainly set an effective date in late 2026 or early 2027. Use the publication of the final rule as your trigger to update your IR program — don't wait for the effective date to start building your CISA notification track.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Incident Response & Breach Notification Kit

Step-by-step incident response playbooks and breach notification templates for all 50 states.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.