Skip to content
RiskTemplates · The Daily Brief Thursday, October 1, 2026
Wire SEC v. Meyer Global: The $46,020 Capital Call That Allegedly Wiped Out a Nearly $3 Million SpaceX Stake SEP 30

Feature Business Continuity

CISA Is Finalizing CIRCIA This Fall. Here's What Financial Services Needs to Build Before the 72-Hour Clock Starts.

The Cyber Incident Reporting for Critical Infrastructure Act final rule is expected this fall. Financial services firms face a new CISA reporting clock on top of existing SEC, NYDFS, and banking agency deadlines. Here is what practitioners need to build now.

By Rebecca Leung · September 30, 2026 ·
Table of Contents

TL;DR

  • CISA has targeted fall 2026 to issue the final CIRCIA rule, creating a new federal 72-hour cyber incident reporting obligation for financial services firms — on top of the 36-hour banking agency requirement, NYDFS’s 72-hour DFS notification, Reg S-P’s 30-day customer clock, and SEC 8-K for public companies
  • “Substantial cyber incident” includes supply chain and managed service provider compromises that result in unauthorized access — a category many financial services IR plans don’t explicitly address
  • CIRCIA creates separate reporting to CISA; a report to your primary regulator does not satisfy CIRCIA and vice versa
  • Compliance timelines won’t begin immediately on publication, but the gaps in most programs — no CISA reporting track, no supply-chain incident criteria, no multi-clock notification matrix — won’t close overnight

Your incident response plan probably has a reporting section. It likely includes the federal banking agencies’ 36-hour notification requirement, the NYDFS 72-hour obligation if your firm is New York-licensed, Regulation S-P’s 30-day customer notification clock, and state breach notification laws that vary from 30 to 90 days depending on jurisdiction.

CIRCIA adds a fifth clock.

The Cybersecurity and Infrastructure Security Agency has been working toward the CIRCIA final rule since 2022, missed its October 2025 statutory deadline, and has targeted fall 2026 for publication. When the rule goes final, covered financial services entities — broadly, those above SBA size standards — will face a mandatory 72-hour reporting obligation to CISA for substantial cyber incidents and a separate 24-hour obligation for ransom payments.

The rule isn’t in effect yet. But the gaps in most firms’ incident response programs — no CISA reporting track, no defined criteria for what constitutes a substantial incident, no multi-clock coordination logic — take months to build. The time to close them is now.

What CIRCIA Is and Why It Took This Long

Congress passed the Cyber Incident Reporting for Critical Infrastructure Act in March 2022 as part of the Consolidated Appropriations Act of 2022. The statute directed CISA to publish a final rule by October 2025. CISA published an extensive Notice of Proposed Rulemaking in April 2024, held over 1,200 stakeholder meetings, and conducted a series of virtual town halls in June 2026 — then missed its own statutory deadline.

The delays reflect the complexity of the coverage question. CIRCIA applies to 16 critical infrastructure sectors: chemical, commercial facilities, communications, critical manufacturing, dams, defense industrial base, emergency services, energy, financial services, food and agriculture, government facilities, healthcare, information technology, nuclear reactors/materials/waste, transportation, and water/wastewater systems.

Defining a “covered entity” across 16 sectors — with different size thresholds, different regulatory environments, and different existing reporting frameworks — is genuinely hard. The April 2024 NPRM proposed using SBA size standards as the cutoff, which means large fintechs, payment processors, banks, broker-dealers, and investment advisers above those thresholds would be covered. The final rule is expected to refine those definitions, but the core financial services industry is clearly in scope.

What “Substantial Cyber Incident” Actually Means

This definition is the load-bearing element of CIRCIA compliance. The proposed rule defines a substantial cyber incident as one that causes:

  1. A substantial loss of confidentiality, integrity, or availability of a covered entity’s information system or network
  2. A serious impact on the safety and resiliency of the entity’s operational systems and processes
  3. A disruption of the entity’s ability to engage in business or industrial operations, or deliver goods or services
  4. Unauthorized access facilitated through a compromise of a cloud service provider, managed service provider, other third-party data hosting provider, or a supply chain compromise

The fourth prong deserves attention. A CISA report is triggered when a third party your firm depends on gets compromised and that compromise results in unauthorized access to your systems or data. You don’t need to be the primary target. A cloud provider breach that exposes your customer data is a CIRCIA reportable event for your firm — regardless of whether your own security controls were bypassed.

What doesn’t trigger reporting: malicious activity blocked by a firewall or other security tool before any unauthorized access occurs. A phishing email that a spam filter catches, or a credential stuffing attempt blocked by multi-factor authentication, is not a substantial cyber incident. The threshold is actual impact — not near-miss.

For most financial services firms, this means three categories of incidents require CIRCIA analysis:

  • Direct breaches of internal systems
  • Third-party/vendor incidents that result in access to the firm’s data or systems
  • Supply chain compromises with downstream effects

Most current IR plans are built around the first category. The second and third are where the compliance gap lives.

The Multi-Clock Problem

CIRCIA creates a new reporting obligation that runs concurrently with, but separately from, every existing framework. There is no cross-reporting mechanism — a CISA report does not satisfy your primary regulator, and a notification to your primary regulator does not satisfy CISA.

FrameworkDeadlineRecipientTrigger
Federal banking agency rule (OCC/Fed/FDIC)36 hoursPrimary federal regulatorComputer-security incident that materially disrupts or degrades systems/services
NYDFS Part 50072 hoursNY DFSCybersecurity event that has a reasonable likelihood of materially harming operations
CIRCIA (final rule expected)72 hoursCISASubstantial cyber incident (see above)
Regulation S-P30 daysAffected customersUnauthorized access to or use of customer information
Regulation S-P (vendor clause)72 hoursCovered firmService provider breach involving firm’s customer data
SEC Form 8-K (public companies)4 business daysSEC/investorsMaterial cybersecurity incident
State breach notification30–90 daysState AG, affected residentsPII exposure meeting state thresholds

The practical effect for a large financial services firm: a single incident may trigger six or seven separate reporting obligations running on different clocks to different recipients. CIRCIA’s 72-hour clock starts at discovery. The banking agency 36-hour clock starts at determination that a computer-security incident has occurred. Reg S-P’s 30-day customer clock starts at awareness of unauthorized access. These are legally distinct triggers.

A multi-clock notification matrix — a document that maps each incident type to applicable reporting deadlines, triggers, and recipients — is not optional for regulated financial services firms. It is the infrastructure that makes compliance possible when a breach happens at midnight.

What Your Incident Response Plan Needs Now

Building CIRCIA readiness doesn’t require starting over. It requires four additions to what most programs already have.

1. A CISA reporting track

Your IR plan’s escalation procedures likely route to your primary regulator and legal counsel. Add a CISA track: a defined decision point at which your incident response team evaluates whether the incident is a “substantial cyber incident” under CIRCIA criteria, and a designated person responsible for submitting the CISA report.

CISA will operate a web-based reporting portal. Reports must include: entity name and contact information, the date and approximate time of the incident, a description of the incident, the systems and data affected, and the suspected threat actor and attack vector if known. The portal is designed to accept preliminary information within 72 hours, with supplemental reports to follow.

2. Defined criteria for “substantial cyber incident”

Your IR plan needs a checklist that maps incident characteristics to CIRCIA’s four-part definition. This is not a judgment call made under pressure in the first hour of an incident — it is a documented standard applied consistently.

Build a one-page reference: what characteristics of an incident qualify under each prong of the definition? Who has authority to make the CIRCIA determination? At what point in the incident timeline does the 72-hour clock start (CIRCIA uses “discovery” — define discovery for your context)?

3. Supply chain and vendor incident criteria

Most firms’ IR plans are written around breaches of the firm’s own systems. CIRCIA’s supply chain prong requires a separate analytical path: when a third-party vendor reports a compromise, who at your firm evaluates whether that compromise gives rise to a CIRCIA reporting obligation? What information do you need from the vendor to make that determination?

The vendor notification provisions in your service agreements — the 72-hour breach notification clause that Regulation S-P now requires — become directly relevant here. If a vendor can’t tell you within 72 hours whether a breach affected your data, you may be unable to make a timely CIRCIA determination.

4. Tabletop exercises that include the CISA clock

Tabletop exercises are the only way to stress-test a multi-clock notification matrix before an actual incident. The test matters: your current tabletop scenarios likely don’t include a CIRCIA reporting determination. Add it. Run a supply chain breach scenario where the CISA clock, the banking agency clock, and the Reg S-P customer clock all start at different points based on different discovery triggers.

UK financial regulators recently demonstrated the direction of travel by placing major cloud providers directly under financial regulatory oversight. CIRCIA takes a parallel approach in the US context — making financial services firms responsible for reporting on incidents involving their critical technology dependencies, not just their own systems.

The NYDFS Overlap — and What It Shows About Multi-Regulator Reality

For NY-licensed entities, NYDFS Part 500 and CIRCIA will run in parallel. Both have 72-hour notification requirements. Both cover supply chain compromises. The recipient is different: NYDFS DFS for Part 500, CISA for CIRCIA.

This is the clearest illustration of what the multi-regulator notification environment looks like. You are not sending one report to one regulator. You are sending two reports to two regulators under similar but not identical definitions, using different portals, on timelines that may start at different moments.

NYDFS has been moving toward heightened examination expectations for incident response — including review of whether firms actually have the operational infrastructure to execute multi-clock reporting under pressure. CISA will eventually examine similarly. The pattern is consistent across regulators: incident response is not a policy document exercise.

So What?

The CIRCIA final rule is expected this fall. After publication, compliance obligations don’t start immediately — CISA has indicated there will be time for covered entities to stand up reporting capabilities. But “time to stand up capabilities” isn’t measured in weeks. It’s measured in months: the months it takes to add a CISA track to your IR plan, define your substantial-cyber-incident criteria, update vendor contracts, build the multi-clock matrix, and run a tabletop that actually tests it.

Firms that wait for the compliance deadline to begin building are the firms that scramble. The useful work is the work done before the clock starts.

A Business Continuity & Disaster Recovery Kit includes the BCP and IR plan templates, tabletop exercise scenarios, and documentation frameworks that let you build toward CIRCIA readiness now — not after the final rule drops.

The fifth reporting clock is coming. The multi-clock matrix needs to exist before it starts.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is CIRCIA and who does it cover?
The Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), signed into law in March 2022, requires covered critical infrastructure entities to report substantial cyber incidents to CISA within 72 hours and ransom payments within 24 hours. Covered entities span all 16 critical infrastructure sectors, including financial services, and are generally organizations that exceed Small Business Administration size standards in their industry. The Cybersecurity and Infrastructure Security Agency (CISA) is the designated recipient for all CIRCIA reports.
What counts as a 'substantial cyber incident' under CIRCIA?
Under the NPRM, a substantial cyber incident is one that causes: (a) a substantial loss of confidentiality, integrity, or availability of an information system or network; (b) a serious impact on the safety or resiliency of operational systems; (c) a disruption of the ability to engage in business operations or deliver goods and services; or (d) unauthorized access facilitated through a compromise of a cloud service provider, managed service provider, other third-party data hosting provider, or a supply chain compromise. Malicious activity blocked by security tools before gaining access is not a qualifying event.
Does filing a CIRCIA report satisfy my SEC, NYDFS, or banking agency reporting obligations?
No. CIRCIA creates a separate CISA reporting obligation that runs in parallel to existing frameworks. A 72-hour CIRCIA report to CISA does not satisfy the federal banking agencies' 36-hour computer-security incident notification requirement, NYDFS Part 500's 72-hour notification to the Department of Financial Services, Regulation S-P's 30-day customer notification obligation, or the SEC's 8-K disclosure requirement for publicly traded companies. Each clock runs independently.
When do financial services firms need to comply?
The final rule has not yet been published as of September 30, 2026. CISA has targeted fall 2026 for finalization. After publication, CIRCIA's statute provides that compliance timelines begin after the rule takes effect — but given the program's complexity and the volume of affected entities, a grace period of months to years between publication and enforcement is expected. Building compliance capabilities now, before the clock starts, is the practical approach.
What are the penalties for not reporting under CIRCIA?
CIRCIA grants CISA subpoena authority to compel submission of CIRCIA reports that were required but not filed. Entities that ignore a CISA subpoena can be referred to the Department of Justice for enforcement. CIRCIA also allows CISA to refer non-compliant entities to relevant sector-specific agencies — which means financial services firms could see CIRCIA non-compliance referred to the OCC, FDIC, or Federal Reserve.
Supply chain and third-party incidents are explicitly covered. What does that mean in practice?
If a cloud provider, managed service provider, or other third-party data hosting provider your firm uses experiences a compromise that results in unauthorized access to your systems or data, that event may trigger CIRCIA reporting even if your own systems were not directly breached. This supply chain nexus is broader than what most firms' current incident response plans address — and it applies whether or not the third party itself has reported the incident to CISA.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Business Continuity & Disaster Recovery (BCP/DR) Kit

BCP and DR templates with BIA, recovery procedures, and a standalone tabletop exercise kit.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.