Feature Business Continuity
CISA Is Finalizing CIRCIA This Fall. Here's What Financial Services Needs to Build Before the 72-Hour Clock Starts.
The Cyber Incident Reporting for Critical Infrastructure Act final rule is expected this fall. Financial services firms face a new CISA reporting clock on top of existing SEC, NYDFS, and banking agency deadlines. Here is what practitioners need to build now.
Table of Contents
TL;DR
- CISA has targeted fall 2026 to issue the final CIRCIA rule, creating a new federal 72-hour cyber incident reporting obligation for financial services firms — on top of the 36-hour banking agency requirement, NYDFS’s 72-hour DFS notification, Reg S-P’s 30-day customer clock, and SEC 8-K for public companies
- “Substantial cyber incident” includes supply chain and managed service provider compromises that result in unauthorized access — a category many financial services IR plans don’t explicitly address
- CIRCIA creates separate reporting to CISA; a report to your primary regulator does not satisfy CIRCIA and vice versa
- Compliance timelines won’t begin immediately on publication, but the gaps in most programs — no CISA reporting track, no supply-chain incident criteria, no multi-clock notification matrix — won’t close overnight
Your incident response plan probably has a reporting section. It likely includes the federal banking agencies’ 36-hour notification requirement, the NYDFS 72-hour obligation if your firm is New York-licensed, Regulation S-P’s 30-day customer notification clock, and state breach notification laws that vary from 30 to 90 days depending on jurisdiction.
CIRCIA adds a fifth clock.
The Cybersecurity and Infrastructure Security Agency has been working toward the CIRCIA final rule since 2022, missed its October 2025 statutory deadline, and has targeted fall 2026 for publication. When the rule goes final, covered financial services entities — broadly, those above SBA size standards — will face a mandatory 72-hour reporting obligation to CISA for substantial cyber incidents and a separate 24-hour obligation for ransom payments.
The rule isn’t in effect yet. But the gaps in most firms’ incident response programs — no CISA reporting track, no defined criteria for what constitutes a substantial incident, no multi-clock coordination logic — take months to build. The time to close them is now.
What CIRCIA Is and Why It Took This Long
Congress passed the Cyber Incident Reporting for Critical Infrastructure Act in March 2022 as part of the Consolidated Appropriations Act of 2022. The statute directed CISA to publish a final rule by October 2025. CISA published an extensive Notice of Proposed Rulemaking in April 2024, held over 1,200 stakeholder meetings, and conducted a series of virtual town halls in June 2026 — then missed its own statutory deadline.
The delays reflect the complexity of the coverage question. CIRCIA applies to 16 critical infrastructure sectors: chemical, commercial facilities, communications, critical manufacturing, dams, defense industrial base, emergency services, energy, financial services, food and agriculture, government facilities, healthcare, information technology, nuclear reactors/materials/waste, transportation, and water/wastewater systems.
Defining a “covered entity” across 16 sectors — with different size thresholds, different regulatory environments, and different existing reporting frameworks — is genuinely hard. The April 2024 NPRM proposed using SBA size standards as the cutoff, which means large fintechs, payment processors, banks, broker-dealers, and investment advisers above those thresholds would be covered. The final rule is expected to refine those definitions, but the core financial services industry is clearly in scope.
What “Substantial Cyber Incident” Actually Means
This definition is the load-bearing element of CIRCIA compliance. The proposed rule defines a substantial cyber incident as one that causes:
- A substantial loss of confidentiality, integrity, or availability of a covered entity’s information system or network
- A serious impact on the safety and resiliency of the entity’s operational systems and processes
- A disruption of the entity’s ability to engage in business or industrial operations, or deliver goods or services
- Unauthorized access facilitated through a compromise of a cloud service provider, managed service provider, other third-party data hosting provider, or a supply chain compromise
The fourth prong deserves attention. A CISA report is triggered when a third party your firm depends on gets compromised and that compromise results in unauthorized access to your systems or data. You don’t need to be the primary target. A cloud provider breach that exposes your customer data is a CIRCIA reportable event for your firm — regardless of whether your own security controls were bypassed.
What doesn’t trigger reporting: malicious activity blocked by a firewall or other security tool before any unauthorized access occurs. A phishing email that a spam filter catches, or a credential stuffing attempt blocked by multi-factor authentication, is not a substantial cyber incident. The threshold is actual impact — not near-miss.
For most financial services firms, this means three categories of incidents require CIRCIA analysis:
- Direct breaches of internal systems
- Third-party/vendor incidents that result in access to the firm’s data or systems
- Supply chain compromises with downstream effects
Most current IR plans are built around the first category. The second and third are where the compliance gap lives.
The Multi-Clock Problem
CIRCIA creates a new reporting obligation that runs concurrently with, but separately from, every existing framework. There is no cross-reporting mechanism — a CISA report does not satisfy your primary regulator, and a notification to your primary regulator does not satisfy CISA.
| Framework | Deadline | Recipient | Trigger |
|---|---|---|---|
| Federal banking agency rule (OCC/Fed/FDIC) | 36 hours | Primary federal regulator | Computer-security incident that materially disrupts or degrades systems/services |
| NYDFS Part 500 | 72 hours | NY DFS | Cybersecurity event that has a reasonable likelihood of materially harming operations |
| CIRCIA (final rule expected) | 72 hours | CISA | Substantial cyber incident (see above) |
| Regulation S-P | 30 days | Affected customers | Unauthorized access to or use of customer information |
| Regulation S-P (vendor clause) | 72 hours | Covered firm | Service provider breach involving firm’s customer data |
| SEC Form 8-K (public companies) | 4 business days | SEC/investors | Material cybersecurity incident |
| State breach notification | 30–90 days | State AG, affected residents | PII exposure meeting state thresholds |
The practical effect for a large financial services firm: a single incident may trigger six or seven separate reporting obligations running on different clocks to different recipients. CIRCIA’s 72-hour clock starts at discovery. The banking agency 36-hour clock starts at determination that a computer-security incident has occurred. Reg S-P’s 30-day customer clock starts at awareness of unauthorized access. These are legally distinct triggers.
A multi-clock notification matrix — a document that maps each incident type to applicable reporting deadlines, triggers, and recipients — is not optional for regulated financial services firms. It is the infrastructure that makes compliance possible when a breach happens at midnight.
What Your Incident Response Plan Needs Now
Building CIRCIA readiness doesn’t require starting over. It requires four additions to what most programs already have.
1. A CISA reporting track
Your IR plan’s escalation procedures likely route to your primary regulator and legal counsel. Add a CISA track: a defined decision point at which your incident response team evaluates whether the incident is a “substantial cyber incident” under CIRCIA criteria, and a designated person responsible for submitting the CISA report.
CISA will operate a web-based reporting portal. Reports must include: entity name and contact information, the date and approximate time of the incident, a description of the incident, the systems and data affected, and the suspected threat actor and attack vector if known. The portal is designed to accept preliminary information within 72 hours, with supplemental reports to follow.
2. Defined criteria for “substantial cyber incident”
Your IR plan needs a checklist that maps incident characteristics to CIRCIA’s four-part definition. This is not a judgment call made under pressure in the first hour of an incident — it is a documented standard applied consistently.
Build a one-page reference: what characteristics of an incident qualify under each prong of the definition? Who has authority to make the CIRCIA determination? At what point in the incident timeline does the 72-hour clock start (CIRCIA uses “discovery” — define discovery for your context)?
3. Supply chain and vendor incident criteria
Most firms’ IR plans are written around breaches of the firm’s own systems. CIRCIA’s supply chain prong requires a separate analytical path: when a third-party vendor reports a compromise, who at your firm evaluates whether that compromise gives rise to a CIRCIA reporting obligation? What information do you need from the vendor to make that determination?
The vendor notification provisions in your service agreements — the 72-hour breach notification clause that Regulation S-P now requires — become directly relevant here. If a vendor can’t tell you within 72 hours whether a breach affected your data, you may be unable to make a timely CIRCIA determination.
4. Tabletop exercises that include the CISA clock
Tabletop exercises are the only way to stress-test a multi-clock notification matrix before an actual incident. The test matters: your current tabletop scenarios likely don’t include a CIRCIA reporting determination. Add it. Run a supply chain breach scenario where the CISA clock, the banking agency clock, and the Reg S-P customer clock all start at different points based on different discovery triggers.
UK financial regulators recently demonstrated the direction of travel by placing major cloud providers directly under financial regulatory oversight. CIRCIA takes a parallel approach in the US context — making financial services firms responsible for reporting on incidents involving their critical technology dependencies, not just their own systems.
The NYDFS Overlap — and What It Shows About Multi-Regulator Reality
For NY-licensed entities, NYDFS Part 500 and CIRCIA will run in parallel. Both have 72-hour notification requirements. Both cover supply chain compromises. The recipient is different: NYDFS DFS for Part 500, CISA for CIRCIA.
This is the clearest illustration of what the multi-regulator notification environment looks like. You are not sending one report to one regulator. You are sending two reports to two regulators under similar but not identical definitions, using different portals, on timelines that may start at different moments.
NYDFS has been moving toward heightened examination expectations for incident response — including review of whether firms actually have the operational infrastructure to execute multi-clock reporting under pressure. CISA will eventually examine similarly. The pattern is consistent across regulators: incident response is not a policy document exercise.
So What?
The CIRCIA final rule is expected this fall. After publication, compliance obligations don’t start immediately — CISA has indicated there will be time for covered entities to stand up reporting capabilities. But “time to stand up capabilities” isn’t measured in weeks. It’s measured in months: the months it takes to add a CISA track to your IR plan, define your substantial-cyber-incident criteria, update vendor contracts, build the multi-clock matrix, and run a tabletop that actually tests it.
Firms that wait for the compliance deadline to begin building are the firms that scramble. The useful work is the work done before the clock starts.
A Business Continuity & Disaster Recovery Kit includes the BCP and IR plan templates, tabletop exercise scenarios, and documentation frameworks that let you build toward CIRCIA readiness now — not after the final rule drops.
The fifth reporting clock is coming. The multi-clock matrix needs to exist before it starts.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Business Continuity & Disaster Recovery (BCP/DR) Kit
BCP and DR templates with BIA, recovery procedures, and a standalone tabletop exercise kit.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is CIRCIA and who does it cover?
What counts as a 'substantial cyber incident' under CIRCIA?
Does filing a CIRCIA report satisfy my SEC, NYDFS, or banking agency reporting obligations?
When do financial services firms need to comply?
What are the penalties for not reporting under CIRCIA?
Supply chain and third-party incidents are explicitly covered. What does that mean in practice?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Business Continuity & Disaster Recovery (BCP/DR) Kit
BCP and DR templates with BIA, recovery procedures, and a standalone tabletop exercise kit.
◆ Keep reading
Related posts.
Business Continuity
The UK Just Put AWS, Azure, Google Cloud, and Oracle Under Direct Financial Regulatory Oversight. Here's What US Financial Services Needs to Build for Cloud Concentration Risk.
On July 13, 2026, the UK's Critical Third Parties regime went live with four cloud hyperscalers designated under direct FCA/PRA oversight. The US interagency TPRM proposed guidance addresses the same concentration risk. Here's what your business continuity and vendor risk programs need to do.
Sep 22, 2026
Business Continuity
The OCC's 2026 Cybersecurity Report Changed the Standard. Documenting Controls Isn't Enough Anymore.
The OCC's June 2026 Cybersecurity and Financial System Resilience Report shifts examiner expectations from control documentation to demonstrated, tested capability. Here is what that means for your program.
Sep 19, 2026
Business Continuity
AWS Went Down in October. Most BCPs Assumed It Wouldn't. Here's How to Fix That.
The October 2025 AWS DNS outage knocked out DynamoDB endpoints across multiple regions. Most financial institution BCPs treat cloud infrastructure as a given, not a dependency to plan around. Here's what FFIEC and DORA actually require — and what cloud-aware recovery planning looks like.
Sep 12, 2026