Feature Cybersecurity
CIRCIA 72-Hour Reporting: A Pre-Final-Rule Compliance Guide
CIRCIA reporting is not yet mandatory. Build a conditional 72-hour and 24-hour workflow while keeping the existing bank 36-hour rule live.
Table of Contents
August 17, 2026 correction: CIRCIA reporting is not currently mandatory. No final rule or September 2026 effective date had been issued. Every 72-hour or 24-hour CIRCIA step below is future-state planning based on the statute and 2024 NPRM.
TL;DR
- CISA’s status page says reporting begins only after the final rule goes into effect.
- The proposed architecture uses a 72-hour covered-incident clock and a 24-hour ransom-payment clock.
- Coverage and detailed procedures remain provisional.
- The banking agencies’ current 36-hour notification rule remains operative.
Start With Legal Status
CIRCIA was enacted in 2022 and directs CISA to establish a reporting regime by rule. CISA published a detailed NPRM in April 2024.
An NPRM supplies proposed text and a comment record. It does not create the current filing obligation. In 2026 CISA also held town halls, confirming that rulemaking work continued.
A defensible policy status line is:
CIRCIA is enacted, but mandatory reports begin only after CISA’s final rule goes into effect. The 2024 NPRM is used for provisional readiness and must be revalidated.
What the Future-State Workflow Should Model
The statute and NPRM contemplate:
- a covered cyber-incident report within 72 hours after the relevant statutory trigger;
- a ransom-payment report within 24 hours after payment; and
- supplemental reporting in circumstances defined by the implementing rule.
Do not convert proposal details into final policy language. Use conditional verbs—would, proposed, and if covered—for coverage, definitions, form fields, preservation, and enforcement mechanics.
Step 1: Record a Provisional Coverage View
For each legal entity, retain:
| Field | Evidence |
|---|---|
| Legal entity and services | Charter, registrations, product and service inventory |
| Critical-infrastructure sector | Applicable sector analysis |
| Proposed coverage criterion | Exact NPRM provision and supporting facts |
| Proposed exception | Exact provision and evidence |
| Owner and review date | Named legal/compliance owner |
| Final-rule trigger | Mandatory revalidation task |
Financial-services sector membership alone is not enough to declare every firm covered.
Step 2: Use One Incident Intake
Capture facts once across security, legal, operations, vendors, communications, and finance:
- incident discovery and escalation timestamps;
- affected systems and services;
- business and customer impact;
- suspected cause and attack vector;
- data and account impact;
- third-party involvement;
- recovery status;
- ransom demand, payment, and facilitator facts; and
- known or expected regulatory and contractual notices.
Route that record to separate trigger analyses. Do not use a CIRCIA assessment as a substitute for a bank, SEC, state, insurance, or contract analysis.
Step 3: Keep the Current Bank Rule Active
The federal banking agencies’ rule requires covered banking organizations to notify their primary federal regulator as soon as possible and no later than 36 hours after determining that an incident rises to the level of a notification incident.
The future CIRCIA framework has a different agency, scope, trigger, and clock. A playbook should show both:
| Analysis | Status | Recipient | Clock concept |
|---|---|---|---|
| Bank computer-security incident notice | Current | Primary federal banking regulator | No later than 36 hours after determination |
| CIRCIA covered incident | Future pending final rule | CISA | Statutory/proposed 72-hour framework |
| CIRCIA ransom payment | Future pending final rule | CISA | Statutory/proposed 24-hour framework |
Step 4: Preserve Trigger Decisions
For every possible notice, record:
- the legal trigger tested;
- the facts known at the time;
- when the decision-maker received those facts;
- open questions and investigation owner;
- decision, rationale, and approver; and
- the next review time.
A timer that starts on generic “discovery” can be wrong. Different regimes use determination, reasonable belief, materiality, harm, payment, or other events.
Step 5: Map Proposed Report Fields
Create a future-state data map, not a filing promise. Likely owners include:
- security operations for technical indicators and attack vector;
- infrastructure and vendors for affected systems and third parties;
- business continuity for service impact and recovery;
- legal for privilege, trigger, and law-enforcement coordination;
- finance for ransom-payment facts; and
- communications for customer and public statements.
Mark every field PROPOSED—VERIFY AGAINST FINAL RULE.
Step 6: Tabletop Concurrent Duties
Use a scenario involving a cloud or software provider, uncertain customer impact, an evolving recovery estimate, and a possible ransom payment. Require the team to:
- make the current bank 36-hour determination;
- analyze other live obligations;
- run the proposed CIRCIA module separately;
- identify evidence gaps; and
- draft an executive status update that states legal status correctly.
Step 7: Install the Final-Rule Change Trigger
Monitor CISA’s CIRCIA FAQs and Federal Register. Final publication should trigger:
- legal-entity coverage revalidation;
- NPRM-to-final redline;
- effective-date and transition analysis;
- form and submission testing;
- policy and contract updates;
- role-based training; and
- a post-update exercise.
So What?
Build the evidence and decision workflow now, because short incident clocks are difficult to improvise. But keep the status label accurate: CIRCIA is not yet an operative filing duty.
For the consolidated current-status analysis, see CIRCIA Status in August 2026.
The Incident Response & Breach Notification Kit can organize ownership and evidence. It must be adapted to the effective final rule before use as a CIRCIA filing procedure.
Primary sources: CISA CIRCIA status | CISA FAQs | 2024 NPRM | 2026 town-hall notice | Federal banking agencies’ 36-hour rule announcement
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Incident Response & Breach Notification Kit
Step-by-step incident response playbooks and breach notification templates for all 50 states.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Must financial institutions file CIRCIA reports now?
What reporting clocks does CIRCIA contemplate?
Does every bank or fintech qualify as a covered entity?
What incident-reporting rule applies to banks today?
How can a team prepare without treating the NPRM as law?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Incident Response & Breach Notification Kit
Step-by-step incident response playbooks and breach notification templates for all 50 states.