Skip to content
RiskTemplates · The Daily Brief Saturday, August 22, 2026
Wire SEC's Tricolor Fraud Case: The Double-Pledging Controls Lenders Missed AUG 20

Feature Cybersecurity

CIRCIA 72-Hour Reporting: A Pre-Final-Rule Compliance Guide

CIRCIA reporting is not yet mandatory. Build a conditional 72-hour and 24-hour workflow while keeping the existing bank 36-hour rule live.

By Rebecca Leung · June 30, 2026 ·
Table of Contents

August 17, 2026 correction: CIRCIA reporting is not currently mandatory. No final rule or September 2026 effective date had been issued. Every 72-hour or 24-hour CIRCIA step below is future-state planning based on the statute and 2024 NPRM.

TL;DR

  • CISA’s status page says reporting begins only after the final rule goes into effect.
  • The proposed architecture uses a 72-hour covered-incident clock and a 24-hour ransom-payment clock.
  • Coverage and detailed procedures remain provisional.
  • The banking agencies’ current 36-hour notification rule remains operative.

CIRCIA was enacted in 2022 and directs CISA to establish a reporting regime by rule. CISA published a detailed NPRM in April 2024.

An NPRM supplies proposed text and a comment record. It does not create the current filing obligation. In 2026 CISA also held town halls, confirming that rulemaking work continued.

A defensible policy status line is:

CIRCIA is enacted, but mandatory reports begin only after CISA’s final rule goes into effect. The 2024 NPRM is used for provisional readiness and must be revalidated.

What the Future-State Workflow Should Model

The statute and NPRM contemplate:

  • a covered cyber-incident report within 72 hours after the relevant statutory trigger;
  • a ransom-payment report within 24 hours after payment; and
  • supplemental reporting in circumstances defined by the implementing rule.

Do not convert proposal details into final policy language. Use conditional verbs—would, proposed, and if covered—for coverage, definitions, form fields, preservation, and enforcement mechanics.

Step 1: Record a Provisional Coverage View

For each legal entity, retain:

FieldEvidence
Legal entity and servicesCharter, registrations, product and service inventory
Critical-infrastructure sectorApplicable sector analysis
Proposed coverage criterionExact NPRM provision and supporting facts
Proposed exceptionExact provision and evidence
Owner and review dateNamed legal/compliance owner
Final-rule triggerMandatory revalidation task

Financial-services sector membership alone is not enough to declare every firm covered.

Step 2: Use One Incident Intake

Capture facts once across security, legal, operations, vendors, communications, and finance:

  • incident discovery and escalation timestamps;
  • affected systems and services;
  • business and customer impact;
  • suspected cause and attack vector;
  • data and account impact;
  • third-party involvement;
  • recovery status;
  • ransom demand, payment, and facilitator facts; and
  • known or expected regulatory and contractual notices.

Route that record to separate trigger analyses. Do not use a CIRCIA assessment as a substitute for a bank, SEC, state, insurance, or contract analysis.

Step 3: Keep the Current Bank Rule Active

The federal banking agencies’ rule requires covered banking organizations to notify their primary federal regulator as soon as possible and no later than 36 hours after determining that an incident rises to the level of a notification incident.

The future CIRCIA framework has a different agency, scope, trigger, and clock. A playbook should show both:

AnalysisStatusRecipientClock concept
Bank computer-security incident noticeCurrentPrimary federal banking regulatorNo later than 36 hours after determination
CIRCIA covered incidentFuture pending final ruleCISAStatutory/proposed 72-hour framework
CIRCIA ransom paymentFuture pending final ruleCISAStatutory/proposed 24-hour framework

Step 4: Preserve Trigger Decisions

For every possible notice, record:

  • the legal trigger tested;
  • the facts known at the time;
  • when the decision-maker received those facts;
  • open questions and investigation owner;
  • decision, rationale, and approver; and
  • the next review time.

A timer that starts on generic “discovery” can be wrong. Different regimes use determination, reasonable belief, materiality, harm, payment, or other events.

Step 5: Map Proposed Report Fields

Create a future-state data map, not a filing promise. Likely owners include:

  • security operations for technical indicators and attack vector;
  • infrastructure and vendors for affected systems and third parties;
  • business continuity for service impact and recovery;
  • legal for privilege, trigger, and law-enforcement coordination;
  • finance for ransom-payment facts; and
  • communications for customer and public statements.

Mark every field PROPOSED—VERIFY AGAINST FINAL RULE.

Step 6: Tabletop Concurrent Duties

Use a scenario involving a cloud or software provider, uncertain customer impact, an evolving recovery estimate, and a possible ransom payment. Require the team to:

  1. make the current bank 36-hour determination;
  2. analyze other live obligations;
  3. run the proposed CIRCIA module separately;
  4. identify evidence gaps; and
  5. draft an executive status update that states legal status correctly.

Step 7: Install the Final-Rule Change Trigger

Monitor CISA’s CIRCIA FAQs and Federal Register. Final publication should trigger:

  • legal-entity coverage revalidation;
  • NPRM-to-final redline;
  • effective-date and transition analysis;
  • form and submission testing;
  • policy and contract updates;
  • role-based training; and
  • a post-update exercise.

So What?

Build the evidence and decision workflow now, because short incident clocks are difficult to improvise. But keep the status label accurate: CIRCIA is not yet an operative filing duty.

For the consolidated current-status analysis, see CIRCIA Status in August 2026.

The Incident Response & Breach Notification Kit can organize ownership and evidence. It must be adapted to the effective final rule before use as a CIRCIA filing procedure.


Primary sources: CISA CIRCIA status | CISA FAQs | 2024 NPRM | 2026 town-hall notice | Federal banking agencies’ 36-hour rule announcement

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Must financial institutions file CIRCIA reports now?
No. As of August 17, 2026, CISA had not issued the final rule, and CISA states that mandatory CIRCIA reporting will begin only after the final rule goes into effect.
What reporting clocks does CIRCIA contemplate?
The statute and 2024 NPRM contemplate a 72-hour report for a covered cyber incident and a 24-hour report after a ransom payment. Detailed scope, triggers, fields, procedures, and effective timing depend on the final rule.
Does every bank or fintech qualify as a covered entity?
Not automatically. The 2024 NPRM contains proposed sector, size, category, and exception criteria. Record a provisional view and revalidate the exact legal entity against final text.
What incident-reporting rule applies to banks today?
The federal banking agencies' existing rule requires a covered banking organization to notify its primary federal regulator as soon as possible and no later than 36 hours after determining that a computer-security incident is a notification incident.
How can a team prepare without treating the NPRM as law?
Create a clearly labeled future-state CIRCIA module, map proposed fields to evidence owners, preserve trigger timestamps, tabletop concurrent analyses, and assign an owner to activate a final-rule redline.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Incident Response & Breach Notification Kit

Step-by-step incident response playbooks and breach notification templates for all 50 states.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.