What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
No CIRCIA report is mandatory yet. CISA states: “Until the effective date of the final rule, organizations are not required to submit covered cyber incident or ransom payment reports under CIRCIA.” The proposed rule is still being developed as of September 28, 2026; a timetable entry in the 2026 Unified Agenda is not proof that a final, effective regulation has been published.
Where CIRCIA stands in 2026
The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) directs the Cybersecurity and Infrastructure Security Agency (CISA) to establish reporting requirements for covered cyber incidents and ransom payments.
Proposed rule and comment period
CISA published its notice of proposed rulemaking (NPRM) on April 4, 2024. The comment period ultimately closed on July 3, 2024. The NPRM is not the final compliance rule, and its definitions, deadlines and reporting fields can change.
What CISA has done since the NPRM
CISA held four town halls in June 2026 and says it continues work on the final rule after funding lapses. The 2026 Unified Agenda lists the rule at the final-rule stage under RIN 1670-AA04 and includes a September 2026 timetable entry. That date is an internal planning milestone, not evidence that the final rule has been issued or taken effect.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
Does CIRCIA apply to your company?
A company cannot determine its final CIRCIA status from the NPRM alone. The final rule will establish which organizations qualify as covered entities and how the reporting thresholds apply. CISA’s estimate of the rule’s reach is therefore a proposal-stage estimate rather than a definitive list of regulated businesses.
What the proposal calls a covered cyber incident
The NPRM generally frames a covered cyber incident as a substantial cyber incident. Proposed triggers include one or more of the following:
Rank #2
- Ideal for Gifting
- Ideal for a bookworm
- Compact for travelling
- A substantial loss of confidentiality, integrity or availability of information or systems.
- A serious impact on safety or the resiliency of operations.
- Disruption of business or industrial operations, or of the delivery of goods and services.
- Unauthorized access facilitated through a cloud-service provider, managed-service provider or third-party host.
- A supply-chain compromise that produces the required level of impact.
These are proposed standards. The final definitions and any thresholds for particular sectors or entity types may differ.
What the 316,000 figure means
A 2024 U.S. House hearing record quotes a CISA estimate of more than 316,000 companies potentially affected by the proposed rule. The same record says CISA anticipated more than 15,000 incident reports per year. Both numbers are planning estimates tied to the proposal; they are not a final count of covered entities or a guaranteed annual workload.
Recommended Free Tools
Rank #3
Proposed reporting deadlines
The NPRM sets two principal clocks. Their starting points and treatment of follow-up information are summarized below.
| Report | Proposed trigger | Proposed deadline | Important qualification |
|---|---|---|---|
| Covered cyber-incident report | When a covered entity reasonably believes a covered cyber incident occurred | Within 72 hours | The definition of a covered incident and the final clock could change. |
| Ransom-payment report | Payment of ransom in connection with an incident | Within 24 hours after payment | This is a proposed obligation, not an operative CIRCIA deadline before the final rule takes effect. |
| Supplemental information | Material developments after the initial submission | As needed until the incident is concluded, fully mitigated and resolved | The NPRM contemplates continuing updates rather than a single immutable filing. |
One submission can cover both events
If a ransom payment occurs before the proposed incident-report deadline, the NPRM would allow one joint report to satisfy both proposed reporting obligations. Organizations would still need to provide later supplemental information until the matter is concluded and resolved.
Rank #4
How ransomware payments would be treated
The proposed 24-hour payment report is separate from the proposed 72-hour incident report unless the timing permits a joint submission. A payment report would capture payment and threat-actor details along with the incident information required by the rule. Because the NPRM is not final, organizations should not treat the proposed 24-hour period as a current CISA filing requirement.
What organizations should prepare now
CISA’s proposed data fields provide a practical basis for improving incident-response records, even though they are not a final compliance checklist.
Best Value
- It can be a gift option
- Comes with secure packaging
- Helpful in various ways
Map existing records to likely CIRCIA fields
- Affected systems, networks and devices.
- Incident start, detection and mitigation dates.
- Operational effects, including disruption to business, industrial activity or service delivery.
- Details about unauthorized access and information affected.
- Exploited vulnerabilities and defensive measures taken.
- Attacker tactics, techniques and procedures.
- Categories of information accessed or acquired.
- Ransom-payment amount, method, timing and threat-actor information when applicable.
Preserve evidence for later updates
Incident logs, forensic images, identity and access records, cloud-provider notifications, communications with managed-service providers and payment documentation can help support an initial report and subsequent updates. Keep timestamps and decision records showing when the organization first reasonably believed an incident met the proposed threshold.
Assign ownership and escalation paths
Define who can declare an incident, who approves external reporting, how legal and security teams coordinate, and how executives are notified. Include cloud, managed-service, hosting and supply-chain contacts so that third-party evidence is available quickly.
Account for overlapping duties
CIRCIA would not automatically replace reporting required by the Securities and Exchange Commission, the Transportation Security Administration, a sector regulator, a state authority or a contract. Compare each obligation’s trigger threshold, clock start, ransom-payment treatment, data fields, supplemental-update rules, receiving agency, confidentiality or safe-harbor provisions, and any exception for a substantially similar report. The NPRM discusses such an exception, but the final rule may revise it.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Voluntary reporting before the final rule
Although mandatory CIRCIA submissions are not yet in force, CISA encourages organizations to voluntarily report unusual cyber activity and incidents during the rulemaking period. CISA says this information helps it “rapidly deploy resources and render assistance to victims suffering attacks, analyze incoming reporting across sectors to spot trends, and quickly share that information with network defenders to warn other potential victims.” Organizations should use CISA’s current voluntary-reporting channels and confirm any submission instructions directly with the agency.
Quick Recap
Preparation checklist for the final rule
- Identify the systems, services and business processes whose disruption would have significant operational or safety effects.
- Make sure incident-response records capture the proposed CIRCIA data fields and reliable timestamps.
- Document escalation criteria for suspected substantial incidents and ransom payments.
- Confirm contracts require timely notice from cloud, managed-service, hosting and other critical providers.
- Inventory other federal, state, sectoral and contractual reporting deadlines that could run at the same time.
- Set a process for preserving evidence and issuing supplemental updates as facts change.
- Monitor CISA’s final-rule publication and effective date rather than relying on the Unified Agenda’s planning date.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




