CISA Submitted Final Cyber Reporting Rule
The cybersecurity agency delivered the CIRCIA rule to federal regulators for final review.
Updated on Oct. 2, 2026 in Cybersecurity

Live Poll
Should the government mandate standardized cyber incident reporting for all critical infrastructure sectors?
The Cybersecurity and Infrastructure Security Agency submitted its final CIRCIA rule to the Office of Management and Budget on October 1, 2026. This regulation follows a 2022 Congressional mandate designed to standardize reporting requirements for critical infrastructure entities.
Why it matters
The agency aims to provide clear reporting protocols to the industry, addressing regulatory delays caused by the need for extensive due diligence across multiple sectors. Finalizing this rule is intended to streamline incident response and data management standards for thousands of organizations.
The proposal mandates a 72-hour window for reporting cyber incidents and a 24-hour deadline for disclosing ransom payments. It also requires entities to maintain two years of incident data, a significant increase from previous standards like the 90-day DFARS requirement.
The players
CISA
The Cybersecurity and Infrastructure Security Agency is the federal agency responsible for protecting the nation's critical infrastructure from cyber threats.
Office of Management and Budget
The Office of Management and Budget is the federal agency within the White House that oversees the performance of federal agencies and manages the administration's budget.
GAO
The Government Accountability Office is a non-partisan legislative branch agency that provides auditing, evaluation, and investigative services for the United States Congress.
DHS
The Department of Homeland Security is the cabinet-level federal department responsible for public security, including anti-terrorism and border control.
The details
The rule affects approximately 300,000 organizations that must comply with new reporting and record-keeping protocols. CISA finalized the proposal after holding stakeholder town halls to address concerns regarding the complexity of existing federal cybersecurity oversight.
Timeline
Congress mandated the creation of the CIRCIA rule in 2022.
CISA moved its internal target date for the rule in May 2026.
DHS held stakeholder town halls on the rule in June 2026.
A GAO report on regulatory overlap was published in July 2026.
CISA submitted the final rule for review on October 1, 2026.
The Tech Race
This story follows a pattern set by the July 2026 GAO report on federal cybersecurity regulatory overlap, which identified that 70% of existing regulations contain duplicative requirements. The new rule represents a shift toward replacing fragmented legacy policies with a centralized, unified standard for incident reporting.
For affected organizations, this rule necessitates immediate updates to internal IT documentation and incident response playbooks to meet the strict 72-hour reporting timeline. Firms will also need to reconfigure data storage systems to ensure compliance with the mandatory two-year retention requirement.
The takeaway
The move toward mandatory, time-sensitive incident reporting reflects the government's effort to gain better visibility into the national threat landscape. Businesses should prioritize auditing their current data retention policies to prepare for these upcoming federal obligations.
Further reading
Learn more about evolving Cybersecurity standards and federal compliance requirements on our site.
Live Poll
Should the government mandate standardized cyber incident reporting for all critical infrastructure sectors?










