CISA Submitted Final Cyber Reporting Rule

The cybersecurity agency delivered the CIRCIA rule to federal regulators for final review.

Updated on Oct. 2, 2026 in Cybersecurity

Isometric editorial illustration of a large, monolithic server rack in a clean, minimalist data environment.
The Cybersecurity and Infrastructure Security Agency submitted the final CIRCIA rule to the Office of Management and Budget for review on October 1, 2026. AI Illustration. Upload story photo >

Live Poll

Should the government mandate standardized cyber incident reporting for all critical infrastructure sectors?

The Cybersecurity and Infrastructure Security Agency submitted its final CIRCIA rule to the Office of Management and Budget on October 1, 2026. This regulation follows a 2022 Congressional mandate designed to standardize reporting requirements for critical infrastructure entities.

Why it matters

The agency aims to provide clear reporting protocols to the industry, addressing regulatory delays caused by the need for extensive due diligence across multiple sectors. Finalizing this rule is intended to streamline incident response and data management standards for thousands of organizations.

The proposal mandates a 72-hour window for reporting cyber incidents and a 24-hour deadline for disclosing ransom payments. It also requires entities to maintain two years of incident data, a significant increase from previous standards like the 90-day DFARS requirement.

The players

CISA

The Cybersecurity and Infrastructure Security Agency is the federal agency responsible for protecting the nation's critical infrastructure from cyber threats.

Office of Management and Budget

The Office of Management and Budget is the federal agency within the White House that oversees the performance of federal agencies and manages the administration's budget.

GAO

The Government Accountability Office is a non-partisan legislative branch agency that provides auditing, evaluation, and investigative services for the United States Congress.

DHS

The Department of Homeland Security is the cabinet-level federal department responsible for public security, including anti-terrorism and border control.

The details

The rule affects approximately 300,000 organizations that must comply with new reporting and record-keeping protocols. CISA finalized the proposal after holding stakeholder town halls to address concerns regarding the complexity of existing federal cybersecurity oversight.

Timeline

  1. Congress mandated the creation of the CIRCIA rule in 2022.

  2. CISA moved its internal target date for the rule in May 2026.

  3. DHS held stakeholder town halls on the rule in June 2026.

  4. A GAO report on regulatory overlap was published in July 2026.

  5. CISA submitted the final rule for review on October 1, 2026.

The Tech Race

This story follows a pattern set by the July 2026 GAO report on federal cybersecurity regulatory overlap, which identified that 70% of existing regulations contain duplicative requirements. The new rule represents a shift toward replacing fragmented legacy policies with a centralized, unified standard for incident reporting.

For affected organizations, this rule necessitates immediate updates to internal IT documentation and incident response playbooks to meet the strict 72-hour reporting timeline. Firms will also need to reconfigure data storage systems to ensure compliance with the mandatory two-year retention requirement.

The takeaway

The move toward mandatory, time-sensitive incident reporting reflects the government's effort to gain better visibility into the national threat landscape. Businesses should prioritize auditing their current data retention policies to prepare for these upcoming federal obligations.

Further reading

Learn more about evolving Cybersecurity standards and federal compliance requirements on our site.

Live Poll

Should the government mandate standardized cyber incident reporting for all critical infrastructure sectors?