On October 1, 2026, CISA submitted a draft of the Final Rule implementing the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) to OIRA. CIRCIA will require covered critical‑infrastructure entities to report cybersecurity incidents within 72 hours and ransomware payments within 24 hours. The rule’s effective date has not been set, but it is expected to be at least 60 days after Federal Register publication.
Why it matters: The rule will impose rapid cyber‑incident reporting obligations on critical‑infrastructure operators, shaping their security and compliance programs.
Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.