Regulatory Watch  /  United States (federal)  /  Proposed regulation
Low impactProposed regulationAnnounced

CISA submits Final CIRCIA Rule to OIRA for interagency review

On October 1, 2026, CISA submitted a draft of the Final Rule implementing the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) to OIRA. CIRCIA will require covered critical‑infrastructure entities to report cybersecurity incidents within 72 hours and ransomware payments within 24 hours. The rule’s effective date has not been set, but it is expected to be at least 60 days after Federal Register publication.

Why it matters: The rule will impose rapid cyber‑incident reporting obligations on critical‑infrastructure operators, shaping their security and compliance programs.

Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.

Sources
CISA Submits Final CIRCIA Rule for OMB Review
Covington Inside Privacy · primary source · Oct 9, 2026
Details
JurisdictionUnited States (federal)
RegulatorCybersecurity and Infrastructure Security Agency (CISA)
LawCyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA)
StatusAnnounced
PublishedOctober 9, 2026
Effectivenot stated
Topicsbreach notification, security