What happened
On October 1, 2026, the Office of Information and Regulatory Affairs recorded receipt of CISA’s Cyber Incident Reporting for Critical Infrastructure Act reporting requirements for final regulatory review.
The OMB review page identifies RIN 1670-AA04, the agency as DHS/CISA and the stage as Final Rule; submission for review is not publication or an operative compliance deadline.
The older CIRCIA proposal used a 72-hour clock for covered cyber incidents and a 24-hour clock for ransom payments, but those provisions remain planning assumptions until the final text is published.
The final text, effective date, covered-entity test, harmonisation mechanisms, supplemental-report requirements and final record-retention duties were not published on the OMB review page. The practical change is therefore procedural but material: a rule that has repeatedly remained in development is now in final executive review, narrowing the preparation window without resolving the provisions that determine who must report and exactly when.
Why this matters now
Submission for final review is the clearest sign yet that CIRCIA is moving from a long-running proposal into an implementation decision. Covered organisations may receive limited time between publication and effective compliance, while incident-response, legal, privacy, communications and operational teams still need a shared trigger for starting regulatory clocks.
The most damaging preparation error would be treating the proposal as final law or waiting for publication before assigning ownership. The prudent position is to test current workflows against the proposed 72-hour incident and 24-hour ransom-payment clocks while marking scope, definitions, supplemental-report duties and retention requirements as unresolved until the final text appears.
CIRCIA readiness is not only a legal exercise. Security operations must preserve the facts needed for an early report, executives must decide who can authorise submission with incomplete evidence, and third-party contracts must support rapid notification when an incident at a provider affects a potentially covered entity.
The decision for security leaders
Prepare for the final rule without asserting that proposed provisions are settled. General counsel should maintain the authoritative interpretation, while the CISO ensures incident workflows can produce an initial fact pattern, materiality view, affected-system scope and decision log under compressed time pressure.
Run one cross-functional exercise using an incident with incomplete attribution and uncertain impact. The test should identify who starts the clock, who approves the report, which facts can be labelled preliminary and how supplemental information reaches regulators without contradicting earlier submissions.
Require third-party risk owners to identify providers whose incidents could trigger reporting for the enterprise. Contractual notice periods, forensic access, subcontractor visibility and evidence-retention terms should be compared with the proposed clocks before the final compliance date is known.
Evidence of closure
- Approved responsibility matrix names applicability, clock, submission and board-notification owners.
- Exercise record proves an initial report can be assembled under the proposed time constraints.
- Obligation map reconciles CIRCIA planning with existing federal, state and sector reports.
- Contract review records provider-notification gaps and approved remediation dates.
The Security.io assessment
The new information is not that CIRCIA exists or that rapid reporting has been proposed; both are older. The material change is that CISA’s final rule has reached OMB review, moving preparation from an open-ended policy project to a near-term governance task.
Organisations should resist two opposite errors: freezing investment until every definition is final, or hard-coding the proposal into policy as though nothing can change. Rehearsable capabilities such as decision ownership, evidence preservation, reporting coordination and third-party notice are durable regardless of the final wording.
Attribution posture: No threat actor attribution applies because the development is a federal rulemaking review, not a cyber incident.
Security.io assesses the submission milestone with high confidence because the government review record is direct evidence. Any statement about final scope, effective dates or binding retention requirements remains unresolved until the actual rule is published.
Questions for the morning meeting
- Who owns the organisation’s CIRCIA applicability decision and reporting clock?
- Can legal, security and operations assemble a defensible initial incident report before forensic certainty exists?
- Which existing federal or sector reports could overlap with CIRCIA obligations?