Skip to content
RiskTemplates · The Daily Brief Friday, September 11, 2026
Wire SEC's $3.02M Doximity Insider Trading Judgment: The MNPI Control Test SEP 10

Feature Incident Response

CIRCIA Status in August 2026: No Final Rule and No Current 72-Hour Duty

CIRCIA remains in rulemaking. Separate its proposed 72- and 24-hour reports from the banking agencies' existing 36-hour notification rule.

By Rebecca Leung · August 1, 2026 ·
Table of Contents

TL;DR

  • No CIRCIA final rule existed as of August 17, 2026. CISA says mandatory reporting begins only after the final rule goes into effect.
  • The statute’s future architecture includes a 72-hour covered-cyber-incident report and a 24-hour ransom-payment report. The detailed 2024 implementation text remains proposed.
  • The federal banking agencies’ 36-hour notification rule is already operative and should remain active in incident playbooks.
  • Prepare a conditional CIRCIA module now, but do not label it a current duty or promise a September effective date.

August 17, 2026 Status Update

CISA’s current CIRCIA status page says that covered entities will not be required to report covered cyber incidents or ransom payments until the final rule goes into effect.

The governing status is therefore:

ArtifactStatusOperational effect as of August 17, 2026
CIRCIA statuteEnactedDirects CISA to establish reporting by rule and sets the future clock architecture
April 2024 CIRCIA NPRMProposedSupplies proposed coverage, definitions, content, and procedures; not a current filing rule
2026 town-hall noticeRulemaking inputShows that CISA continued refining the proposal
CIRCIA final ruleNot issuedNo current mandatory CIRCIA report

Delete any playbook sentence that says CIRCIA reporting is now required or assigns the rule a September 2026 effective date. A planning target or forecast is not final agency action.

What the NPRM Proposes

The 2024 NPRM proposes that a covered entity would report:

  • a covered cyber incident within 72 hours after it reasonably believes the incident occurred;
  • a ransom payment within 24 hours after the payment; and
  • supplemental information in circumstances defined by the final rule.

The proposal also addresses covered entities, covered incidents, report content, submission, preservation, enforcement mechanics, and harmonization. Those details may change. Build provisional controls from the NPRM, then conduct a legal and operational redline when final text appears.

Coverage Is Provisional

Financial services is a critical-infrastructure sector, but not every firm in or supporting the sector can be declared covered from that fact alone. The NPRM proposes a combination of criteria and exceptions.

A provisional coverage memo should identify:

  • the exact legal entity;
  • sector and services;
  • the proposed criterion that may apply;
  • any proposed exception;
  • supporting facts and data owner;
  • source and review date; and
  • a mandatory final-rule revalidation step.

Do not hard-code a proposed size threshold into policy as though it were final.

Keep the Existing 36-Hour Rule Live

The banking agencies’ computer-security incident notification rule is current law for covered banking organizations. The OCC’s Bulletin 2021-55 explains that an OCC-supervised bank must notify the OCC as soon as possible and no later than 36 hours after determining that a computer-security incident is a notification incident. Parallel requirements apply for Federal Reserve- and FDIC-supervised banking organizations.

The future CIRCIA and existing bank rules differ:

IssueExisting bank ruleProposed CIRCIA framework
StatusOperativeProposed pending an effective final rule
RecipientPrimary federal banking regulatorCISA
Core triggerDetermination of a notification incidentProposed reasonable belief of a covered cyber incident
ClockNo later than 36 hours after determinationProposed 72 hours after reasonable belief
CoverageBanking organizations within agency rulesProposed covered entities across critical-infrastructure sectors

An incident can eventually require both analyses. One cannot be substituted for the other unless final law and any harmonization arrangement say so.

Build a Conditional CIRCIA Module

Capture incident facts once, then route them through separate decision records for the banking rule, SEC disclosure, state breach laws, contractual notices, and future CIRCIA reporting.

2. Preserve decision timestamps

Record what was known, when it was known, who evaluated the trigger, and why the team reached its conclusion. Different clocks may begin at different points.

3. Map proposed fields to owners

Identify likely sources across security, infrastructure, legal, vendor management, communications, and finance. Do not discover during an event that no one owns ransom-payment or third-party-impact facts.

4. Test uncertainty

Use a scenario involving a critical provider, incomplete facts, changing recovery estimates, and possible ransom payment. Require the team to make the live 36-hour determination and a separately labeled future CIRCIA assessment.

5. Add a final-rule trigger

Assign an owner to monitor the CISA FAQs and Federal Register. Final publication should trigger coverage review, legal redline, procedure changes, training, and a new exercise.

Every provisional page should display: NOT A CURRENT CIRCIA FILING DUTY—REVALIDATE AGAINST THE EFFECTIVE FINAL RULE.

So What?

CIRCIA readiness is legitimate regulatory-change work. Treating an NPRM as an operative reporting rule is not.

Keep current notification obligations functioning. Build a conditional CIRCIA process using the proposal. Revalidate scope, triggers, fields, harmonization, and dates when CISA issues final text.

The Incident Response & Breach Notification Kit can organize trigger matrices, escalation, and evidence. Any CIRCIA module must remain conditional until the final rule is effective.


Primary sources: CISA CIRCIA status page | CISA CIRCIA FAQs | 2024 CIRCIA NPRM | 2026 town-hall notice | OCC Bulletin 2021-55

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Has CISA issued a CIRCIA final rule?
No. As of August 17, 2026, CISA had not issued a final rule. CISA states that covered cyber-incident and ransom-payment reports will not be required until the final rule goes into effect.
Are CIRCIA's 72-hour and 24-hour reports mandatory today?
Not yet. CIRCIA establishes the future 72-hour covered-incident and 24-hour ransom-payment framework, but coverage, definitions, content, procedures, and the operative reporting duty depend on an effective final rule. The 2024 document is an NPRM, not current filing instructions.
Does CIRCIA already cover every bank and fintech?
No final coverage determination can be made from the proposal alone. Financial services is a critical-infrastructure sector, but the 2024 NPRM contains proposed size, sector, category, and exception criteria. Revalidate every provisional assessment against final text.
Is the banking agencies' 36-hour rule already in force?
Yes. A banking organization must notify its primary federal regulator as soon as possible and no later than 36 hours after determining that a computer-security incident rises to the level of a notification incident. That existing rule has a different trigger and recipient from proposed CIRCIA reporting.
What preparation is appropriate before a final rule?
Maintain a provisional applicability assessment, map proposed report fields to evidence owners, add a regulatory-change trigger, and tabletop concurrent 36-hour and future CIRCIA analyses. Mark every CIRCIA step as proposed and not currently mandatory.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Incident Response & Breach Notification Kit

Step-by-step incident response playbooks and breach notification templates for all 50 states.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.