Feature Incident Response
CIRCIA Status in August 2026: No Final Rule and No Current 72-Hour Duty
CIRCIA remains in rulemaking. Separate its proposed 72- and 24-hour reports from the banking agencies' existing 36-hour notification rule.
Table of Contents
TL;DR
- No CIRCIA final rule existed as of August 17, 2026. CISA says mandatory reporting begins only after the final rule goes into effect.
- The statute’s future architecture includes a 72-hour covered-cyber-incident report and a 24-hour ransom-payment report. The detailed 2024 implementation text remains proposed.
- The federal banking agencies’ 36-hour notification rule is already operative and should remain active in incident playbooks.
- Prepare a conditional CIRCIA module now, but do not label it a current duty or promise a September effective date.
August 17, 2026 Status Update
CISA’s current CIRCIA status page says that covered entities will not be required to report covered cyber incidents or ransom payments until the final rule goes into effect.
The governing status is therefore:
| Artifact | Status | Operational effect as of August 17, 2026 |
|---|---|---|
| CIRCIA statute | Enacted | Directs CISA to establish reporting by rule and sets the future clock architecture |
| April 2024 CIRCIA NPRM | Proposed | Supplies proposed coverage, definitions, content, and procedures; not a current filing rule |
| 2026 town-hall notice | Rulemaking input | Shows that CISA continued refining the proposal |
| CIRCIA final rule | Not issued | No current mandatory CIRCIA report |
Delete any playbook sentence that says CIRCIA reporting is now required or assigns the rule a September 2026 effective date. A planning target or forecast is not final agency action.
What the NPRM Proposes
The 2024 NPRM proposes that a covered entity would report:
- a covered cyber incident within 72 hours after it reasonably believes the incident occurred;
- a ransom payment within 24 hours after the payment; and
- supplemental information in circumstances defined by the final rule.
The proposal also addresses covered entities, covered incidents, report content, submission, preservation, enforcement mechanics, and harmonization. Those details may change. Build provisional controls from the NPRM, then conduct a legal and operational redline when final text appears.
Coverage Is Provisional
Financial services is a critical-infrastructure sector, but not every firm in or supporting the sector can be declared covered from that fact alone. The NPRM proposes a combination of criteria and exceptions.
A provisional coverage memo should identify:
- the exact legal entity;
- sector and services;
- the proposed criterion that may apply;
- any proposed exception;
- supporting facts and data owner;
- source and review date; and
- a mandatory final-rule revalidation step.
Do not hard-code a proposed size threshold into policy as though it were final.
Keep the Existing 36-Hour Rule Live
The banking agencies’ computer-security incident notification rule is current law for covered banking organizations. The OCC’s Bulletin 2021-55 explains that an OCC-supervised bank must notify the OCC as soon as possible and no later than 36 hours after determining that a computer-security incident is a notification incident. Parallel requirements apply for Federal Reserve- and FDIC-supervised banking organizations.
The future CIRCIA and existing bank rules differ:
| Issue | Existing bank rule | Proposed CIRCIA framework |
|---|---|---|
| Status | Operative | Proposed pending an effective final rule |
| Recipient | Primary federal banking regulator | CISA |
| Core trigger | Determination of a notification incident | Proposed reasonable belief of a covered cyber incident |
| Clock | No later than 36 hours after determination | Proposed 72 hours after reasonable belief |
| Coverage | Banking organizations within agency rules | Proposed covered entities across critical-infrastructure sectors |
An incident can eventually require both analyses. One cannot be substituted for the other unless final law and any harmonization arrangement say so.
Build a Conditional CIRCIA Module
1. Use one intake and separate legal analyses
Capture incident facts once, then route them through separate decision records for the banking rule, SEC disclosure, state breach laws, contractual notices, and future CIRCIA reporting.
2. Preserve decision timestamps
Record what was known, when it was known, who evaluated the trigger, and why the team reached its conclusion. Different clocks may begin at different points.
3. Map proposed fields to owners
Identify likely sources across security, infrastructure, legal, vendor management, communications, and finance. Do not discover during an event that no one owns ransom-payment or third-party-impact facts.
4. Test uncertainty
Use a scenario involving a critical provider, incomplete facts, changing recovery estimates, and possible ransom payment. Require the team to make the live 36-hour determination and a separately labeled future CIRCIA assessment.
5. Add a final-rule trigger
Assign an owner to monitor the CISA FAQs and Federal Register. Final publication should trigger coverage review, legal redline, procedure changes, training, and a new exercise.
Every provisional page should display: NOT A CURRENT CIRCIA FILING DUTY—REVALIDATE AGAINST THE EFFECTIVE FINAL RULE.
So What?
CIRCIA readiness is legitimate regulatory-change work. Treating an NPRM as an operative reporting rule is not.
Keep current notification obligations functioning. Build a conditional CIRCIA process using the proposal. Revalidate scope, triggers, fields, harmonization, and dates when CISA issues final text.
The Incident Response & Breach Notification Kit can organize trigger matrices, escalation, and evidence. Any CIRCIA module must remain conditional until the final rule is effective.
Primary sources: CISA CIRCIA status page | CISA CIRCIA FAQs | 2024 CIRCIA NPRM | 2026 town-hall notice | OCC Bulletin 2021-55
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Incident Response & Breach Notification Kit
Step-by-step incident response playbooks and breach notification templates for all 50 states.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Has CISA issued a CIRCIA final rule?
Are CIRCIA's 72-hour and 24-hour reports mandatory today?
Does CIRCIA already cover every bank and fintech?
Is the banking agencies' 36-hour rule already in force?
What preparation is appropriate before a final rule?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Incident Response & Breach Notification Kit
Step-by-step incident response playbooks and breach notification templates for all 50 states.
◆ Keep reading
Related posts.
Incident Response
CISA's CIRCIA Is Finalizing This Month. Here's What the New 72-Hour Reporting Clock Means for Your Financial Services Incident Response Program.
CISA's CIRCIA final rule — requiring 72-hour cyber incident reporting to CISA and 24-hour ransomware payment disclosure — is expected to publish in September 2026. For financial services firms, it creates a fifth notification obligation running parallel to OCC/FDIC, SEC, NYDFS, and state breach notification clocks. Here's what your IR program needs to add before the effective date.
Sep 8, 2026
Incident Response
The 36-Hour Notification Clock Doesn't Wait for Your Investigation. Here's What the OCC's June 2026 Cybersecurity Report Means for Your Incident Response Program.
The OCC's June 2026 Cybersecurity Report and NYDFS's $144M+ enforcement record make one thing clear: incident response programs designed around investigating before notifying will fail the regulatory test. Here's what your program needs to do differently.
Sep 4, 2026
Incident Response
The FTC's 30-Day Breach Notification Requirement: What Non-Bank Fintechs Keep Getting Wrong
The FTC's Safeguards Rule amendment has required non-bank financial institutions to report data breaches to the FTC within 30 days since May 13, 2024. The clock starts when any employee discovers the breach — not when legal decides it's reportable. Here's what most fintech incident response plans still don't address.
Aug 30, 2026