Feature Incident Response
CISA's CIRCIA Is Finalizing This Month. Here's What the New 72-Hour Reporting Clock Means for Your Financial Services Incident Response Program.
CISA's CIRCIA final rule — requiring 72-hour cyber incident reporting to CISA and 24-hour ransomware payment disclosure — is expected to publish in September 2026. For financial services firms, it creates a fifth notification obligation running parallel to OCC/FDIC, SEC, NYDFS, and state breach notification clocks. Here's what your IR program needs to add before the effective date.
Table of Contents
TL;DR
- CISA’s CIRCIA final rule is expected to publish in September 2026, creating a mandatory 72-hour cyber incident reporting obligation to CISA for covered critical infrastructure entities — including financial services firms exceeding SBA size thresholds.
- CIRCIA also requires a 24-hour report to CISA for any ransomware payment, separate from the incident report, and is the first U.S. federal law mandating disclosure of ransom payments.
- For financial services firms, CIRCIA adds a fifth notification track running alongside OCC/FDIC 36-hour, SEC 4-day, NYDFS 72-hour, and state breach notification clocks — each going to a different agency with different triggers and different content.
- The effective date will be set in the final rule, but preparation shouldn’t wait: your IR runbook, incident classification criteria, and notification workflows need CISA added as a distinct track before the first incident after the rule takes effect.
Your incident response runbook already has at least three notification tracks. If you’re an OCC-supervised entity or bank partner, there’s a 36-hour clock ticking to your primary federal regulator. If you’re a public company, there’s a four-day clock to the SEC via Form 8-K. If you’re NYDFS-licensed, there’s a 72-hour clock to NYDFS. And underneath all of it, there are 50 different state breach notification laws with timelines ranging from 30 to 90 days.
CIRCIA adds a sixth — a mandatory report to CISA, the Cybersecurity and Infrastructure Security Agency, within 72 hours of a “substantial” cyber incident. And a separate 24-hour report if you pay ransom.
These aren’t hypothetical future obligations. The Cyber Incident Reporting for Critical Infrastructure Act of 2022 has been moving toward a final rule since Congress passed it. After a statutory October 2025 deadline came and went, CISA targeted May 2026, then September 2026. The final rule is either newly published or days from publication as this goes out.
If you’re a financial services firm and CIRCIA isn’t in your IR runbook yet, you’re behind.
What CIRCIA Is and Why It Matters Differently for Financial Services
Congress passed CIRCIA in March 2022, requiring CISA to develop rules mandating that organizations in “critical infrastructure” sectors report significant cyber incidents to CISA. The theory: the federal government sees only a fraction of the cyber incidents hitting critical infrastructure because voluntary reporting is inconsistent. Mandatory reporting gives CISA visibility to identify patterns, coordinate response, and push threat intelligence back to industry.
CISA’s proposed rule — which gave the framework for the final rule — estimated 316,244 entities would be covered, spanning all 16 designated critical infrastructure sectors. Financial Services is Sector 7.
That’s a large tent. And unlike some sector-specific cyber rules (OCC, NYDFS, FDIC) that apply only to supervised entities, CIRCIA’s scope is defined by sector membership and size — not by holding a particular license or charter.
The practical implication: some financial services firms that aren’t bank-supervised, aren’t NYDFS-licensed, and don’t file with the SEC may still be covered under CIRCIA. Fintechs operating payment processing infrastructure. Crypto exchanges with significant transaction volumes. Credit unions that fall under NCUA. Insurance companies that aren’t bank-supervised. If you’re in financial services and above the SBA size threshold, CIRCIA applies to you.
Are You a “Covered Entity”?
The CIRCIA covered entity analysis is a two-part test.
First: Does your organization operate in one of CISA’s 16 designated critical infrastructure sectors? For financial services, this includes banking, securities, insurance, and payments infrastructure. If you process payments, extend credit, hold deposits, trade securities, or provide financial data that other financial institutions depend on, you’re likely in the Financial Services Sector.
Second: Do you exceed the SBA small business size standard for your industry? The SBA size standard for financial services entities is generally set by revenue, assets, or employee count depending on the NAICS code. The exception is narrower than most fintechs assume — many Series B and later-stage fintechs will exceed the threshold regardless of whether they think of themselves as “large” companies.
Don’t assume you’re exempt without running the analysis. CISA has been clear that the small-business exception is a floor, not a default.
What Triggers the 72-Hour Clock
CIRCIA requires reporting of “covered cyber incidents,” which CISA defines as “substantial” cyber incidents. The CISA Covered Cyber Incident Fact Sheet describes a substantial incident as one that:
- Causes substantial loss of confidentiality, integrity, or availability — data exfiltration of personal information, financial data, or intellectual property affecting a material volume of records
- Creates serious impacts to safety or operational resilience
- Disrupts business or industrial operations for more than a de minimis period or number of users
- Involves unauthorized access through a cloud provider, managed service provider, third-party data host, or supply-chain compromise
That last category is significant for financial services. If your core banking platform goes down because a cloud provider is breached, or your payment processor is compromised through a supply chain attack, CIRCIA’s threshold may be met even if your own systems weren’t directly penetrated.
The critical timing detail: the 72-hour clock starts from “reasonable belief” that a substantial incident occurred — not from confirmation, not from a materiality determination, not from the moment you notify your primary regulator. For contrast, the SEC’s Item 1.05 Form 8-K clock starts when the company “determines” the incident is material — a later, more deliberate trigger. CIRCIA’s clock is earlier.
This matters for your IR procedures. If your current runbook says “notify regulators after we’ve confirmed the scope,” you may already be late on the CIRCIA clock when you get to that step.
The Notification Pile-Up: Running Multiple Clocks at Once
When a significant cyber incident hits a financial services firm, the current notification landscape looks like this:
| Requirement | Who Reports | Notify Whom | Clock Starts | Approximate Trigger |
|---|---|---|---|---|
| OCC/FDIC 36-hour | Bank-supervised entities | Primary federal banking regulator | 36 hours | Notification incident (4+ hour critical disruption) |
| SEC Item 1.05 Form 8-K | SEC-registered public companies | SEC (via EDGAR) | 4 business days | Determined material |
| NYDFS 72-hour | NYDFS licensees | NYDFS Superintendent | 72 hours | Cybersecurity event affecting NYDFS license |
| FTC Safeguards 30-day | Non-bank financial institutions | FTC + customers | 30 days | Breach of customer information |
| CIRCIA (new) | Critical infrastructure covered entities | CISA | 72 hours from reasonable belief | Substantial cyber incident |
| State breach notification | Varies by state | State AG and/or consumers | 30–90 days | PII exposure (varies by state) |
This is not a choose-one situation. A mid-sized federally supervised bank that is also NYDFS-licensed and publicly traded could face OCC/FDIC, NYDFS, SEC, CIRCIA, and state breach notification obligations simultaneously — running parallel clocks to five different reporting destinations.
Most IR programs weren’t built with this many tracks. As the earlier OCC/FDIC 36-hour notification post covered, bank-supervised entities already struggle to manage the primary regulator notification within the 36-hour window while simultaneously containing the incident. Adding a CISA notification track — with different content requirements and a different definition of what triggers reporting — compounds the operational challenge.
The practitioner reality: when your IR team is managing a live incident, they won’t stop to figure out whether CIRCIA applies. That analysis needs to happen during tabletop exercises and runbook design — before the incident, not during it.
The Ransomware Payment Rule Nobody Has Fully Internalized
CIRCIA’s ransomware payment reporting requirement gets less attention than the 72-hour incident report, but it may be operationally harder to manage.
The requirement: any covered entity that makes a ransom payment must report that payment to CISA within 24 hours. This is separate from and in addition to any incident report. It applies even if the ransomware attack itself doesn’t rise to “substantial” under CIRCIA’s incident definition.
CIRCIA is the first U.S. federal law mandating disclosure of ransomware payments. Before CIRCIA, reporting was voluntary (except under certain OFAC sanctions screening obligations). Paying ransom and telling no one was legal — and common. CIRCIA changes that.
The 24-hour clock on a ransomware payment is aggressive. If your organization makes a payment on a Friday evening to restore operations before Monday’s business hours, the CISA report is due Saturday evening. That requires designating someone with authority to file the report, knowing where and how to file, and having a decision-making chain that doesn’t require waiting for the CEO to return from a flight.
What Your IR Program Needs Before the Effective Date
CISA’s final rule will set an effective date. That date — plus any compliance runway built into the rule — is when penalties can begin. But the work of updating your IR program doesn’t wait for enforceability.
The gaps most financial services IR programs need to close before CIRCIA takes effect:
1. Add CISA as a notification recipient. Your runbook probably identifies your primary federal banking regulator, NYDFS (if applicable), and the SEC as notification targets. Add CISA and CISA’s Incident Reporting Form as a distinct track with its own timing trigger and content checklist.
2. Update your incident severity classification to flag CIRCIA-triggering events. Not every incident triggers CIRCIA — you’re looking for “substantial” events. Your severity tiers need criteria that map to CIRCIA’s definition, so your incident commander knows in the first hour whether CIRCIA applies.
3. Build a ransomware payment decision tree. If your organization faces a ransomware demand and makes a payment, the 24-hour CISA report is mandatory. That decision tree needs to include: CISA notification, OFAC sanctions screening (mandatory before any payment), FBI notification (strongly recommended), and your primary regulator.
4. Brief your board and executive team. NYDFS has been explicit that the board owns cybersecurity governance. CIRCIA adds a material external reporting obligation that the board should understand — including the ransomware payment requirement, which has direct board-level implications.
5. Run a tabletop exercise that tests all notification tracks simultaneously. If your last tabletop scenario only tracked one notification clock, run it again with the full current landscape. Find out where your IR team’s bottlenecks are before the first real incident after CIRCIA takes effect.
So What?
CIRCIA’s final rule isn’t coming as a surprise to anyone paying attention. CISA has been publishing the timeline, the proposed rule, and the content requirements for years. What’s catching financial services firms short isn’t the regulation itself — it’s the assumption that their existing IR program already handles it.
It doesn’t. CIRCIA creates a new notification recipient (CISA), a new timing trigger (72 hours from “reasonable belief”), a new payment disclosure requirement (24 hours for ransom payments), and a new definition of what constitutes a reportable event that doesn’t map cleanly onto the definitions your existing program uses.
The firms that will struggle after the effective date are the ones that treat CIRCIA as just “another line in the notification matrix.” It’s a separate track, with different timing, different content, and a different agency relationship than anything already in your IR runbook.
The Incident Response & Breach Notification Kit includes an all-50-states notification matrix and multi-agency notification playbook — the kind of pre-built framework that makes adding CIRCIA as a new track an update, not a rebuild. If your IR program is still a document you haven’t tested, that’s the more fundamental problem to solve before September’s final rule lands.
The FTC Safeguards Rule’s 30-day breach notification requirement is another parallel obligation that non-bank fintechs frequently underestimate until it’s too late. The pattern repeats: new notification requirement, different agency, different clock, inadequate existing program design to handle it.
The CIRCIA final rule is one more reason to have an IR program that was built to run multiple notification tracks simultaneously — because that’s the reality of what financial services cyber incident response now requires.
Sources: CISA CIRCIA FAQs | CISA Covered Cyber Incident Fact Sheet | Hunton: CISA Plans to Finalize CIRCIA in September 2026 | Federal News Network: CIRCIA Expected to Finalize This Fall | ComplianceHub: CIRCIA Readiness Guide
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Incident Response & Breach Notification Kit
Step-by-step incident response playbooks and breach notification templates for all 50 states.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Is CIRCIA reporting in addition to — or instead of — existing bank notification requirements?
What makes an entity a 'covered entity' under CIRCIA?
What exactly is a 'covered cyber incident' that starts the 72-hour clock?
What does the CIRCIA ransomware payment requirement actually require?
How does CIRCIA's 72-hour clock differ from the OCC/FDIC 36-hour notification requirement?
When does CIRCIA's reporting requirement actually become enforceable?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Incident Response & Breach Notification Kit
Step-by-step incident response playbooks and breach notification templates for all 50 states.
◆ Keep reading
Related posts.
Incident Response
The 36-Hour Notification Clock Doesn't Wait for Your Investigation. Here's What the OCC's June 2026 Cybersecurity Report Means for Your Incident Response Program.
The OCC's June 2026 Cybersecurity Report and NYDFS's $144M+ enforcement record make one thing clear: incident response programs designed around investigating before notifying will fail the regulatory test. Here's what your program needs to do differently.
Sep 4, 2026
Incident Response
The FTC's 30-Day Breach Notification Requirement: What Non-Bank Fintechs Keep Getting Wrong
The FTC's Safeguards Rule amendment has required non-bank financial institutions to report data breaches to the FTC within 30 days since May 13, 2024. The clock starts when any employee discovers the breach — not when legal decides it's reportable. Here's what most fintech incident response plans still don't address.
Aug 30, 2026
Incident Response
After the 36-Hour Clock Stops: What OCC Examiners Review Following a Bank Cyber Incident
Filing the 36-hour OCC incident notification is not the end of the process. What follows—examiner review, documentation requests, and examination findings—is where incident response programs either hold up or fall apart. Here's what to prepare for.
Aug 23, 2026