Home/Deadlines/CIRCIA Final Rule Expected

CIRCIA Final Rule Expected

CISA📅 May 31, 2026📅94days

Description

CISA is expected to finalize the CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) implementing regulations by May 2026. Once effective, critical infrastructure operators must report significant cyber incidents to CISA within 72 hours and ransomware payments within 24 hours.

Requirements

  • Monitor CIRCIA final rule publication
  • Assess applicability as covered critical infrastructure entity
  • Prepare 72-hour incident reporting procedures
  • Establish 24-hour ransomware payment reporting process
  • Train incident response team on CIRCIA requirements

Applicable To

Critical Infrastructure OperatorsEnergy SectorCommunications SectorFinancial ServicesHealthcare OrganizationsTransportation Sector

Penalty Information

âš Civil enforcement by CISA including administrative subpoenas and potential contempt for non-compliance with reporting obligations.
94
days remaining
May 31, 2026

Framework

CISA

Cybersecurity and Infrastructure Security Agency Requirements