Overview
The Cybersecurity and Infrastructure Security Agency's (CISA) final rule implementing the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) moved to the Office of Management and Budget (OMB) for review on October 1 after the agency missed its previously announced September 2026 publication target. OMB review is the final major regulatory review step before the final rule is published.
Broad Effects on Critical Infrastructure
The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) established a mandatory cyber incident reporting framework intended to improve the federal government's visibility into threats affecting critical infrastructure and support coordinated response and information sharing. Under the proposed reporting rule, CISA estimated that approximately 316,000 entities across 16 critical-infrastructure sectors would be subject to reporting and related record-preservation requirements. Potentially affected industries include defense, energy, financial services, healthcare, transportation, communications, and information technology.
CISA published its proposed rule in April 2024. The proposal would require covered entities to report covered cyber incidents to CISA within 72 hours after reasonably believing a covered cyber incident has occurred, and to report ransom payments within 24 hours of payment, including payments tied to ransomware attacks that do not independently qualify as covered cyber incidents. Those obligations will not take effect until the final rule is published and becomes effective. The final rule will establish the operative coverage criteria, incident thresholds, reporting procedures, and compliance effective date.
What Companies Should Do Now
Potentially covered entities should take substantive steps now to prepare for the reporting obligations, such as:
- Updating corporate incident response plans and playbooks so that they set out clear decision-making authorities and escalation paths, with separate workflows for incident and ransom-payment reporting.
- Developing a comprehensive list of reporting obligations that identify reporting triggers, reporting timelines, and report requirements for each reporting obligation.
- Reviewing vendor arrangements and preservation procedures to ensure timely access to information needed for reporting and compliance.
- Considering a tabletop exercise that simulates a cyber incident, ideally conducted under the direction of outside counsel to help preserve attorney-client privilege, to pressure test the company's decision-making, escalation, and reporting preparedness.
Companies that take these steps now will be better positioned to meet their reporting obligations once the final rule is published and takes effect. For more information or guidance on preparing for CIRCIA compliance, please contact our firm's Cybersecurity Team.