CISA officials said in early July 2026 that they expect to finalize the Cyber Incident Reporting for Critical Infrastructure Act rule by September, according to Nextgov/FCW, which reported that a DHS funding lapse in spring 2026 had delayed additional stakeholder town halls the agency had been holding on the forthcoming rule. Federal News Network similarly reported that CIRCIA is among several major cybersecurity regulations expected to move forward in the fall of 2026.

The underlying law dates back to 2022, when Congress passed CIRCIA directing CISA to write regulations requiring covered critical infrastructure entities to report major cyber incidents and ransomware payments to the federal government. Law firm Hunton's client alert, published in July 2026, notes CISA "continues to finalize regulations to implement" the act, with the final rule expected the following month.

Why it matters

CIRCIA is meant to give the federal government, for the first time, a mandatory and timely picture of ransomware payments and major cyber incidents across critical infrastructure sectors — water utilities, energy, healthcare, financial services and more — rather than relying on voluntary disclosure or piecemeal state breach-notification laws. That data gap has been a long-standing complaint from federal cybersecurity officials, who have said they frequently learn about major intrusions from press reports rather than from victims directly.

A final rule also starts the compliance clock for thousands of critical infrastructure operators who will need new incident-reporting processes, legal review workflows and, in many cases, new internal escalation procedures to meet strict reporting deadlines once the rule takes effect.

How it works

MeriTalk's reporting describes the substance of the regulation plainly: it would require critical infrastructure entities to report both major cyber incidents and ransomware payments to CISA under the 2022 law. The regulatory tracking entry on Reginfo.gov confirms CISA's mandate under CIRCIA to finalize regulations requiring such reporting, listing the rule under RIN 1670-AA04. Specific reporting deadlines and covered-entity thresholds were still being finalized as of the reports reviewed for this story, so this piece does not state exact timeframes or thresholds that have not been confirmed in a final published rule.

Evidence

Three independent trade-press outlets — Nextgov/FCW, MeriTalk and Federal News Network — reported in the same week in July 2026 that CISA was targeting a September 2026 finalization date, each citing agency statements or officials directly. Law firm Hunton's cybersecurity blog corroborates the same timeline for legal and compliance audiences. As of this writing, DailyTech could not confirm whether the rule had actually been published in final form; this story reports on the expected timeline as described by these sources rather than asserting the rule has already taken effect.

What defenders should do

Legal and compliance teams at organizations that may fall within CIRCIA's definition of covered critical infrastructure entities should begin, or continue, preparing incident-reporting workflows now rather than waiting for the final rule's publication, given the multi-year runway that is typical between a final rule's publication and its compliance deadline. Security teams should also review existing incident-response playbooks to ensure they can produce the kind of technical detail — attack vector, indicators of compromise, and, notably, any ransomware payment made — that CIRCIA reporting is expected to require.

What happens next

If CISA meets its stated September 2026 target, publication of the final rule will start a compliance countdown for covered entities, and will likely trigger a fresh round of industry comment and, potentially, litigation challenging specific provisions, as has occurred with other major federal cybersecurity rules such as the SEC's 2023 cybersecurity disclosure rule for public companies. DailyTech will report on the rule's actual publication and its specific reporting deadlines once CISA issues the final text.