HomeComplianceThe CIRCIA Final Rule Deadline Has Passed. A DHS Funding Lapse Helped...

The CIRCIA Final Rule Deadline Has Passed. A DHS Funding Lapse Helped Push CISA’s Next Target to September 2026.

CIRCIA set an 18-month statutory clock, running from the proposed rule's April 2024 publication, for CISA to finalize its cyber-incident-reporting rule. That clock expired October 4, 2025, and CISA's current target is now September 2026.

What Is the CIRCIA Final Rule Deadline, and Why Has CISA Already Missed It?

MSSPs and GRC vendors can productize CIRCIA readiness now, before the final rule forces the market to. DIB and Information Technology contractors that wait risk an incident-reporting scramble once that rule lands. The slipping deadline is a business opening and a retention risk, not just a compliance footnote.

The CIRCIA final rule deadline was October 4, 2025. CISA, the Cybersecurity and Infrastructure Security Agency, let that date pass with no final rule. Critical-infrastructure cybersecurity is the agency’s mandate inside DHS. CIRCIA is the Cyber Incident Reporting for Critical Infrastructure Act of 2022. Congress enacted it in March 2022 and set the clock: a proposed rule by March 15, 2024, then a final rule within 18 months (6 U.S.C. 681b(b)). CISA published its Notice of Proposed Rulemaking (NPRM) on April 4, 2024, on schedule (Federal Register 2024-06526). That start date put the statutory deadline 18 months later, on October 4, 2025.

CISA’s own projections have moved twice since. The Spring 2025 Unified Agenda pushed the internal target to May 2026, before the statutory deadline arrived. That target slipped too. CISA’s latest stated target, per the most recent Unified Agenda, is September 2026.

  • The statute: CIRCIA, enacted March 2022, requiring CISA to build a mandatory reporting regime for critical-infrastructure cyber incidents.
  • The proposed rule: NPRM published April 4, 2024, with a public comment period extended to July 3, 2024 (Federal Register 2024-09505).
  • The clock: an 18-month statutory deadline that landed on October 4, 2025 and expired without a final rule.

Why the Rule Slipped Twice, and Why the Second Slip Wasn’t About Comment Volume

Missing a statutory rulemaking deadline is not unusual. The usual cause is comment volume: a large docket takes longer to work through. That is not what happened here. CISA’s own notice puts total NPRM comments at about 300 (Federal Register 2026-02948), a modest docket by federal standards.

CISA had scheduled stakeholder town halls for March 9 through April 2, 2026. Those did not happen. The rescheduling notice states plainly: “Due to the lapse in the Department of Homeland Security’s (DHS) appropriations from February 14, 2026, to April 30, 2026, CISA did not hold the previously announced town hall meetings” (Federal Register 2026-10417).

The rescheduled sessions ran June 15 through 18, 2026, split into two general sessions plus two sector groupings. One group covered Communications, Dams, Emergency Services, Food and Agriculture, Government Facilities, Healthcare and Public Health, Transportation Systems, and Water and Wastewater. The other covered Chemical, Commercial Facilities, Critical Manufacturing, Defense Industrial Base, Energy, Financial Services, Information Technology, and Nuclear Reactors, Materials, and Waste. Per Hunton Andrews Kurth’s reporting, more than 1,200 stakeholders attended. The original schedule gave DIB and Information Technology a town hall of their own on March 19, 2026. Those are the two sectors most relevant to this audience. The lapse canceled that session. Both sectors ended up inside the eight-sector June 18 group.

CISA’s own preliminary regulatory-impact analysis estimates CIRCIA will affect 316,244 covered entities. It puts the total cost at $2.6 billion (undiscounted) over an 11-year analysis period, an annualized $244.6 million. This is a rulemaking cost estimate, not appropriated or obligated federal spending. (Federal Register 2024-06526, accessed 2026-08-12)
“Due to the lapse in the Department of Homeland Security’s (DHS) appropriations from February 14, 2026, to April 30, 2026, CISA did not hold the previously announced town hall meetings.” (Federal Register 2026-10417, CISA’s own rescheduling notice)

DHS operated under its own appropriations lapse for roughly eleven weeks. During that stretch, CISA could not hold the stakeholder sessions it needed before finalizing the rule. That is not a knock on CISA’s diligence. It is a documented, government-side reason for the slip, not the comment-volume story that usually explains a slow rulemaking. The rule now runs nearly a year behind its statutory deadline.

Three separate points in this rulemaking’s history show the pattern isn’t a single missed date:

  • The October 4, 2025 statutory deadline passed with no final rule issued, for reasons CISA’s public notices do not state.
  • CISA then set and abandoned an internal target of May 2026, per the Spring 2025 Unified Agenda.
  • CISA postponed the town halls it needed before finalizing the rule because of the DHS appropriations lapse, not because of the roughly 300 comments in the docket.

What CIRCIA Will Actually Require Once It Takes Effect

CIRCIA’s core mechanism is mandatory, fast reporting once the final rule takes effect. It replaces today’s voluntary disclosure norm for entities in the sectors the statute covers. A “covered entity” has to clear two tests (6 U.S.C. 681(4)). It must operate in a critical infrastructure sector, as Presidential Policy Directive 21 (PPD-21) defines it, and it must meet criteria the final rule sets. Sector membership alone does not make a company a covered entity.

  1. A covered entity experiences a “covered cyber incident,” per the final rule’s proposed criteria: substantial loss of confidentiality, integrity, or availability of a system, or serious impact to safety and resiliency of operations.
  2. The statute, not the rule CISA is finalizing, requires the entity to report the incident within 72 hours of reasonably believing it occurred (6 U.S.C. 681b(a)(1)).
  3. The entity must separately report any ransom payment connected to a ransomware attack within 24 hours (6 U.S.C. 681b(a)(2)).
  4. CISA analyzes reports across sectors to identify attack trends and shares findings back to network defenders.

PPD-21 designates 16 critical-infrastructure sectors: Chemical, Commercial Facilities, Communications, Critical Manufacturing, Dams, Defense Industrial Base, Emergency Services, Energy, Financial Services, Food and Agriculture, Government Facilities, Healthcare and Public Health, Information Technology, Nuclear Reactors Materials and Waste, Transportation Systems, and Water and Wastewater Systems. The definitions above, and the size criteria that narrow them, apply in all 16. The NPRM, proposed as 6 CFR Part 226, sets sector- and size-based criteria for who counts as a covered entity. CISA has asked stakeholders for improvements that would “clarify or reduce burden” in the final rule (Federal Register 2026-02948). It has not said which criteria would change. One thing can’t change: the statute sets the reporting clocks, not CISA’s rulemaking discretion.

Who Should Actually Be Watching This: DIB Contractors, MSSPs, and GRC Vendors

DIB and Information Technology are two of PPD-21’s 16 covered sectors. So a meaningful share of the contractors this outlet covers could become covered entities directly, not just downstream of a customer’s obligation. No one can say yet whether a given company clears the final rule’s size and sector thresholds.

That uncertainty cuts a second way. MSSPs and GRC vendors should watch it closely. CISA’s notice lists a specific open question: “whether CISA should include in the final rule specific criteria to cover Managed Service Providers (MSPs) or Cloud Service Providers (CSPs) utilizing open-source software” (Federal Register 2026-02948). That is not a hypothetical extension. The rule could reach the firms now positioned to sell CIRCIA-readiness services.

Meeting a 72-hour statutory reporting clock is an operational capability, not a policy position. It takes detection, escalation, and a documented workflow, all in place before an incident happens. None of that work waits on the final rule. The statute’s clocks are fixed now, detailed enough to build against.

  • DIB primes and DIB subs whose operations alone could clear the final rule’s sector and size thresholds.
  • Systems integrators operating infrastructure inside the Information Technology sector’s covered-entity criteria.
  • MSSPs and GRC vendors, who sell CIRCIA-readiness capability today and could become covered entities if CISA finalizes MSP/CSP-specific criteria.
Milestone Date Status
CIRCIA enacted March 2022 Statute in force; legislative authorization for the rule
NPRM published April 4, 2024 Comment period opened; approximately 300 comments received
Comment period closed July 3, 2024 Extended 30 days from original close date
Statutory final-rule deadline October 4, 2025 Passed, no final rule issued
Internal target (Spring 2025 Unified Agenda) May 2026 Missed
Town halls originally scheduled March 9 to April 2, 2026 Canceled by the DHS appropriations lapse
Town halls held June 15 to 18, 2026 Completed; DIB and IT folded into the 8-sector June 18 group, not a dedicated session
Current stated target September 2026 Not yet confirmed as final

Why Contractors Shouldn’t Wait for the Final Rule to Build Readiness

A company watching only for the CIRCIA final rule deadline is missing the more useful signal. This docket’s own target dates have moved twice. September 2026 is the current projection, not a locked date. Wait for the final rule before building any reporting capability and you start from zero once it publishes, against a compressed timeline.

  • Confirm whether your company, or a key client, operates in one of PPD-21’s 16 sectors, especially DIB and Information Technology.
  • Read the NPRM’s proposed covered-entity criteria (regulations.gov docket CISA-2022-0010) and flag where your organization would fall once the rule locks those thresholds.
  • Stress-test your incident-response plan against the statute’s fixed 72-hour and 24-hour clocks, since most plans assume slower, voluntary-disclosure timelines.
  • If you’re an MSSP or GRC vendor, track whether the final rule adds MSP/CSP-specific covered-entity criteria. You may end up inside the rule you’re helping clients comply with.
Pull the NPRM’s proposed covered-entity criteria (6 CFR Part 226) from regulations.gov docket CISA-2022-0010. Check it against your NAICS code, sector, and revenue or employee count today, not after the final rule publishes. If you’re a DIB prime or sub, that comparison shows your retention-risk exposure. If you’re an MSSP or GRC vendor advising one, it shows the readiness sale this rule’s delay has bought you time to build.

What This Rule’s History Says About Tracking Federal Cyber Deadlines

A federal compliance deadline is a projection until the final document publishes, not a fixed date to plan against. CIRCIA proves it. Congress put the rule on a compressed statutory clock. It now runs nearly a year behind. This outlet’s earlier coverage of CISA Binding Operational Directive 26-04 found a related failure mode: that directive doesn’t bind contractors at all. Yet FedRAMP cited it to pull a cloud-provider deadline forward. The calendar a program starts with and the one it finishes on are rarely the same. That gap is where planning mistakes happen.

Reading “no final rule yet” as “no reason to act” is the mistake this rule’s history argues against. The next test is whether September 2026 holds, given two prior targets did not. The realistic move for a contractor: build reporting capability against the NPRM’s proposed shape now, then adjust once the final rule locks the details. Waiting on a date this docket has already broken twice is not a plan.

FAQ

What is CIRCIA and who does it apply to?

CIRCIA is the Cyber Incident Reporting for Critical Infrastructure Act of 2022. It requires CISA to build a mandatory reporting regime for cyber incidents and ransom payments. It reaches the 16 critical-infrastructure sectors PPD-21 designates, including Defense Industrial Base and Information Technology. Within those sectors, only entities meeting the final rule’s criteria count as covered.

When is the CIRCIA final rule expected?

CISA’s current stated target, per the most recent Unified Agenda, is September 2026. That target follows two that did not hold: the October 4, 2025 statutory deadline and a May 2026 internal target. Treat it as a projection, not a confirmed date, until the final rule publishes.

Why did CISA miss the CIRCIA statutory deadline?

CISA’s public notices don’t state a reason for the initial October 2025 miss. The later delay, from the May 2026 internal target to the current September 2026 target, ties to the documented DHS appropriations lapse described above. That lapse forced CISA to postpone and reschedule the stakeholder town halls it needed first.

What are the CIRCIA reporting timeframes for cyber incidents and ransom payments?

The statute sets these clocks, not the rule CISA is still finalizing. A covered cyber incident starts a 72-hour clock. A ransom payment starts a separate 24-hour clock.

Is my company a “covered entity” under CIRCIA?

That depends on sector and size criteria the NPRM proposed but the final rule hasn’t locked. DIB and Information Technology are the two most relevant sectors for this audience. To confirm exact thresholds, read the NPRM and watch for the changes CISA has signaled but not yet detailed.

Does CIRCIA apply to federal contractors specifically, or only critical-infrastructure operators broadly?

CIRCIA’s coverage runs by sector and size, not contractor status. A company becomes a covered entity by operating in a designated sector like Defense Industrial Base, not by holding a federal contract. CISA is weighing whether to add MSPs and CSPs using open-source software as their own category. That would reach vendors, not just contractors.

The Contract Opportunity Atlas

Two issues a week.. Free.

Two issues a week. Data-driven intelligence for small tech firms selling to the federal government. Free.

Subscribe to Contract Opportunity Atlas

Get federal technology, AI, procurement, and GovCon insights delivered to your inbox.

Shahid Shah
Shahid Shah
Shahid specializes in bringing world-class CTO, CISO, and EiR expertise to startups, business units and companies on a part-time (fractional) basis. With a rich background in regulated, safety-critical industries like Med Devices, Digital Health, and Gov 2.0, he possess a unique understanding of complex, high-demand products and services. He is a C-suite native that can easily blend in with technical and engineering teams that need to deliver revenue-generating solutions to the marketplace. He has served as an Entrepreneur in Residence when a market seems lucrative but it's unclear how to build and launch products and services for such opportunities. Shahid has years of leadership experience as a co-founding startup CTO for multiple venture-backed companies, business unit CTO and EiR, and public company CTO helping transform product teams from marginal to high performance. His software/hardware engineering and cybersecurity body of knowledge is up to date because he rolls up his sleeves to create code when appropriate & dive into system architecture and design when required. He also conduct technology due diligence exercises for corporate acquisition or product integration requirements.
RELATED ARTICLES

Most Popular

CATEGORIES