What Is the CIRCIA Final Rule Deadline, and Why Has CISA Already Missed It?
MSSPs and GRC vendors can productize CIRCIA readiness now, before the final rule forces the market to. DIB and Information Technology contractors that wait risk an incident-reporting scramble once that rule lands. The slipping deadline is a business opening and a retention risk, not just a compliance footnote.
The CIRCIA final rule deadline was October 4, 2025. CISA, the Cybersecurity and Infrastructure Security Agency, let that date pass with no final rule. Critical-infrastructure cybersecurity is the agency’s mandate inside DHS. CIRCIA is the Cyber Incident Reporting for Critical Infrastructure Act of 2022. Congress enacted it in March 2022 and set the clock: a proposed rule by March 15, 2024, then a final rule within 18 months (6 U.S.C. 681b(b)). CISA published its Notice of Proposed Rulemaking (NPRM) on April 4, 2024, on schedule (Federal Register 2024-06526). That start date put the statutory deadline 18 months later, on October 4, 2025.
CISA’s own projections have moved twice since. The Spring 2025 Unified Agenda pushed the internal target to May 2026, before the statutory deadline arrived. That target slipped too. CISA’s latest stated target, per the most recent Unified Agenda, is September 2026.
- The statute: CIRCIA, enacted March 2022, requiring CISA to build a mandatory reporting regime for critical-infrastructure cyber incidents.
- The proposed rule: NPRM published April 4, 2024, with a public comment period extended to July 3, 2024 (Federal Register 2024-09505).
- The clock: an 18-month statutory deadline that landed on October 4, 2025 and expired without a final rule.
Why the Rule Slipped Twice, and Why the Second Slip Wasn’t About Comment Volume
Missing a statutory rulemaking deadline is not unusual. The usual cause is comment volume: a large docket takes longer to work through. That is not what happened here. CISA’s own notice puts total NPRM comments at about 300 (Federal Register 2026-02948), a modest docket by federal standards.
CISA had scheduled stakeholder town halls for March 9 through April 2, 2026. Those did not happen. The rescheduling notice states plainly: “Due to the lapse in the Department of Homeland Security’s (DHS) appropriations from February 14, 2026, to April 30, 2026, CISA did not hold the previously announced town hall meetings” (Federal Register 2026-10417).
The rescheduled sessions ran June 15 through 18, 2026, split into two general sessions plus two sector groupings. One group covered Communications, Dams, Emergency Services, Food and Agriculture, Government Facilities, Healthcare and Public Health, Transportation Systems, and Water and Wastewater. The other covered Chemical, Commercial Facilities, Critical Manufacturing, Defense Industrial Base, Energy, Financial Services, Information Technology, and Nuclear Reactors, Materials, and Waste. Per Hunton Andrews Kurth’s reporting, more than 1,200 stakeholders attended. The original schedule gave DIB and Information Technology a town hall of their own on March 19, 2026. Those are the two sectors most relevant to this audience. The lapse canceled that session. Both sectors ended up inside the eight-sector June 18 group.
DHS operated under its own appropriations lapse for roughly eleven weeks. During that stretch, CISA could not hold the stakeholder sessions it needed before finalizing the rule. That is not a knock on CISA’s diligence. It is a documented, government-side reason for the slip, not the comment-volume story that usually explains a slow rulemaking. The rule now runs nearly a year behind its statutory deadline.
Three separate points in this rulemaking’s history show the pattern isn’t a single missed date:
- The October 4, 2025 statutory deadline passed with no final rule issued, for reasons CISA’s public notices do not state.
- CISA then set and abandoned an internal target of May 2026, per the Spring 2025 Unified Agenda.
- CISA postponed the town halls it needed before finalizing the rule because of the DHS appropriations lapse, not because of the roughly 300 comments in the docket.
What CIRCIA Will Actually Require Once It Takes Effect
CIRCIA’s core mechanism is mandatory, fast reporting once the final rule takes effect. It replaces today’s voluntary disclosure norm for entities in the sectors the statute covers. A “covered entity” has to clear two tests (6 U.S.C. 681(4)). It must operate in a critical infrastructure sector, as Presidential Policy Directive 21 (PPD-21) defines it, and it must meet criteria the final rule sets. Sector membership alone does not make a company a covered entity.
- A covered entity experiences a “covered cyber incident,” per the final rule’s proposed criteria: substantial loss of confidentiality, integrity, or availability of a system, or serious impact to safety and resiliency of operations.
- The statute, not the rule CISA is finalizing, requires the entity to report the incident within 72 hours of reasonably believing it occurred (6 U.S.C. 681b(a)(1)).
- The entity must separately report any ransom payment connected to a ransomware attack within 24 hours (6 U.S.C. 681b(a)(2)).
- CISA analyzes reports across sectors to identify attack trends and shares findings back to network defenders.
PPD-21 designates 16 critical-infrastructure sectors: Chemical, Commercial Facilities, Communications, Critical Manufacturing, Dams, Defense Industrial Base, Emergency Services, Energy, Financial Services, Food and Agriculture, Government Facilities, Healthcare and Public Health, Information Technology, Nuclear Reactors Materials and Waste, Transportation Systems, and Water and Wastewater Systems. The definitions above, and the size criteria that narrow them, apply in all 16. The NPRM, proposed as 6 CFR Part 226, sets sector- and size-based criteria for who counts as a covered entity. CISA has asked stakeholders for improvements that would “clarify or reduce burden” in the final rule (Federal Register 2026-02948). It has not said which criteria would change. One thing can’t change: the statute sets the reporting clocks, not CISA’s rulemaking discretion.
Who Should Actually Be Watching This: DIB Contractors, MSSPs, and GRC Vendors
DIB and Information Technology are two of PPD-21’s 16 covered sectors. So a meaningful share of the contractors this outlet covers could become covered entities directly, not just downstream of a customer’s obligation. No one can say yet whether a given company clears the final rule’s size and sector thresholds.
That uncertainty cuts a second way. MSSPs and GRC vendors should watch it closely. CISA’s notice lists a specific open question: “whether CISA should include in the final rule specific criteria to cover Managed Service Providers (MSPs) or Cloud Service Providers (CSPs) utilizing open-source software” (Federal Register 2026-02948). That is not a hypothetical extension. The rule could reach the firms now positioned to sell CIRCIA-readiness services.
Meeting a 72-hour statutory reporting clock is an operational capability, not a policy position. It takes detection, escalation, and a documented workflow, all in place before an incident happens. None of that work waits on the final rule. The statute’s clocks are fixed now, detailed enough to build against.
- DIB primes and DIB subs whose operations alone could clear the final rule’s sector and size thresholds.
- Systems integrators operating infrastructure inside the Information Technology sector’s covered-entity criteria.
- MSSPs and GRC vendors, who sell CIRCIA-readiness capability today and could become covered entities if CISA finalizes MSP/CSP-specific criteria.
| Milestone | Date | Status |
|---|---|---|
| CIRCIA enacted | March 2022 | Statute in force; legislative authorization for the rule |
| NPRM published | April 4, 2024 | Comment period opened; approximately 300 comments received |
| Comment period closed | July 3, 2024 | Extended 30 days from original close date |
| Statutory final-rule deadline | October 4, 2025 | Passed, no final rule issued |
| Internal target (Spring 2025 Unified Agenda) | May 2026 | Missed |
| Town halls originally scheduled | March 9 to April 2, 2026 | Canceled by the DHS appropriations lapse |
| Town halls held | June 15 to 18, 2026 | Completed; DIB and IT folded into the 8-sector June 18 group, not a dedicated session |
| Current stated target | September 2026 | Not yet confirmed as final |
Why Contractors Shouldn’t Wait for the Final Rule to Build Readiness
A company watching only for the CIRCIA final rule deadline is missing the more useful signal. This docket’s own target dates have moved twice. September 2026 is the current projection, not a locked date. Wait for the final rule before building any reporting capability and you start from zero once it publishes, against a compressed timeline.
- Confirm whether your company, or a key client, operates in one of PPD-21’s 16 sectors, especially DIB and Information Technology.
- Read the NPRM’s proposed covered-entity criteria (regulations.gov docket CISA-2022-0010) and flag where your organization would fall once the rule locks those thresholds.
- Stress-test your incident-response plan against the statute’s fixed 72-hour and 24-hour clocks, since most plans assume slower, voluntary-disclosure timelines.
- If you’re an MSSP or GRC vendor, track whether the final rule adds MSP/CSP-specific covered-entity criteria. You may end up inside the rule you’re helping clients comply with.
What This Rule’s History Says About Tracking Federal Cyber Deadlines
A federal compliance deadline is a projection until the final document publishes, not a fixed date to plan against. CIRCIA proves it. Congress put the rule on a compressed statutory clock. It now runs nearly a year behind. This outlet’s earlier coverage of CISA Binding Operational Directive 26-04 found a related failure mode: that directive doesn’t bind contractors at all. Yet FedRAMP cited it to pull a cloud-provider deadline forward. The calendar a program starts with and the one it finishes on are rarely the same. That gap is where planning mistakes happen.
Reading “no final rule yet” as “no reason to act” is the mistake this rule’s history argues against. The next test is whether September 2026 holds, given two prior targets did not. The realistic move for a contractor: build reporting capability against the NPRM’s proposed shape now, then adjust once the final rule locks the details. Waiting on a date this docket has already broken twice is not a plan.
FAQ
What is CIRCIA and who does it apply to?
CIRCIA is the Cyber Incident Reporting for Critical Infrastructure Act of 2022. It requires CISA to build a mandatory reporting regime for cyber incidents and ransom payments. It reaches the 16 critical-infrastructure sectors PPD-21 designates, including Defense Industrial Base and Information Technology. Within those sectors, only entities meeting the final rule’s criteria count as covered.
When is the CIRCIA final rule expected?
CISA’s current stated target, per the most recent Unified Agenda, is September 2026. That target follows two that did not hold: the October 4, 2025 statutory deadline and a May 2026 internal target. Treat it as a projection, not a confirmed date, until the final rule publishes.
Why did CISA miss the CIRCIA statutory deadline?
CISA’s public notices don’t state a reason for the initial October 2025 miss. The later delay, from the May 2026 internal target to the current September 2026 target, ties to the documented DHS appropriations lapse described above. That lapse forced CISA to postpone and reschedule the stakeholder town halls it needed first.
What are the CIRCIA reporting timeframes for cyber incidents and ransom payments?
The statute sets these clocks, not the rule CISA is still finalizing. A covered cyber incident starts a 72-hour clock. A ransom payment starts a separate 24-hour clock.
Is my company a “covered entity” under CIRCIA?
That depends on sector and size criteria the NPRM proposed but the final rule hasn’t locked. DIB and Information Technology are the two most relevant sectors for this audience. To confirm exact thresholds, read the NPRM and watch for the changes CISA has signaled but not yet detailed.
Does CIRCIA apply to federal contractors specifically, or only critical-infrastructure operators broadly?
CIRCIA’s coverage runs by sector and size, not contractor status. A company becomes a covered entity by operating in a designated sector like Defense Industrial Base, not by holding a federal contract. CISA is weighing whether to add MSPs and CSPs using open-source software as their own category. That would reach vendors, not just contractors.

