\n\n

On October 1, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (“CISA”) submitted a draft of the Final Rule implementing the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (“CIRCIA”) to the Office of Information and Regulatory Affairs (“OIRA”) for interagency review, marking one of the final steps before the Final Rule will be published in the Federal Register.  

As previously described, CIRCIA will require covered critical-infrastructure entities to report certain cybersecurity incidents within 72 hours and ransomware payments within 24 hours to CISA.  CISA published its Notice of Proposed Rulemaking (“Proposed Rule”) in April 2024 and received substantial feedback from industry and trade associations regarding the proposal’s scope, reporting requirements, and overlap with existing reporting obligations.  In response to the hundreds of comments that it received, CISA held a series of town halls in June 2026 to solicit additional stakeholder input.  Covington previously summarized the town halls and steps organizations can take to prepare for the Final Rule, here.

The review by OIRA can take up to 90 days (or longer if OIRA seeks an extension), in which case the Final Rule would not be published until early next year.  While the effective date is not provided in CIRCIA, it is likely that implementing regulations will not become effective for at least 60 days after publication in the Federal Register.  The precise effective date will be included in the Final Rule text.