Someone Says CIRCIA Reporting Starts Now. Check the Rule Status First
Separate the 2022 statute, the 2024 proposed rule and the 2026 CISA rulemaking notices before treating 72-hour or 24-hour language as an effective reporting duty.

Signals to watch
- A critical-infrastructure operator asks for a CIRCIA implementation project but only cites the 2024 NPRM
- A message states that a 72-hour or 24-hour CIRCIA clock is effective without naming a final-rule publication and effective date
- A 2026 CISA town-hall notice prompts scope or burden questions that may change an eventual final rule
As of 14 August 2026, the official record checked for this article did not show an effective CIRCIA final rule. The Federal Register classifies CISA’s 4 April 2024 document as a proposed rule. A 26 May 2026 notice was still inviting limited additional input on refining that proposal’s scope and burden. The often-repeated 72-hour incident and 24-hour ransom-payment periods therefore belong to the proposal, not to a final-rule effective-date notice.
For a cyber-incident reporting platform or advisory provider’s sales director watching authorised critical-infrastructure, Information Sharing and Analysis Center (ISAC) and CISO Telegram groups, that status changes the first response. A message saying “CIRCIA starts this quarter” needs a source check before it becomes a deadline project. Missing it by one day may still cost a requirements workshop, but inventing an effective date can mis-scope the entire engagement.
The current event is continued rulemaking, not a final-rule launch
CIRCIA is the Cyber Incident Reporting for Critical Infrastructure Act of 2022. The statute directed the Cybersecurity and Infrastructure Security Agency (CISA) to issue regulations for covered cyber-incident and ransom-payment reporting by covered entities.
On 4 April 2024, CISA published the CIRCIA Reporting Requirements NPRM. NPRM means Notice of Proposed Rulemaking: it presents proposed regulatory text and asks for comment; it is not the final rule.
The 26 May 2026 Federal Register notice described revised town halls that would give stakeholders another limited opportunity to comment on refining the scope and burden of the 2024 NPRM. That later notice is strong evidence of ongoing rulemaking. It is not an effective-date notice.
Put every deadline claim on a source-status card
Use five fields:
- Authority: statute, proposed rule, final rule, sector rule, state law, SEC rule or contract;
- Document status: enacted, proposed, final, stayed, amended or effective;
- Covered actor and event: who reports, and what fact starts the clock;
- Time period: number and unit, including when counting begins; and
- As-of date: the date the official source was last checked.
This source-status card is the article’s original contribution. It prevents a correct number from a proposal being attached to the wrong legal status.
For this article the card reads: CIRCIA statute enacted in 2022; implementing NPRM published 4 April 2024; additional rulemaking input announced in 2026; no final rule found in the checked Federal Register record as of 14 August 2026.
Keep the 72-hour and 24-hour numbers in the proposal column
The 2024 NPRM proposed reports to CISA within 72 hours after a covered entity reasonably believes a covered cyber incident occurred, and within 24 hours after a ransom payment was made. It also proposed supplemental reporting where substantial new or different information becomes available.
Those numbers matter for product architecture and scenario planning. A reporting platform may need an event time, belief or determination time, legal-entity owner, payment time, submission status and later supplement history. But a proposal-labelled requirement should not be sold as an operative CIRCIA deadline.
The eventual final rule can change definitions, covered-entity scope, exceptions, report contents, process details or burden. The final document and its effective-date provisions must be read when published.
Example: the 72-hour request belongs to another regime
Consider this illustrative composite exchange, not a real customer conversation:
“Ops wants CIRCIA workflow live before September. They said 72h.”
“We are public, transport subsidiary. Legal also mentioned SEC, not sure which clock.”
The discussion gives a month, a proposed CIRCIA number, public-company status and a transport subsidiary. It does not identify the incident, materiality decision, relevant transport rule, covered entity, ransom payment, contract or official citation.
The source-status card should split the request:
- CIRCIA: proposal status as of the checked date; covered-entity and incident definitions are not yet final.
- SEC: a separate public-company disclosure analysis with its own trigger and timing.
- Transport: possible sector-specific obligations that require the exact operator and rule.
- Contract: any customer or insurer notice term, which can be shorter and independent.
The commercial need may be real—a team can legitimately want one incident record routed to several rule-specific clocks. The phrase “CIRCIA is live” is still unsupported.
No final CIRCIA rule does not mean “no reporting”
Organisations may already have incident-notification duties under sector regulations, state breach laws, SEC disclosure rules, government contracts, insurance terms or customer agreements. CISA also accepts voluntary reporting. Those routes should not be relabelled CIRCIA to make the project sound current.
The safer scope is a rule-aware incident record: preserve the observed facts once, then let authorised legal and compliance owners map them to each applicable trigger. A platform vendor should never promise that one generic severity field decides materiality, coverage or reportability across regimes.
For a separate example of recovering an official disclosure source, see the SEC incident-disclosure source guide. The official-source ladder explains why a screenshot or repost cannot replace the current primary document.
What to watch next
The status card changes only when an official event changes it. Watch for a Federal Register document identified as a final rule, the final regulatory text, an effective date, any phased compliance dates and updated CISA implementation guidance. Record the exact publication and access dates.
TOP Prospect can surface references to those events from Telegram groups the user deliberately connects and is authorised to access, preserve message sources and times, combine repeat mentions and rank them for review. It cannot declare a rule effective, interpret coverage, file an incident report or contact the message author. Pricing and access options cover discovery, not legal reporting.
Key facts
- CIRCIA was enacted in 2022 and directs CISA to implement covered cyber-incident and ransom-payment reporting through regulations.
- The 4 April 2024 Federal Register document is labelled a proposed rule.
- The proposed periods are 72 hours for a covered cyber incident and 24 hours for a ransom payment.
- The 26 May 2026 notice continued stakeholder input on refining the NPRM’s scope and burden.
- The official sources checked on 14 August 2026 did not show a published CIRCIA final rule.
- Other incident-reporting and disclosure duties may apply independently.
- An eventual final rule and its effective-date text, not a group message, will change the status card.
FAQ
Was a CIRCIA final rule published by 14 August 2026?
The Federal Register materials checked on 14 August 2026 showed the 4 April 2024 CIRCIA document as a proposed rule and 2026 notices continuing to seek input on that NPRM. This source check found no published CIRCIA final rule.
Are the proposed 72-hour and 24-hour periods meaningless?
No. They are important design assumptions from the NPRM: 72 hours for a covered cyber incident and 24 hours for a ransom payment. They should be labelled proposed until an effective final rule establishes the operative requirements.
Does the absence of a CIRCIA final rule mean an organisation has no incident-reporting duties?
No. Sector rules, SEC disclosure, state law, contractual notice terms and voluntary CISA reporting can exist independently. Each claim needs its own authority and trigger.
The official-source check starts with document status
Start with the Federal Register document type, publication date and effective-date text, then confirm against CISA current rulemaking material and the organisation-specific regime.
Write the as-of date beside the deadline. Otherwise a proposed number can quietly become a false effective date.
Frequently asked questions
Was a CIRCIA final rule published by 14 August 2026?
The Federal Register materials checked on 14 August 2026 showed the 4 April 2024 CIRCIA document as a proposed rule and 2026 notices continuing to seek input on that NPRM. This source check found no published CIRCIA final rule.
Are the proposed 72-hour and 24-hour periods meaningless?
No. They are important design assumptions from the NPRM: 72 hours for a covered cyber incident and 24 hours for a ransom payment. They should be labelled proposed until an effective final rule establishes the operative requirements.
Does the absence of a CIRCIA final rule mean an organisation has no incident-reporting duties?
No. Sector rules, SEC disclosure, state law, contractual notice terms and voluntary CISA reporting can exist independently. Each claim needs its own authority and trigger.
What official source should be checked first?
Start with the Federal Register document type, publication date and effective-date text, then confirm against CISA current rulemaking material and the organisation-specific regime.
Sources and further reading
How a Signal worth attention is found
See how Top Prospect finds and organizes Signals worth checking, keeps the original Telegram context, removes duplicates, and helps you decide what to review first. You decide whether to follow up and what to do next.
