IC Oversight & Policy — 2026-07-07
CISA Expects to Finalize Mandatory Cyber Incident Reporting Rule by September After Missing 2025 Deadline
BLUFFinalization of mandatory cyber incident reporting by end of September remains unlikely, leaving critical infrastructure breach visibility stuck in the same gap exposed by SolarWinds five years ago.
CISA expects to finalize the CIRCIA mandatory cyber incident reporting rule by September, according to a regulation document published last week and reported by Nextgov 1. The rule will require critical infrastructure entities to report substantial cyber incidents to CISA within 72 hours and ransomware payments within 24 hours 1. CISA published the notice of proposed rulemaking on April 4, 2024, and missed the statutory October 2025 final-rule deadline 1Final Rule Stage" data-source="Office of Information and Regulatory Affairs (reginfo.gov Unified Agenda)" data-url="https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202510&RIN=1670-AA04" data-rt="primary" data-otype="government">2. The Office of Information and Regulatory Affairs lists the rule as in Final Rule Stage, with CISA still reviewing public comments that emphasized reducing the scope of proposed reporting requirements and harmonizing CIRCIA with other federal reporting regimes 2. CISA held additional stakeholder town halls last month after a since-resolved DHS funding lapse in the spring delayed the scheduling of those sessions 1.
AnalysisFinalization by September is
unlikely, given CISA missed the October 2025 statutory deadline while still working through public comments pressing to narrow reporting scope and harmonize CIRCIA with other federal regimes. Moderate confidence reflects a track record of slipped timelines set against a documented rulemaking-stage advance, with no independent signal on how CISA will resolve the scope disputes driving the delay. Mandatory reporting for substantial incidents and ransomware payments remains suspended pending the rule, extending the reporting gap first flagged after SolarWinds and Colonial Pipeline.
2 sources
- CISA expects to finalize key cyber reporting rule by September - Nextgov
- View Rule: Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements, RIN 1670-AA04 - Final Rule Stage - Office of Information and Regulatory Affairs (reginfo.gov Unified Agenda)
View in full brief →