IC Oversight & Policy — 2026-10-05
CISA Submits Mandatory Cyber Incident Reporting Final Rule for Interagency Review After Two-Year Delay
BLUFCISA's CIRCIA final rule is genuinely uncertain to reach the Federal Register by mid-January 2027, as the 90-day OIRA clock leaves no margin for extension and unresolved Pentagon reporting overlaps could stall interagency clearance.
CISA submitted the final Cyber Incident Reporting for Critical Infrastructure Act rule to OMB's Office of Information and Regulatory Affairs, with Inside Cybersecurity dating the filing to October 1 and GovInfoSecurity to Thursday, after CISA missed its September target in the regulatory agenda 12. Inside Cybersecurity reported that review runs 90 days unless extended, which would allow publication in early January 1. The 2024 proposal would require covered entities to report substantial incidents within 72 hours and ransom payments within 24 hours; Congress set an October 2025 deadline that CISA extended twice 12. National Cyber Director Sean Cairncross said Tuesday the White House has "a tremendous partnership" with CISA on the rule 2. Summit 7's Jacob Horne said defense contractors, already bound by a 72-hour Pentagon reporting requirement, face a second regime, and that no agreement with the Pentagon has been indicated 2.
AnalysisPublication of the CIRCIA final rule by January 15, 2027 is
genuinely uncertain. A full 90-day OIRA review lands in early January and leaves almost no margin for an extension or post-clearance publication lag. The submission is a real step past the missed May and September targets, but White House pressure may instead produce clearance well inside 90 days and December publication. Defense contractors already under a 72-hour Pentagon requirement face a second regime with no harmonization agreement indicated, so overlap fights would surface in review. Confidence is moderate: the two outlets converge but are not independent, and neither sees inside OIRA. A YES starts compliance clocks and forces dual-reporting spending in early 2027, while a NO extends the voluntary-reporting gap and gives industry time to lobby for a single-report agreement.
2 sources
- CISA submits incident reporting final rule for interagency review - Inside Cybersecurity
- CISA Sends Final CIRCIA Rule to White House for Review - GovInfoSecurity
View in full brief →