A sweeping federal cyber incident reporting law is set to cover approximately 316,000 organizations across US critical infrastructure, yet its implementation date remains uncertain after multiple missed deadlines, according to a report published by Infosecurity Magazine on September 29, 2026. The Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), passed by Congress and signed in March 2022, will require covered entities to report cyber incidents within 72 hours and ransom payments within 24 hours after payment is made. The law represents what experts call the broadest cyber reporting mandate the federal government has ever proposed, but final rules from the Cybersecurity and Infrastructure Security Agency (CISA) have been delayed repeatedly, with an October 2025 statutory deadline and a May 2026 target both missed before the government set a September 2026 goal that also appears likely to slip.
The legislation covers organizations in 16 critical infrastructure sectors that exceed the Small Business Administration's small business size threshold, as well as specific categories including hospitals, communications providers, and certain defense contractors regardless of size. Defense contractors and subcontractors make up the single largest category, accounting for 72,000 of the estimated 316,000 covered entities. These defense firms already report to the Department of Defense under DFARS 252.204-7012, a contract clause requiring adequate security for Controlled Unclassified Information and cyber incident reporting. Under the proposed rule, covered entities would need to retain records and information related to reported incidents for two years, including technical evidence, logs, communications, and any other information tied to the incidents.
Frank Balonis, field CISO at Kiteworks, told the publication that "CIRCIA is the broadest cyber reporting mandate the US federal government has ever proposed." The report notes that CIRCIA will shield submitted reports from Freedom of Information Act disclosure and from use as evidence in enforcement actions, though this protection doesn't cover the underlying incident or a response compelled by subpoena. Emil Sayegh, CEO of CyberSheath, said "CIRCIA will turn CISA into a meaningful enforcement authority," adding that the agency will gain administrative subpoena power and the government can pursue enforcement through the courts. Noncompliant entities can face subpoenas and referral to the Department of Justice, or for federal contractors, suspension and debarment.
The consecutive delays appear linked to CISA funding challenges caused by the US government shutdown at the end of 2025 and beginning of 2026, according to the report. Uncertainty persists around whether enforcement will begin immediately after publication or whether CISA will grant a grace period of months, with one expert suggesting reporting duties likely start sometime in late 2026 or 2027. The report highlights that many organizations aren't prepared for the two-year retention requirement, with some systems capturing only 30 days of information, creating a bottleneck that will require additional cyber investment. The law will establish a Cyber Incident Reporting Council, chaired by the Department of Homeland Security, to harmonize overlapping federal reporting requirements—particularly important for defense contractors already subject to multiple regimes including DFARS, NIST SP 800-171, and Cybersecurity Maturity Model Certification.
Despite the delays, experts interviewed for the report recommend that potentially covered organizations begin preparing immediately by conducting gap assessments, updating incident response plans to map CIRCIA's requirements, and strengthening detection and evidence-preservation capabilities. Balonis cautioned organizations not to "wait and see which date holds," warning that Washington wants real-time visibility into breaches across critical infrastructure and that organizations building toward that now won't be scrambling when the final rule lands. The report outlines an 11-step compliance playbook including determining coverage status, establishing harmonized reporting processes for multiple regimes, conducting regular tabletop exercises, and preparing supply-chain notification protocols. Organizations that focus on demonstrating cyber governance through documented evidence trails and rehearsed decision paths—rather than simply maintaining policies on paper—will be best positioned when the rule takes effect, regardless of when that happens. The fundamental challenge isn't regulatory timing but operational readiness, since the threats CIRCIA addresses don't pause while agencies work through administrative procedures.

