Infosecurity-Magazine CIRCIA Final Rules Expected to Transform Cyber Incident Reporting in the US
Article Content
- •CIRCIA mandates reporting cyber incidents within 72 hours and ransom payments within 24 hours.
- •Approximately 316,000 entities, including defense contractors, will be affected by the new rules.
- •Final regulations are expected to be published soon, following delays in implementation timelines.
The Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) is set to implement new reporting rules for cyber incidents across 16 critical infrastructure sectors in the US. Organizations will be required to report incidents to the Cybersecurity and Infrastructure Security Agency (CISA) within 72 hours and ransomware payments within 24 hours. The final rules, which are anticipated to be published soon, aim to harmonize existing reporting structures and clarify requirements for affected entities. Approximately 316,000 organizations, including 72,000 defense contractors, will be impacted by these regulations. The implementation timeline has faced delays, with the latest target set for September 2026. Industry stakeholders have raised concerns about the broad and overlapping nature of the draft rules, which may complicate compliance with existing regulations. National Cyber Director Sean Cairncross emphasized the need for clarity and cooperation among agencies to streamline the reporting process.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…