First Source
Cybersecurity · July 24, 2026
CIRCIA · CISA proposed rule April 2024 · statutory deadline missed · final rule now expected September 2026

Everyone read the delay as breathing room. But you can't stand up a someday 72-hour reflex in the middle of the incident that needs it.

Ask the security lead you trust most when CIRCIA “kicks in,” and you'll get a date with a shrug attached. The rule has slipped again — CISA now says it expects to finalize the cyber incident reporting regulation in September, after blowing past the October 2025 deadline Congress wrote into the statute. Every slip lands the same way in a boardroom: good, we have more time. That reading is the trap.

Because the thing the rule turns on is not a filing date. It is a reflex. Once the final rule is in force, a covered entity will have to report a covered cyber incident to CISA within 72 hours — and a ransom payment within 24. And here is the detail almost nobody is pricing: CISA's own materials start that 72-hour count “from the time the entity reasonably believes the incident occurred.” Not when you've confirmed it. Not when legal signs off. When you have reason to believe.

Verbatim, from CISA's CIRCIA materials (the trigger)
72 hours from the time the entity reasonably believes the incident occurred.

Sit with “reasonably believes” for a second, because it is doing all the work. It is an earlier trigger than the ones most teams have rehearsed to. The SEC's is material. A cyber-insurance policy's is notice “as soon as practicable.” CIRCIA's fires on suspicion — on the Friday-night pager, before you know how bad it is. A team that waits for certainty to start the clock has already spent a night of the seventy-two hours it didn't know it was on.

So my read for anyone advising covered entities: stop treating the September date as the thing to plan around. The date is soft — it has moved before and can move again. The 72-hour muscle is hard, and it is the one thing that cannot be built reactively. You do not draft a reporting workflow, name the human who files, and pre-clear it with counsel while you are containing an intrusion. You do it now, in the quiet the delay is handing you, or you do it badly at three in the morning.

72 hrs
to report a covered cyber incident once the rule is in force — counted from when the entity reasonably believes it occurred, not when it's confirmed
24 hrs
to report a ransom payment — a separate, shorter clock that can start on a night you're least ready to run a process

The regulation's publication date keeps moving. Neither of these two numbers ever has.

The scope nobody opts out of

CIRCIA reaches across the 16 critical infrastructure sectors — not just power and water, but healthcare, financial services, food, comms, and the vendors woven through all of them. “We're not critical infrastructure” is a sentence a lot of companies will say and a smaller number will actually be right about; the sector definitions are broad, and the proposed rule reaches entities most people would never file under “utility.”

Name the human, not the plan
A 72-hour clock needs a person, not a policy PDF. Decide now who decides an incident is reportable, who writes the report, and who can reach them on a holiday weekend. The most common CIRCIA gap won't be knowing the rule — it'll be a report nobody was named to file.
Wire the trigger to 'reasonably believes'
Set your internal clock to start on suspicion, not confirmation. If your runbook says “begin reporting timeline once the incident is validated,” you've mis-set the CIRCIA clock by hours you don't have. Rehearse the version where you're not yet sure — that's the real one.
Reconcile the clocks you already carry
Most covered entities already owe notice to a regulator, an insurer, and sometimes the SEC on different triggers and different clocks. Map them side by side now. When they collide during an actual incident, the 72-hour CIRCIA clock will usually be the one that starts first — and the one people forget.

Kept honest: CIRCIA (the Cyber Incident Reporting for Critical Infrastructure Act of 2022) is not yet in force — the 72-hour and 24-hour obligations bind covered entities only after CISA's final rule takes effect, and this edition is about preparing for that, not a duty owed today. The reporting timeframes and the “reasonably believes” trigger are quoted from CISA's own CIRCIA materials, fetched this run; the proposed rule was published in April 2024, the statutory final-rule deadline of October 2025 was missed, and the September finalization is CISA's stated expectation as reported this month — a target, not a published effective date, and it has moved before. The SEC and insurance comparisons are the general shape of those obligations, not legal advice; every entity's exact status and clocks turn on its own facts and its own counsel.

Sources (primary, verified today): CISA, “Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA),” agency page fetched this run with a browser user-agent (WebFetch is 403-blocked there), from which the 72-hour covered-incident timeframe (“72 hours from the time the entity reasonably believes the incident occurred”), the 24-hour ransom-payment timeframe, and the 16 critical-infrastructure-sector scope are quoted verbatim. The CIRCIA notice of proposed rulemaking was published in the Federal Register on April 4, 2024 (89 FR 23644). That CISA missed the statutory October 2025 final-rule deadline and now expects to finalize the rule in September 2026 is CISA's stated timeline as reported in July 2026 trade coverage (Nextgov/FCW, Hunton, Federal News Network); it is a target, not a published effective date, and is presented as such.

Meschelle Peterson
code63labs

LinkedIn-ready text

CIRCIA slipped again. CISA now says it expects to finalize the cyber incident reporting rule in September — after missing the October 2025 deadline Congress put in the statute.

Every time the date moves, a boardroom exhales: good, more time.

That's the trap. The rule doesn't turn on a filing date. It turns on a reflex.

Once it's in force, a covered entity has 72 hours to report a covered cyber incident to CISA — and 24 hours to report a ransom payment. And the part almost nobody is pricing: CISA's own materials start the 72-hour count "from the time the entity reasonably believes the incident occurred." Not when it's confirmed. Not when legal signs off. When you have reason to believe.

Sit with "reasonably believes," because it's doing all the work. It's an earlier trigger than the ones most teams rehearse to. The SEC's is material. Your cyber policy's is "as soon as practicable." CIRCIA's fires on suspicion — on the Friday-night pager, before you know how bad it is. A team that waits for certainty to start the clock has already burned a night of the 72 hours it didn't know it was on.

So here's the read I'd give anyone advising covered entities: stop planning around September. The date is soft — it's moved before. The 72-hour muscle is hard, and it's the one thing you can't build reactively.

Three things to do in the quiet the delay is handing you:

— Name the human, not the plan. A 72-hour clock needs a person who files, not a policy PDF. The most common gap won't be knowing the rule — it'll be a report nobody was named to send.

— Wire your internal trigger to "reasonably believes," not "confirmed." If your runbook starts the timeline once an incident is validated, you've mis-set the clock by hours you don't have.

— Reconcile the clocks you already carry — regulator, insurer, SEC. When they collide in a real incident, the 72-hour CIRCIA clock usually starts first, and it's the one people forget.

The publication date keeps moving. The 72 hours never has.

Source: CISA CIRCIA materials, quoted verbatim; NPRM published April 4, 2024 (89 FR 23644); September finalization is CISA's stated expectation, reported July 2026.

Your narrated animation

A finished, narrated animation of this edition came with your email (MP4, 1080×1350 — sized for LinkedIn and Instagram). Post it as-is.

FIRST SOURCE · one verified original-source finding, composed for one reader · this edition: cybersecurity — written for the advisers, ISSA chapters, and security teams whose clients are reading a rule delay as a reprieve