Status: Proposed – Final Rule Delayed Past May 2026 Target. CISA's final rule missed its extended May 2026 publication target following the DHS appropriations lapse. Rescheduled stakeholder town halls begin June 15, 2026, and CISA has indicated continued funding disruptions are likely to push the final rule into late 2026 or beyond.
Jurisdiction: Federal
Category: Cybersecurity, Critical Infrastructure
Effective Date: Final rule delayed – originally targeted May 2026. DHS appropriations lapse forced postponement of CIRCIA town halls (March–April 2026). Final rule now expected late 2026 at earliest.
Summary: The Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), signed into law in March 2022, requires CISA to develop and implement regulations requiring covered entities to report covered cyber incidents and ransom payments to CISA. The final rulemaking process has been significantly delayed due to a DHS appropriations lapse that forced postponement of planned CIRCIA town halls in March–April 2026. The final rule is now expected late 2026 at the earliest.
Requirements: Covered entities in critical infrastructure sectors must report covered cyber incidents within 72 hours and ransom payments within 24 hours to CISA. Final rule will define covered entities, covered incidents, and reporting procedures.
Affected Entities: Critical infrastructure operators across 16 designated sectors including healthcare, energy, water, transportation, and communications.
IntelliSee Relevance: Medium – IntelliSee's physical security systems complement cyber incident reporting requirements for critical infrastructure facilities.