Ransomware

CIRCIA's 72-Hour and 24-Hour Reporting Clocks Are Federal Law, and Still Have No Start Date

Key Takeaways

  • 6 U.S.C. 681b sets a 72-hour report for covered cyber incidents and a 24-hour report for ransom payments, but paragraph (a)(7) makes both effective only on dates prescribed in the final rule
  • Covered entity and covered cyber incident are both defined by reference to the final rule, so the statute alone does not identify who reports
  • CISA's April 4, 2024 proposal estimated 316,244 potentially affected entities and 210,525 reports; it remains a proposal
  • The statute required a final rule within 18 months of the proposal, which the Unified Agenda records as October 4, 2025; the 2026 agenda projects September 2026
  • A Federal Register search on September 14, 2026 returned no final rule; the latest rulemaking document is a May 26, 2026 notice rescheduling town halls

What Congress Enacted in March 2022

CIRCIA was enacted on March 15, 2022 as division Y of Public Law 117-103 and is codified in Title 6 of the United States Code beginning at section 681. Its core is section 681b. Paragraph (a)(1)(A) provides that a covered entity that experiences a covered cyber incident "shall report the covered cyber incident to the Agency not later than 72 hours after the covered entity reasonably believes that the covered cyber incident has occurred." Paragraph (a)(2) requires a covered entity that makes a ransom payment as the result of a ransomware attack to report it "not later than 24 hours after the ransom payment has been made," and states that the payment duty applies "even if the ransomware attack is not a covered cyber incident."

The 72 hours binds the agency as well as the reporter. Paragraph (a)(1)(B) provides that the Director "may not require reporting under subparagraph (A) any earlier than 72 hours" after the reasonable belief arises. The rest of subsection (a) builds around the two clocks:

  • Supplemental reports under (a)(3), submitted promptly when substantial new or different information becomes available or a ransom is paid after an incident report, until the entity notifies CISA that the incident has concluded and been fully mitigated and resolved
  • Preservation of data relevant to the incident or payment under (a)(4), following procedures the final rule sets
  • A single combined report under (a)(5)(A) where a ransom is paid before the 72-hour incident report is due
  • An exception under (a)(5)(B) for an entity required to report substantially similar information to another federal agency within a substantially similar timeframe, which takes effect only once CISA and that agency have an agreement and sharing mechanism in place
  • An exclusion under (a)(5)(C) for multi-stakeholder organizations that govern the Domain Name System

Subsection (d) lets a covered entity use a third party, such as an incident response company, insurance provider, service provider or law firm, to submit a report, without relieving the entity of the duty. A third party that makes a ransom payment for the entity is not required to file its own payment report, but one that "knowingly makes a ransom payment" on the entity's behalf must advise it of its reporting responsibilities.

Every Operative Term Waits on the Final Rule

The clocks are complete on paper. The definitions that decide whom they bind are not. Under 6 U.S.C. 681, a covered entity is "an entity in a critical infrastructure sector, as defined in Presidential Policy Directive 21, that satisfies the definition established by the Director in the final rule," and a covered cyber incident is "a substantial cyber incident experienced by a covered entity that satisfies the definition and criteria established by the Director in the final rule." Ransom payment is defined in the statute itself, as the transmission of any money or other property or asset, including virtual currency, delivered as ransom in connection with a ransomware attack.

Timing is deferred the same way. Section 681b(a)(7) provides that paragraphs (1) through (4) "shall take effect on the dates prescribed in the final rule," and (a)(6) leaves the manner and form of reports to that rule. Section 681b(c) prescribes what the rule must contain. The covered entity description is to rest on the consequences that disrupting an entity could cause, the likelihood it is targeted, and whether compromising it would enable disruption of critical infrastructure. The covered cyber incident description must at minimum reach substantial loss of confidentiality, integrity or availability, disruption of business or industrial operations including by ransomware, and unauthorized access or disruption caused through a compromised cloud, managed service or other third-party provider or a supply chain compromise. It must exclude good-faith activity performed at the system owner's request and a threat of disruption made as extortion.

CISA's own statements track the statute. Its CIRCIA page says: "Until the effective date of the final rule, organizations are not required to submit covered cyber incident or ransom payment reports under CIRCIA." Its FAQ adds that the final rule "will expressly identify its effective date."

What the April 2024 Proposal Would Do

CISA published its notice of proposed rulemaking at 89 FR 23644 on April 4, 2024, proposing a new 6 CFR part 226. The comment period was extended to July 3, 2024 at 89 FR 37141, and a correction followed at 89 FR 47471 on June 3, 2024. None of the proposal binds anyone. What CISA proposed includes:

  • Covered entity: an entity in a critical infrastructure sector that either exceeds the Small Business Administration size standard for its industry code under 13 CFR part 121 or meets one of a set of sector-based criteria, with either route sufficient
  • Scale: an estimated 316,244 potentially affected entities submitting an estimated 210,525 reports over the period of analysis, at an undiscounted cost of $1.4 billion to industry and $1.2 billion to the federal government
  • Supplemental reports: "promptly" read as within 24 hours of the triggering event, including a supplemental report within 24 hours of a ransom payment tied to an incident already reported
  • Preservation: data and records kept from the date of reasonable belief or of payment until two years after the latest report
  • Noncompliance: referral to the DHS Suspension and Debarment Official, and sharing information with federal contracting officials, alongside the statutory request and subpoena tools

The proposal also projected its own timing. Its regulatory analysis stated that "CISA expects the Final Rule to publish in late 2025" and that the required 60-day delay "would likely push the effective date to 2026."

The Deadline Congress Set, and the Rulemaking Since

Section 681b(b)(2) required the Director to issue the final rule "[n]ot later than 18 months after publication of the notice of proposed rulemaking." The Spring 2025 Unified Agenda entry for RIN 1670-AA04 records that statutory deadline as October 4, 2025 and projected the final rule for May 2026. The 2026 agenda entry keeps the same deadline, moves the projected final rule to September 2026, lists the priority as other significant rather than economically significant, and says CISA "received significant public comments on the proposed rule, many of which emphasized the need to reduce the scope and burden of the proposed reporting requirements, improve harmonization of CIRCIA with other federal cyber incident reporting requirements, and clarify terms."

Two Federal Register notices in 2026 record the delay. The February 13, 2026 notice at 91 FR 6794 announced town halls to take further input on "refining the scope and burden" of the proposal and reported approximately 300 comments on it. The May 26, 2026 notice at 91 FR 30498 explained that those meetings were not held "[d]ue to the lapse in the Department of Homeland Security's (DHS) appropriations from February 14, 2026, to April 30, 2026," and rescheduled them for June 15 to 18, 2026. CISA's page states that four town halls took place on those dates and that "multiple funding lapses impacted CISA's ability to conduct rulemaking activity for CIRCIA. CISA continues to work on the final rule."

A Federal Register search for the Act's name, run for this article on September 14, 2026, returned no final rule. The most recent document in rulemaking docket CISA-2022-0010 is the May 26, 2026 town hall notice. On that record the 72-hour and 24-hour obligations have no effective date, and the population they will reach has not been fixed.

Enforcement Runs Through Requests and Subpoenas

The statute's compliance mechanism, at 6 U.S.C. 681d, contains no schedule of fines. Where the Director has reason to believe a covered entity failed to report, the Director may request information. If there is no response, or an inadequate one, 72 hours after the request, the Director may issue a subpoena. A subpoena the entity does not comply with may be referred to the Attorney General for a civil action in federal district court, and a court may punish noncompliance as contempt. The subpoena authority may not be delegated, and the section does not apply to state, local, tribal or territorial government entities.

Information obtained by subpoena is treated differently from a report. Section 681d(d) allows the Director to provide it to the Attorney General or the head of the appropriate federal regulatory agency if the facts may constitute grounds for a regulatory enforcement action or criminal prosecution. The Director reports to Congress each year on the number of requests, subpoenas and referrals, and publishes a version on CISA's website.

Limits on How Reports Can Be Used

Section 681e attaches protections to reports. A federal, state, local or tribal government may not use information obtained solely through reporting to CISA "to regulate, including through an enforcement action," the reporting entity, unless that government expressly allows entities to submit CIRCIA reports to meet its own reporting obligations. Reports are exempt from the federal Freedom of Information Act and from state open records laws, do not waive any privilege, and are treated as commercial, financial and proprietary information when the entity so designates them.

Section 681e(c) bars any cause of action based solely on submitting a report that conforms to the Act and the rule, except the government's own action to enforce a subpoena, and provides that a report, and records created for the sole purpose of preparing it, may not be received in evidence or be subject to discovery in any proceeding. The same paragraph states that it creates no defense to discovery of records not created for that sole purpose. CISA must anonymize the victim when making report information available to critical infrastructure owners and operators or the public.

How It Sits Beside Other Federal Reporting Duties

CIRCIA does not displace existing regimes. Section 681b(h) provides that nothing in the section limits the authority of any federal officer or agency to regulate or take action with respect to an entity's cybersecurity. The proposed rule noted that at the federal level alone "more than three dozen" cyber incident reporting requirements were already in place, and proposed a defined "CIRCIA Agreement": an agreement between CISA and another federal agency that, when publicly posted, would indicate that the substantially similar reporting exception is available.

The sequencing is set by statute. The exception in 681b(a)(5)(B) takes effect for a covered entity only once an agreement and sharing mechanism is in place with the relevant agency, and there is no CIRCIA reporting duty for the exception to relieve until the final rule prescribes one.

Background

For the underlying law rather than this development: Financial Services privacy law.

Frequently Asked Questions

Is CIRCIA reporting mandatory as of September 2026?
No. 6 U.S.C. 681b(a)(7) makes the reporting paragraphs effective on dates prescribed in a final rule, and no final rule had been published in the Federal Register as of September 14, 2026. CISA's CIRCIA page states that until the final rule's effective date, organizations are not required to submit reports under CIRCIA.
Which organizations will CIRCIA cover?
The statute limits covered entities to entities in a critical infrastructure sector under Presidential Policy Directive 21 and leaves the definition to the final rule. CISA's 2024 proposal would cover sector entities above the SBA size standard or meeting sector-based criteria, an estimated 316,244 entities. The 2026 Unified Agenda entry says many comments emphasized reducing the scope and burden of that proposal.
Does the CIRCIA 24-hour ransom payment report apply when the attack is not a covered cyber incident?
Under the statute, yes. Section 681b(a)(2)(B) applies the payment duty even if the ransomware attack is not a covered cyber incident, and 681b(a)(5)(A) allows one combined report where a payment is made before the 72-hour incident report is due. Neither duty is in effect until the final rule sets its date.
Can an incident response firm or insurer file a CIRCIA report for a covered entity?
Section 681b(d) allows a covered entity to use a third party, including an incident response company, insurance provider or law firm, to submit a report, but the entity keeps the duty to comply. A third party that knowingly pays a ransom on the entity's behalf must advise the entity of its payment reporting responsibilities.
What does CIRCIA provide if a covered entity does not report?
Section 681d provides for a request for information, then a subpoena if there is no adequate response within 72 hours, and referral to the Attorney General for a civil action to enforce the subpoena. Information obtained by subpoena may be passed to the Attorney General or a federal regulator. The section sets no civil penalty amount.

Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.