CIRCIA's Final Rule Is Due This Month. The Exemption You Are Counting On Does Not Exist Yet.
CISA's final rule implementing the Cyber Incident Reporting for Critical Infrastructure Act carries a September 2026 target in the Unified Agenda. It has not published. CISA's own CIRCIA page says the agency continues to work on it and points to multiple appropriations lapses as the cause of the delay.
Nothing is reportable under CIRCIA until that rule takes effect. CISA states this directly on its site.
So why spend time on it now? Because the scope question takes weeks to answer and the reporting question runs on a 72-hour clock. Wait for publication and you will be doing the slow part under the fast part's deadline.
Where the rule actually stands
CIRCIA was enacted in March 2022 and is codified at 6 U.S.C. 681 through 681g. It directed CISA to publish a proposed rule within 24 months and a final rule within 18 months after that.
The NPRM published April 4, 2024, at 89 FR 23644. The statutory deadline for the final rule was October 2025. CISA missed it and moved the target to May 2026. It then held four town hall sessions from June 15 to 18, 2026, drawing more than 1,200 participants. The July 2026 Unified Agenda preview moved the target again, to September 2026.
Two targets have already slipped. Treat September as a target, not a schedule.
CISA has said it intends to narrow scope and deconflict with existing reporting regimes. What that means in practice is not public. Everything below describes the proposed rule, because that is the only version anyone outside CISA has seen.
Whether you are in scope
Under the proposal you are a covered entity if you sit in one of the 16 critical infrastructure sectors and meet either of two independent tests. One is enough.
The size test. You exceed the applicable SBA small business size standard for your industry. For credit unions, NAICS 522130, that standard is currently $850 million in assets. The measurement is not your latest balance sheet. Under 13 CFR 121.201, it is the average of assets reported across your four quarterly NCUA 5300 call reports for the preceding year. SBA opened a five-year review of its monetary size standards in August 2025, so confirm the current figure rather than assuming it.
The sector test. You meet one or more sector-based criteria. The financial services criterion turns on whether you own or operate a legal entity qualifying as one of several specified financial service entity types. The full list is in the proposed regulatory text.
Two features of the sector test catch people.
It applies regardless of size. A small business meeting a sector criterion is covered anyway.
And criteria from other sectors reach you. CISA proposed that an entity meeting any sector criterion is covered even if it does not consider itself part of that sector. If you are a fintech, read the information technology criteria: they reach entities that develop or license critical software, that provide IT products or services to the federal government, and that manufacture or vend operational technology components.
CISA's preliminary analysis estimated 316,244 covered entities. That estimate belongs to the proposed scope, not the final one.
The exception most readers assume protects them
If you already report cyber incidents to NCUA within 72 hours under 12 CFR Part 748, or to NYDFS under Part 500, you might reasonably assume CIRCIA is duplicative and that some exemption will sort it out.
The proposal does contain a substantially similar reporting exception. It carries three conditions, and the third is the problem.
You must be required by law, regulation, or contract to report substantially similar information. You must report it in a substantially similar timeframe. And CISA and that agency must have both an information-sharing mechanism and a written agreement in place, called a CIRCIA Agreement, publicly posted so covered entities know the exception is available.
No CIRCIA Agreement can exist yet, because the framework that creates it is proposed. CISA writes in its own NPRM overview that it "cannot make a final determination about which reporting programs may be eligible" until the final rule publishes.
Two things follow. There is no CIRCIA reporting obligation to satisfy today, and nobody can tell you whether your NCUA or NYDFS reporting will qualify for the exception once there is one. Separately, the proposed data preservation requirement applies even to entities that qualify for the exception. An exemption from reporting would not be an exemption from preserving.
That preservation obligation is worth reading closely. Under the proposal it covers indicators of compromise, relevant log entries, forensic artifacts including memory captures and images, network data, and communications with the threat actor. The clock starts on the date you form a reasonable belief that a covered incident occurred and runs until two years after your last report.
What to do now
Nothing here is a present obligation, and the final rule could change any of it. Treat the following as work that holds its value either way.
Run the size test and write down the answer. Pull four quarters of call report assets, average them, and compare against the current SBA standard for your NAICS code. Date the memo. If the final rule keeps this test, you will have your answer already. If it changes the threshold, you rerun one calculation instead of starting cold.
Read the sector criteria for sectors you do not think you are in. The information technology criteria are the ones that surprise fintechs. This is a thirty-minute read of the proposed regulatory text and it is the only way to find out whether size is even relevant to you.
Check what triggers your incident response plan. The proposed reporting trigger is reasonable belief, not confirmation, which matches the NCUA standard and differs from the "determines" language in the federal banking rule. The proposed definition of a substantial cyber incident also includes unauthorized access facilitated through compromise of a cloud provider, a managed service provider, another third-party data host, or a supply chain compromise. A separate 24-hour clock would run from disbursement of a ransom payment, so map both paths rather than one. If your plan only triggers on incidents inside your own perimeter, that gap is worth closing regardless of what CIRCIA does.
Build preservation into response, not after it. Forensic images and threat actor communications are easy to preserve on day one and hard to reconstruct on day ninety. Your vendor risk assessment process should also ask whether your third parties can preserve and hand over the same categories.
Watch the docket, not the trade press. Docket CISA-2022-0010 on regulations.gov holds the NPRM, the preliminary regulatory impact analysis, the draft privacy guidance, all public comments, and the town hall transcripts. CISA has said it will communicate timeline updates through cisa.gov/CIRCIA.
One last detail that rewards compliance. Under the proposal, CIRCIA reports carry a FOIA exemption, preserve applicable privileges, and come with a bar on any cause of action arising from the submission. Those protections do not attach to material produced in response to a subpoena. The enforcement path runs from a request for information, to a subpoena issued no earlier than 72 hours after service, to a civil action by the Department of Justice. Reporting on time and being compelled to produce are not the same posture.
Source note
This article is based on CISA's CIRCIA page and its NPRM Informational Overview (May 2024); the CIRCIA NPRM published April 4, 2024 at 89 FR 23644, docket CISA-2022-0010; the CIRCIA statute at 6 U.S.C. 681 through 681g; SBA size standards at 13 CFR 121.201 and SBA's August 2025 proposed monetary size standard review; and reporting on the July 2026 Unified Agenda preview from Federal News Network and Hunton Andrews Kurth. Scope, thresholds, and exceptions described here come from the proposed rule and are subject to change in the final rule.
Disclaimer
This article is provided for general information and does not constitute legal advice. Regulatory requirements, compliance dates, examiner priorities, and enforcement posture change frequently. The CIRCIA rulemaking is active and unresolved, and the scope, thresholds, and exceptions described here reflect a proposed rule that has not been finalized. Verify current requirements against primary agency sources and your legal counsel before acting on anything described here.

