CIRCIA's September Target Passed Without a Rule. Publication Day Would Not Be Day One Anyway.
CISA's final rule implementing the Cyber Incident Reporting for Critical Infrastructure Act carried a September 2026 target in the Unified Agenda. September closed. No final rule has published, and the Federal Register index for RIN 1670-AA04 still lists only the April 2024 proposal and its two follow-on notices.
That makes three targets missed. The statutory deadline was October 2025, 18 months after the proposed rule appeared at 89 FR 23644 on April 4, 2024. CISA moved the target to May 2026, then to September.
If you started scope work on the strength of the September date, the useful correction is not a new date. It is understanding what publication would actually start.
Publication and enforceability are different events
A published final rule does not create an immediate reporting obligation. Rules carry an effective date, and the rulemaking process generally provides a compliance window between publication and the date obligations attach.
CISA states the position directly on its CIRCIA page. Organizations are not required to submit cyber incident or ransom payment reports under CIRCIA until the effective date of the final rule, and that date is not yet determined.
What is knowable is the structure. The obligations described in the proposal would begin on the final rule's effective date, not on the day it appears in the Federal Register. CISA has said nothing public about how long that window would be.
So the gap between today and your first report is probably longer than the calendar suggests. The gap between publication and your first report will be shorter than you want if the scope work is not done.
The funding explanation does not cover the next ten weeks
CISA has attributed the delay to appropriations lapses affecting its rulemaking activity. That described real disruption through 2025 and into 2026. It does not describe the window you are in now.
The Continuing Appropriations and Extensions Act, 2027 was signed September 2, 2026 as Public Law 119-103. Division A continues appropriations through December 11, 2026. Roughly ten funded weeks sit between today and that date.
The same law carries a second cyber item to the same day. Section 2011 amended 6 U.S.C. 1510(a) by striking September 30, 2026 and inserting December 11, 2026, which moved the sunset on the Cybersecurity Information Sharing Act of 2015 protections. If you are tracking one December 11 date, you are tracking two.
Expectations for the rule have moved from a month to a season. National Cyber Director Sean Cairncross, speaking at a USTelecom event the week of September 29, pointed to harmonizing the reporting structure and said attention has gone into fitting the final rules to requirements that already exist. Trade coverage of those remarks places the rule in fall 2026.
Read that against the article's central problem. Harmonization is the substantially similar reporting exception, and that exception is the part of the proposal most likely to move. An on-the-record signal from the National Cyber Director is not a publication date and it is not a CISA commitment. It is a reason to expect the deconfliction language to change rather than disappear.
What the delay does not change
Four things in the proposal have held steady across two and a half years and are unlikely to disappear entirely, whatever narrowing CISA applies.
Reporting would run on two clocks. Seventy-two hours from reasonable belief that a covered incident occurred. Twenty-four hours from disbursement of a ransom payment.
Scope would turn on two independent tests. Exceeding the applicable SBA small business size standard for your industry, or meeting one or more sector-based criteria. Either one is sufficient. CISA's preliminary analysis estimated 316,244 covered entities under the proposed scope.
Data preservation would attach to the incident, not to the report. Under the proposal it covers indicators of compromise, log entries, forensic artifacts including memory captures and images, network data, and communications with the threat actor, running until two years after the last report.
Enforcement would run through compulsory process rather than a penalty schedule. A request for information, then a subpoena no earlier than 72 hours after service, then referral to the Department of Justice for civil enforcement.
The proposal states that data preservation applies even to entities excused from reporting under the substantially similar reporting exception. An exemption from reporting would not be an exemption from preserving. That is the one obligation you can build for now without knowing how CISA narrows scope, because it attaches to the incident rather than to the filing.
What to do with the extra time
Finish the scope determination and date it. Four quarters of assets averaged against the current SBA standard for your NAICS code, plus a read of the sector-based criteria including sectors you do not consider yourself part of. If the final rule moves a threshold, you rerun one calculation.
Build preservation into your incident response runbook now. Forensic images and threat actor communications are cheap to capture on day one and difficult to reconstruct later. This is the requirement least likely to change and the one most likely to be missed in the first weeks after a rule lands.
Ask your third parties the same question. Your vendor risk assessment should establish whether providers can preserve and produce the same categories of data, and how quickly. A 72-hour clock that depends on a vendor's response time is a clock you do not fully control.
Put December 11 on the calendar once and use it twice. The appropriations deadline and the CISA 2015 sunset share the date. If you rely on threat sharing liability protection through an ISAC or ISAO, that exposure is separate from CIRCIA and it is closer.
Watch the docket rather than the trade press. Docket CISA-2022-0010 on regulations.gov holds the proposal, the preliminary regulatory impact analysis, the draft privacy guidance, public comments, and the June 2026 town hall material. CISA communicates timeline updates through its CIRCIA page and the Unified Agenda entry under RIN 1670-AA04.
Do not rebuild your reporting workflow yet. Scope and the substantially similar exception are the two areas signalled for change. Workflow built against the proposed text may need rework. Scope analysis and preservation capability will not.
Source note
This article is based on CISA's CIRCIA page and its NPRM Informational Overview of May 2024; the CIRCIA proposed rule published April 4, 2024 at 89 FR 23644, docket CISA-2022-0010, RIN 1670-AA04, together with the comment period extension of May 6, 2024 and the correction of June 3, 2024; the CIRCIA statute at 6 U.S.C. 681 through 681g; the Federal Register index for RIN 1670-AA04, which showed no final rule as of October 2, 2026; the CIRCIA town hall notices published February 13, 2026 and May 26, 2026; and the Continuing Appropriations and Extensions Act, 2027, Public Law 119-103, approved September 2, 2026, at Division A section 106(3) and section 2011. Remarks by National Cyber Director Sean Cairncross and the fall 2026 expectation come from trade coverage of a USTelecom event dated September 29, 2026, and are reported statements rather than agency rulemaking documents. All substantive provisions described here come from a proposed rule that has not been finalized.
Disclaimer
This article is provided for general information and does not constitute legal advice. Regulatory requirements, compliance dates, examiner priorities, and enforcement posture change frequently. The CIRCIA rulemaking is active and unresolved, and the scope, thresholds, timelines, and exceptions described here reflect a proposed rule that has not been finalized. Verify current requirements against primary agency sources and your legal counsel before acting on anything described here.

