CIRCIA Final Rule: Requirements and Compliance Guide

The federal government has finalized one of the most significant cybersecurity regulations in decades. The CIRCIA Final Rule, implementing the Cyber Incident Reporting for Critical Infrastructure Act of 2022, establishes mandatory, legally enforceable deadlines for reporting cyber incidents and ransomware payments to the Cybersecurity and Infrastructure Security Agency (CISA). For businesses across New Jersey and the mid-Atlantic in healthcare, financial services, manufacturing, government services, and IT, the message is simple: the era of voluntary, on-your-own-timeline incident disclosure is over. 

There is a widespread misconception that CIRCIA is still being debated or that it only applies to Fortune 500 enterprises. Neither is true. The law was signed in March 2022, the proposed rule drew more than 260,000 public comments, and CISA finalized the rule in 2026. And the covered population is far broader than most business leaders expect: a community hospital serving 15,000 people, a regional manufacturer with 50 employees running critical production lines, and an IT provider supporting government systems can all fall in scope. An estimated 300,000+ entities across 16 critical infrastructure sectors are expected to be affected. 

Blueclone Networks helps businesses turn regulatory requirements into practical cybersecurity readiness. This guide breaks down what the CIRCIA Final Rule requires, who must comply, what CIRCIA compliance looks like in practice, and how organizations can prepare before the reporting clocks start running. 

 

What Is CIRCIA? 

The Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) was signed into law in March 2022 as part of the Consolidated Appropriations Act. Its purpose is to give the federal government real-time visibility into attacks on critical infrastructure so that CISA can warn other potential victims, identify active threat campaigns, and coordinate national responses. 

Unlike older breach notification laws, CIRCIA is built around speed. It requires covered entities to report substantial cyber incidents to CISA within 72 hours of reasonably believing an incident has occurred, and to report ransomware payments within 24 hours. Those timelines are not suggestions; they are legal obligations backed by penalties of up to $500,000 per day for non-compliance, according to analysis of the rule by CISA and legal commentators tracking the rulemaking. 

 

What Is the CIRCIA Final Rule? 

CIRCIA set the goals; the rulemaking process defines the details. CISA published the Notice of Proposed Rulemaking in April 2024, collected public comments through July 2024, and finalized the rule in 2026 after extensive stakeholder engagement, including sector-specific town halls attended by more than 1,200 participants. The Final Rule is expected to be codified at 6 CFR Part 226 and published in the Federal Register. 

The Final Rule answers the practical questions the statute left open: exactly who is covered, what makes an incident “substantial” enough to report, what information a report must contain, how long records must be preserved, and when the obligations take effect. Compliance dates phase in after publication, which means most covered entities have a preparation window but that window is shorter than it looks, because the monitoring, logging, and incident response capabilities the rule assumes cannot be built overnight. 

 

Who Must Comply With the CIRCIA Final Rule? 

The 16 Critical Infrastructure Sectors 

CIRCIA applies to entities operating in the 16 critical infrastructure sectors designated under Presidential Policy Directive 21: chemical, commercial facilities, communications, critical manufacturing, dams, defense industrial base, emergency services, energy, financial services, food and agriculture, government facilities, healthcare and public health, information technology, nuclear, transportation systems, and water and wastewater. If your New Jersey business operates in any of these sectors, assume you are in scope until proven otherwise. 

 

The Two-Track Coverage Test 

An entity is a “covered entity” if it meets either of two tests. Track one is size-based: you operate in a covered sector and exceed the Small Business Administration size standards for your industry; thresholds that generally range from roughly 100 to 1,500 employees or several million to tens of millions in revenue depending on the sector. Track two is sector-based: certain entities are covered regardless of size, including federal government IT contractors, software developers with privileged access to customer systems, communications service providers, and state and local government entities serving populations greater than 50,000. 

 

The Small Business Exception and Its Limits 

Entities that meet SBA small business size standards are generally exempt under the size-based track. But do not assume the exception applies to you. Most hospitals and health systems qualify as covered entities regardless of how small their community may be, and businesses that meet sector-based criteria are covered no matter their headcount. The only reliable approach is a documented coverage determination, something we build into every CIRCIA compliance assessment we run for clients. 

 

What About MSPs and IT Providers? 

Managed service providers and cloud providers are explicitly in scope in two ways. First, MSPs that exceed size thresholds in the IT sector, or that support federal government or elections infrastructure, are covered entities themselves. Second, MSPs are supply-chain vectors: if an MSP’s infrastructure is compromised and used to attack covered entity clients, both the MSP and the affected client may have reporting obligations. This dual exposure is one of the most important and least understood aspects of the rule, and it is why choosing an MSP with mature security operations is now a compliance decision, not just an IT decision. 

 

What the CIRCIA Final Rule Requires 

72-Hour Cyber Incident Reporting 

Covered entities must report covered cyber incidents to CISA within 72 hours of reasonably believing the incident occurred. The trigger is belief, not confirmation; meaning the clock may start before a forensic investigation is complete. Meeting that deadline requires real-time detection, rapid triage, and a documented process for deciding whether an incident is reportable. According to IBM’s Cost of a Data Breach Report, the average breach takes roughly 200 days to identify, a timeline that is completely incompatible with a 72-hour federal reporting obligation without continuous monitoring in place. 

 

24-Hour Ransomware Payment Reporting 

If a covered entity makes a ransomware payment, it must report the payment to CISA within 24 hours. This is the tightest deadline in the rule and applies even if the underlying incident is still being investigated. The report must capture what was demanded, what was paid, and what was known at the time of payment, which means the decision-making around any ransom event needs to be documented as it happens, not reconstructed afterward. 

 

Supply Chain and Third-Party Incident Reporting 

Reporting obligations extend to incidents that originate in supply chains; compromises of vendors, software providers, cloud platforms, and IT service providers that lead to unauthorized access to a covered entity’s systems. In practice, this means your vendors’ security posture is now your compliance problem, and your contracts, SLAs, and vendor risk program need to reflect that. 

 

Record Preservation 

Entities that report a covered incident must preserve the underlying incident records in their original form for at least two years. These are not summaries or after-action notes, they are logs, forensic artifacts, communications, and evidence categories that must be maintained intact. This requirement alone makes centralized, tamper-resistant log management a foundational element of CIRCIA compliance, and it is one most businesses cannot satisfy with the logging they have in place today. 

 

What Counts as a Reportable Incident? 

Not every security event is reportable. The rule targets incidents that meet a “substantial” threshold; generally, incidents that lead to: 

  • Substantial loss of confidentiality, integrity, or availability of information systems or data 
  • Serious impact on operational systems and processes 
  • Disruption of business operations or service delivery 
  • Unauthorized access to a covered entity’s systems through a supply chain compromise 

Common examples include ransomware that locks systems, business email compromise that results in unauthorized wire transfers, sustained denial-of-service attacks, data exfiltration, and successful phishing that leads to unauthorized system access. The judgment call is the hard part: someone in your organization, or a trusted partner, must be able to determine within hours whether an incident crosses the reportability line. That determination capability does not exist by accident; it is built with defined criteria, trained analysts, and documented procedures aligned to the NIST Cybersecurity Framework. 

 

What Happens If You Fail to Comply? 

The stakes are material. Non-compliance with CIRCIA reporting requirements can trigger civil penalties of up to $500,000 per day, and CISA holds subpoena authority to compel records and information from non-compliant entities. Separately, knowingly false or misleading statements in a CIRCIA report can expose individuals to federal false-statement liability. In an environment where Verizon’s Data Breach Investigations Report shows ransomware and credential attacks continuing to dominate, the risk of an incident is high, and the cost of mishandling the reporting obligation is now higher still. 

There is also a reputational dimension. CIRCIA reports flow into the federal government’s threat picture; entities that demonstrate mature, cooperative incident handling fare better in follow-up engagements than those that scramble, miss deadlines, or provide incomplete information. 

 

CIRCIA Compliance Does Not Replace Your Other Obligations 

A CIRCIA report does not satisfy your other notification duties. Healthcare organizations still owe HIPAA breach notifications, public companies still owe SEC disclosures, payment processors still operate under PCI DSS, and New Jersey businesses still must comply with the state’s data breach notification requirements. CIRCIA adds a federal track on top of these, with its own deadlines, definitions, and thresholds. If your compliance program treats breach response as a single checklist, it needs to become a coordinated multi-track process. Our guides on PCI DSS compliance and data security standards for NJ retailers and financial institutions cover the adjacent frameworks in detail. 

 

How to Prepare for CIRCIA Compliance: A Step-by-Step Approach 

Step 1: Determine Whether You Are a Covered Entity 

Map your operations against the 16 sectors, apply the two-track coverage test, and document the determination. If you rely on the small business exception, record why. This determination is the foundation of everything that follows, and it should be revisited annually as your business grows, ideally as part of your IT strategic planning cycle. 

 

Step 2: Assess Your Detection and Logging Capabilities 

Ask the hard question: if an incident started today, how quickly would you know? Assess your ability to collect and retain logs from endpoints, networks, cloud platforms, and identity systems; detect threats in real time; and investigate well enough to make a reportability determination within 72 hours. For most businesses, this assessment reveals significant gaps between what the rule assumes and what currently exists. 

 

Step 3: Close the Visibility Gap 

Deploy centralized logging and 24/7 monitoring across all critical systems: endpoints, servers, network infrastructure, cloud workloads, and identity providers. Do not phase this in over years; the rule’s timelines assume comprehensive visibility from day one. According to Gartner, organizations with continuous threat exposure management detect and contain incidents dramatically faster than those relying on periodic reviews. 

 

Step 4: Update Your Incident Response Plan 

Your incident response plan must now answer federal reporting questions explicitly: Who decides whether an incident is reportable? Who completes and submits the CISA report? Who communicates with leadership, legal counsel, and law enforcement? How are ransom payment decisions documented in real time? An IR plan that has never been tested against a 72-hour clock is a liability, not an asset. 

 

Step 5: Get Your Vendor and Supply Chain House in Order 

Review contracts with IT providers, software vendors, and cloud platforms. Ensure they include security commitments, breach notification timelines compatible with your CIRCIA obligations, and cooperation duties for incident response. Remember: your MSP’s compromise can become your reportable incident. 

 

Step 6: Train, Test, and Repeat 

Run tabletop exercises that simulate a CIRCIA-reportable event end to end: detection, triage, determination, reporting, and record preservation. Train leadership and staff on their roles. Then repeat quarterly. CompTIA research consistently shows that human readiness, not tooling alone, determines how fast organizations respond in the first hours of an incident. 

 

Navigating CIRCIA Compliance With Blueclone Networks 

Blueclone Networks delivers the monitoring, detection, and response capabilities covered entities need to prepare for the CIRCIA Final Rule. Here is what that looks like in practice: 

  • Coverage determination — we map your operations against the 16 sectors and the two-track test, and document your covered entity status. 
  • Security assessments — a full evaluation of your current detection, logging, and response capabilities against the rule’s requirements, aligned to the NIST Cybersecurity Framework. 
  • 24/7 monitoring and detection — real-time visibility across endpoints, networks, cloud workloads, and identity systems through our cybersecurity services. 
  • Centralized log management and retention — tamper-resistant collection and two-year-plus preservation of the incident records the rule requires. 
  • Incident response planning and testing — documented IR plans with explicit CIRCIA reporting roles, deadlines, and tabletop exercises that prove they work. 
  • Ransomware and breach readiness — preparation for the 24-hour ransom payment reporting scenario, including decision documentation frameworks. 
  • Vendor and supply chain risk management — contract review and third-party risk assessments so your vendors’ weaknesses do not become your reportable incidents. 
  • Coordinated multi-track compliance — alignment of CIRCIA obligations with PCI DSS, HIPAA, SEC, and New Jersey breach notification duties through our Managed IT Services model. 

You gain access to certified security professionals, compliance expertise, and senior technology leadership without taking on the cost of multiple specialized in-house hires. Contact Blueclone Networks to schedule a CIRCIA readiness assessment and find out exactly where you stand before the reporting clocks start. 

 

Frequently Asked Questions 

The CIRCIA Final Rule is the regulation implementing the Cyber Incident Reporting for Critical Infrastructure Act of 2022. Finalized by CISA, it requires covered entities in 16 critical infrastructure sectors to report substantial cyber incidents to CISA within 72 hours and ransomware payments within 24 hours, preserve related incident records for at least two years, and report incidents that originate in their supply chains. Non-compliance can carry civil penalties of up to $500,000 per day. 

It depends. Entities that meet the Small Business Administration’s small business size standards are generally exempt under the size-based coverage track. However, certain entities are covered regardless of size including federal government IT contractors, software developers with privileged access to customer systems, communications service providers, and state and local governments serving populations over 50,000. Most hospitals and health systems also qualify as covered entities. The only reliable approach is a documented coverage determination. 

The 72-hour deadline applies to covered cyber incidents: a covered entity must report to CISA within 72 hours of reasonably believing a substantial incident occurred. The 24-hour deadline applies specifically to ransomware payments: if a covered entity pays a ransom, it must report the payment within 24 hours, even if the underlying incident is still under investigation. Both clocks are legal obligations, and both assume the entity can detect and assess incidents in real time. 

No. A CIRCIA report to CISA does not satisfy HIPAA breach notification, SEC disclosure obligations, PCI DSS requirements, or New Jersey’s data breach notification law. Each framework has its own deadlines, definitions, and thresholds, so covered entities typically need a coordinated, multi-track reporting process. This is why incident response plans should be built around all applicable obligations at once, not one at a time. 

Start with a coverage determination to confirm whether you are a covered entity, then assess your current detection, logging, and incident response capabilities against the rule’s requirements. Most organizations need to close a visibility gap first, centralized logging and 24/7 monitoring across endpoints, networks, cloud, and identity systems, then update their incident response plan with explicit CIRCIA reporting roles and deadlines, review vendor contracts for supply chain exposure, and test the whole process through tabletop exercises. Working with a managed IT and security partner like Blueclone Networks can compress this timeline significantly.