ARTICLE
8 October 2026

PERSPECTIVE: What CIRCIA Means For The Nation's Critical Infrastructure

S
Steptoe LLP

Contributor

In more than 100 years of practice, Steptoe has earned an international reputation for vigorous representation of clients before governmental agencies, successful advocacy in litigation and arbitration, and creative and practical advice in structuring business transactions. Steptoe has more than 500 lawyers and professional staff across the US, Europe and Asia.
Critical infrastructure organizations face new cyber incident reporting requirements under CIRCIA, requiring careful preparation and strategic planning. Understanding how to establish clear reporting protocols, coordinate communications, and manage vendor dependencies will be essential for compliance. Organizations must proactively engage cyber and legal expertise to navigate these regulatory obligations effectively.
United States Technology

Picture a water utility in the Midwest. It’s a Tuesday afternoon, and an operator notices something odd — a control system that shouldn’t be talking to the outside world is doing exactly that. Nobody knows yet whether this is a misconfigured device, a curious researcher, or the opening move of an attack on the water supply for half a million people. What happens in the next 72 hours will matter not just to that utility, but to the federal government’s ability to see the threat coming for the next one.

That scenario is exactly what Congress had in mind when it passed the Cyber Incident Reporting for Critical Infrastructure Act of 2022, better known as CIRCIA. And after years of delay, the rule that will finally put CIRCIA into force is close. The Cybersecurity and Infrastructure Security Agency (CISA) is now targeting September 2026 to issue the final rule, with covered entities potentially facing real reporting obligations as soon as late 2026 or early 2027. CISA has estimated that roughly 316,000 organizations across all 16 critical infrastructure sectors — energy, water, healthcare, transportation, financial services, communications, and more — could fall within scope, though the final number may shift once the rule is issued.

For anyone working in homeland security, emergency management, or critical infrastructure protection, that number should get your attention. CIRCIA isn’t just another compliance box to check. It’s meant to give the federal government something it has never really had before: a real-time, sector-wide window into the cyberattacks hitting the systems that keep the country running — the power grid, the water supply, the pipelines, the hospitals. When one utility gets hit, CISA wants to be able to warn the next one before it happens too.

But that only works if the reporting actually happens fast, and happens right. And that’s where things get harder than they sound.

A Deceptively Simple Rule

On paper, CIRCIA’s core requirement is short enough to fit on an index card. A covered entity that experiences a “covered cyber incident” must tell CISA within 72 hours of forming a reasonable belief that the incident occurred. If it pays a ransom, it has 24 hours to report that separately. Two numbers, two deadlines.

The trouble is everything sitting underneath those two numbers. Is this particular organization even a “covered entity” under the statute? Does this particular event — a phishing email, a ransomware note, a strange spike in outbound traffic — actually rise to the level of a “covered cyber incident,” or is it just an ordinary bad day for the IT team? And once someone decides it does meet that bar, who inside the organization actually has the authority to make that call?

These are not abstract questions. In the middle of a real incident — alarms going off, systems locking up, phones ringing — these are exactly the questions that eat up the hours an organization doesn’t have to spare. An organization that hasn’t already worked out the answers is essentially trying to write the rulebook and play the game at the same time.

The final rule, once it lands, should help resolve some of this ambiguity. But waiting for it is a bad strategy. The smart move — and the one CISA itself has all but told organizations to make — is to start building the muscle now, before the clock is actually running.

Readiness Can’t Wait for the Final Rule

Here’s a detail that trips a lot of people up: the 72-hour clock doesn’t wait for a forensic investigation to run its course. It starts once an organization has a reasonable, fact-based belief that something reportable occurred — a lower bar than a confirmed conclusion, though still one that requires enough investigation to have an actual factual basis for that belief.

Think about how a real incident actually unfolds. It rarely announces itself. It shows up as a handful of odd signals — an authentication attempt from an unfamiliar location, a security tool that’s mysteriously been switched off, a vendor emailing to say something looks strange on their end. In the early hours, an organization often doesn’t yet know whether it’s looking at a minor glitch or the beginning of a major event, and it takes some investigation just to tell the difference. CIRCIA doesn’t require that investigation to be complete before the clock starts — but it does require organizations to move quickly to reach a reasonable, factually grounded view, and to report once they have one, rather than waiting for full certainty.

That has real implications for how organizations prepare. An incident response plan that was built for other purposes — meeting a different federal reporting requirement or satisfying a state breach-notification law — probably wasn’t designed with a 72-hour trigger tied to “reasonable belief” in mind. Organizations should be reviewing those plans now, not after an incident hits, and building in the decision points CIRCIA actually requires: who evaluates a potential incident, how quickly, and based on what information.

And this is where tabletop exercises earn their keep. Running a simulated incident — start to finish, with the actual people who would be making these calls in real life — is one of the few ways to find the gaps before they cost you. Maybe it turns out nobody’s quite sure who has the authority to declare a reportable incident at 2 a.m. on a Saturday. Better to discover that in a conference room during a drill than in the middle of an actual crisis.

The Story Has to Stay Straight

One thing that’s easy to overlook until it becomes a problem: during a serious incident, an organization often isn’t just talking to one audience. It might be reporting to CISA, briefing law enforcement, notifying customers, updating a cyber insurer, and — if it’s publicly traded — potentially disclosing something to investors under separate SEC rules. Each of those conversations happens on its own timeline and serves its own purpose.

The risk is that these communications drift apart. An early, rough-draft account of what happened, sent to CISA under time pressure, can end up looking inconsistent with a later, more polished public statement — not because anyone was misleading, but because the understanding of the incident kept evolving. Regulators, journalists, and litigants tend not to be especially forgiving of that kind of inconsistency, even when it’s entirely explainable.

The fix isn’t complicated in concept, even if it takes discipline in practice: designate one place — one “source of truth” — where the facts of an incident live as they’re confirmed, updated, and refined. Everyone drawing from that source, whether they’re drafting a CISA report or a customer notice, is working from the same set of facts. It also helps to remember that CIRCIA and other reporting regimes — like the SEC’s cybersecurity disclosure rule — are asking genuinely different questions. A CIRCIA report is about whether a covered cyber incident occurred. An SEC materiality disclosure is about whether investors need to know. Treating those as separate analyses, run on parallel tracks, prevents an organization from accidentally answering the wrong question in the wrong forum.

Vendors Are Part of the Problem — and the Plan

Almost no organization runs its own infrastructure entirely in-house anymore. Cloud providers, managed security firms, and outside detection-and-response vendors often hold the very logs and telemetry an organization needs to figure out whether something reportable happened. But CIRCIA doesn’t let the reporting obligation travel with the data — it stays with the covered entity, full stop.

That creates an obvious failure point. If a managed security provider spots something unusual but takes several days to hand over the relevant logs, the clock doesn’t pause and wait politely. The organization is still on the hook for a 72-hour deadline it may not even know has started. Contracts with these vendors are worth a second look — not to eliminate every risk, since that’s not realistic, but to make clear how fast information has to move, and who’s responsible for what, when something looks wrong.

Where Outside Expertise Earns Its Keep

One practical lesson that’s emerged clearly, even before the final rule takes effect, is that organizations shouldn’t try to run a CIRCIA response entirely with in-house resources — and shouldn’t try to run it with legal alone, either. The best-prepared organizations tend to bring in outside cybersecurity counsel and outside forensic experts early, before an incident, not scrambling for a phone number after one has already started.

There’s a practical reason for this beyond simply having more hands on deck. Outside experts — cyber counsel and forensic investigators alike — bring pattern recognition that’s hard to build in-house, because they see incidents across many organizations and sectors, not just one. They’ve usually already worked through the hard calls: when does an event cross the reporting threshold, how do you word an initial report when the facts are still moving, how do you coordinate with law enforcement without stepping on an active investigation. That experience is difficult to replicate internally, especially for an organization managing its first real incident under a brand-new federal reporting regime.

It also helps to define roles before a crisis, not during one. Who decides when to bring in outside counsel? Who retains the forensic firm, and are they working for legal, for IT, or both? How will the technical response — containing the threat, restoring systems — stay coordinated with the reporting and communications side, without either one slowing the other down? Sorting that out in advance means that when an actual incident hits, the organization is executing a plan instead of improvising one.

None of this should turn into a bottleneck. Routing every single alert and internal email through outside counsel isn’t realistic and isn’t the goal — it would just slow down the technical response and bury the organization in unnecessary process. The goal is knowing, ahead of time, when outside expertise needs to be in the room and when the technical team should simply be left to do its job.

The Bigger Picture

It’s easy to get lost in the mechanics — the 72 hours, the 24 hours, the definitions, the overlapping regulators — and lose sight of what CIRCIA is actually trying to accomplish. The country’s water systems, power grids, hospitals, and pipelines are targets, and they’re targets precisely because an attack on them doesn’t just hurt one company’s bottom line — it can hurt a community. CIRCIA is an attempt to give the federal government the visibility it needs to see attacks as they’re happening across the country, warn the next potential victim, and respond faster.

That mission only works if the reporting behind it is fast, accurate, and consistent — which means it only works if the organizations on the front lines have actually done the preparation. The final rule may still be months away, and CISA has missed its own deadlines before. But critical infrastructure operators that wait for the rule to force their hand will be building a plane while flying it. The organizations that start now — designating response teams, updating their plans, running the drills, lining up the right outside help — will be the ones ready to answer the call when it matters most.

Originally published by Homeland Security Today, 22 September 2026.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

[View Source]
See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More