If you already report cyber incidents under DFARS, brace for one more obligation that runs on its own timetable. The Cyber Incident Reporting for Critical Infrastructure Act of 2022 — CIRCIA — directs CISA to require covered entities to report significant cyber incidents and ransom payments on a fixed clock. After a proposed rule in April 2024 and a string of delays, CISA has not yet issued a final rule — as of July 2026 the rulemaking remains open. CIRCIA's statutory deadline (October 4, 2025) has already passed; CISA's current administrative target under the Unified Agenda is now September 2026, and CISA is still gathering stakeholder input to refine the proposed rule's scope and burden. The schedule keeps slipping amid DHS funding lapses, but the substance is taking shape — and it reaches far more contractors than most expect.
What CIRCIA Will Require
CIRCIA's two headline obligations have stayed stable across the rulemaking and are not expected to change:
- 72-hour incident reporting. A covered entity must report a covered cyber incident to CISA within 72 hours after it reasonably believes the incident occurred.
- 24-hour ransom-payment reporting. A covered entity must report a ransom payment within 24 hours of making it.
The rule also contemplates supplemental reports as new information emerges, and data-preservation duties tied to the reported incident. In other words, the report isn't a one-and-done filing — it opens an ongoing obligation.
Why This Lands on Government Contractors
CIRCIA is written around "covered entities" in the 16 critical-infrastructure sectors — defense industrial base, IT, healthcare, financial services, energy, water, transportation, and more. Here's the overlap problem: many companies that hold federal contracts also operate in one of the 16 critical-infrastructure sectors. A defense supplier, a health IT vendor, a cloud provider serving agencies — each may be a covered entity under CIRCIA depending on its sector and size, regardless of what its contract clauses say. Coverage turns on CISA's covered-entity criteria, not on contractor status alone.
That means CIRCIA stacks on top of obligations you already carry. A single incident could trigger:
- DFARS 252.204-7012 — report to DoD within 72 hours (for covered defense information).
- The proposed FAR CUI rule — report suspected or confirmed CUI incidents within 8 hours of discovery, if and when finalized.
- CIRCIA — report to CISA within 72 hours, plus 24 hours for any ransom payment.
- State breach-notification laws — their own independent deadlines based on whose data was affected.
These clocks do not satisfy one another. Meeting your DoD window does nothing for your CISA window. You need a single intake process that can fan out to every applicable deadline at once.
The Enforcement Edge
CIRCIA gives CISA real leverage: it can issue requests for information and subpoenas to entities believed to have experienced a reportable incident, and noncompliance can be referred to the Department of Homeland Security's suspension-and-debarment official. For a government contractor, suspension or debarment is an existential risk — which makes CIRCIA's reporting duties a contract-eligibility issue, not just a cybersecurity one.
What to Do Before the Final Rule Lands
The timeline is uncertain, but the obligations are foreseeable. Prepare now:
1. Determine whether you're a covered entity. Map your operations against the 16 critical-infrastructure sectors; if you serve any of them, assume you're in scope until the final rule says otherwise. 2. Build one incident-reporting playbook with multiple clocks. When an incident is detected, the playbook should immediately flag every deadline — DoD, CISA, FAR CUI, state — and assign an owner to each. 3. Set the shortest clock as your default. If an 8-hour FAR CUI obligation could apply, build your process to hit 8 hours; everything else follows automatically. 4. Tighten ransom-payment governance. A 24-hour clock means legal, executive, and security leadership need a pre-agreed decision process before, not during, an extortion event. 5. Preserve evidence by default. Reporting obligations come with preservation expectations; make forensic preservation automatic.
Key Takeaways
- CIRCIA's final rule is not yet issued (as of June 2026), but its 72-hour incident and 24-hour ransom clocks have stayed intact across the rulemaking.
- Many government contractors fall within one of the 16 critical-infrastructure sectors, so CIRCIA may add a third reporting clock alongside DFARS and the proposed FAR CUI rule — coverage depends on CISA's covered-entity criteria, not contractor status alone.
- Noncompliance can reach the suspension-and-debarment official — treat CIRCIA as a contract-eligibility risk and build one playbook that fires every deadline at once.
See how the federal reporting obligations fit together on our Federal Requirements: Statutes page, confirm what applies to you with Find My Requirements, and pair this with our guide to DFARS 252.204-7012.