If your business gets hacked next year, you may have exactly 72 hours to tell the federal government about it — whether you're ready or not.
That's the core of a new federal rule working its way through Washington: the Cyber Incident Reporting for Critical Infrastructure Act, or CIRCIA. It sounds like something that only applies to power plants and pipelines. It doesn't. CISA estimates the rule will eventually cover more than 300,000 organizations, and a meaningful share of them are small and mid-sized businesses that have never had to file an incident report with anyone in their lives.
The rule isn't final yet — its publication date has slipped more than once, and it's now expected sometime in the fall of 2026. But the two deadlines at the center of it, a 72-hour window to report a serious cyber incident and a 24-hour window to report a ransom payment, are written directly into the statute Congress passed. No amount of further delay in the rulemaking process can soften those clocks once the rule takes effect. If you run a business that could plausibly be swept in, this is the year to get ahead of it rather than find out the hard way.
What CIRCIA Actually Requires
Strip away the acronym soup and CIRCIA boils down to two obligations for a "covered entity":
- Report a substantial cyber incident to CISA within 72 hours of reasonably believing one has occurred.
- Report a ransomware payment within 24 hours of making it, even if the incident itself didn't rise to the "substantial" threshold.
These aren't internal notifications to a manager or a vague filing sometime "promptly." They're a hard clock that starts the moment you have reasonable belief an incident occurred — not the moment you've finished investigating it, confirmed the full scope, or lawyered up. That distinction matters enormously for a small business, because 72 hours is not a lot of runway to simultaneously contain a breach, figure out what happened, and produce a report accurate enough to submit to a federal agency.
Who Actually Counts as "Covered"
This is where CIRCIA reaches further than most small business owners assume. Coverage runs through two separate pathways, and you only need to fall into one of them.
Size-based coverage. If your business operates in one of the 16 federally designated critical infrastructure sectors and exceeds Small Business Administration size thresholds (generally somewhere in the range of 100 to 1,500 employees, or roughly $2.25 million to $47 million in annual revenue, depending on the specific industry code), you're likely covered regardless of how unglamorous your business feels.
Sector-based coverage. Certain entity types are covered outright, no size test required — hospitals, banks and credit unions, telecom carriers, utilities, and federal contractors among them.
The 16 sectors are broader than "critical infrastructure" sounds in casual conversation:
- Chemical
- Commercial Facilities
- Communications
- Critical Manufacturing
- Dams
- Defense Industrial Base
- Emergency Services
- Energy
- Financial Services
- Food and Agriculture
- Government Services and Facilities
- Healthcare and Public Health
- Information Technology
- Nuclear Reactors, Materials, and Waste
- Transportation Systems
- Water and Wastewater
A regional IT managed service provider, a mid-sized commercial bakery supplying grocery chains, a specialty finance company, a healthcare billing vendor, a logistics company hauling regulated freight — all of these can plausibly land inside one of these sectors well before they'd describe themselves as "critical infrastructure." If your business touches financial services, IT, healthcare, food supply chains, or government contracting and has grown past a skeleton crew, it's worth actually running the SBA size-standard math rather than assuming the rule is for someone else.
What Counts as a Reportable Incident
CIRCIA's trigger is a "substantial cyber incident," which covers more ground than a full-blown ransomware shutdown. It includes:
- A significant loss of confidentiality, integrity, or availability of an information system or data
- A serious impact on the safety and resiliency of operational systems
- A disruption of your ability to deliver goods or services
- Unauthorized access resulting from a supply chain compromise — including a breach at a vendor, a managed service provider, or a cloud platform you rely on
That last category is the one that catches people off guard. Under CIRCIA, an incident doesn't have to originate on your own network to trigger your reporting obligation. If your cloud provider or a software vendor you depend on gets compromised and it materially affects your systems or data, that can be your incident to report, not just theirs.
Why the Rule Keeps Slipping — and Why That Doesn't Help You
Congress originally set an October 2025 deadline for CISA to publish the final CIRCIA rule. CISA missed it, pushed the target to May 2026, missed that too, and is now aiming for sometime in the fall of 2026, citing repeated funding lapses that stalled rulemaking work. CISA has also been running a series of town hall sessions through the summer to collect feedback from critical infrastructure stakeholders before the rule locks in.
It's tempting to read a slipping deadline as a reason to deprioritize this. That would be a mistake. The delays are happening in the rulemaking process — the part that finalizes exact submission formats, precise thresholds, and procedural detail. The 72-hour and 24-hour clocks themselves are statutory, set by Congress in the underlying law, not by CISA's regulations. When the final rule does take effect, those clocks start immediately; there's no phase-in period where the deadlines are 72 hours in theory but something looser in practice. A slipping publication date just means you have more runway to prepare, not less obligation once it lands.
The Ransom Payment Clock Is Separate — and Shorter
It's worth calling out the ransomware payment reporting requirement on its own, because it's easy to read past it while focused on the 72-hour incident deadline. If your business pays a ransom, you have to report that payment within 24 hours — a full 48 hours tighter than the incident-reporting clock, and it applies even if the underlying incident didn't meet the "substantial" bar on its own. Many small businesses that get hit with ransomware are still negotiating with insurers, weighing whether to pay at all, or working with outside counsel when the payment actually goes out. Whoever in your organization would authorize a ransom payment needs to know, in advance, that the reporting clock on that decision is even less forgiving than the one on the incident itself.
Penalties Aren't the Only Thing at Stake
CISA's enforcement path escalates from an information request to a subpoena for entities that don't comply, and failing to respond to a subpoena can trigger a Department of Justice referral. Beyond the direct penalties, federal contractors face debarment risk for noncompliance — a much bigger threat to many small businesses than a fine, since it can end a government revenue stream outright.
But the bigger financial exposure for most small businesses isn't the regulatory penalty. It's the incident itself. Recent industry data puts average incident response and recovery costs for a small business attack in the tens of thousands of dollars just for investigation and recovery, with total resolution costs for a serious breach often running into six figures. Ransom demands aimed at SMBs now average in the tens of thousands of dollars on their own, before recovery costs are added. And a widely cited estimate holds that a majority of small businesses that suffer a significant attack don't survive it for more than six months afterward. The reporting deadline is a compliance problem. The breach itself is a survival problem — and the two show up on your desk at the same time.
How to Get Ready Before the Rule Is Final
The rule isn't in effect yet, but the businesses that will handle it smoothly are the ones treating the delay as a planning window, not a reason to wait.
1. Figure out if you're actually in scope. Don't guess based on vibes. Check whether your business falls into one of the 16 sectors, then run the actual SBA size-standard test for your specific NAICS code. A lot of businesses that don't feel like "critical infrastructure" are.
2. Write an incident response plan now, while there's no clock running. A tested incident response plan is consistently one of the single biggest cost reducers when a breach happens, because the decisions that eat the most time under pressure — who to call, what to preserve, who has authority to make the call — are already made in advance instead of debated live during hour one of a crisis.
3. Know what "reasonable belief" will mean for your business. You don't get to wait for a full forensic conclusion before the clock starts. Decide in advance who inside your organization is authorized to make the call that a reportable incident has occurred, so that judgment isn't made for the first time in the middle of an actual event.
4. Map your vendor and cloud dependencies. Because a compromise at a vendor or cloud provider can be your reportable incident, know which of your critical systems live on someone else's infrastructure, and confirm those vendors have their own breach notification commitments to you that are fast enough to feed your 72-hour clock.
5. Keep records clean enough to move fast under pressure. When an incident happens, investigators and insurers will want a clear picture of what systems touch what data, what a normal transaction looks like, and what changed. A business whose financial and operational records are already well organized can answer those questions in hours. A business untangling messy, informal bookkeeping at the same time it's fighting a breach loses precious hours of its 72-hour window just reconstructing what "normal" looked like.
That last point is worth sitting with, because it's easy to think of a compliance deadline like this as purely a legal or IT problem. In practice, a breach investigation pulls on the same records your accountant does: who has access to what, when transactions happened, what your normal operating pattern looks like so investigators can spot what's abnormal. Businesses that already keep transparent, well-organized financial records aren't just easier to audit — they're faster to investigate when something goes wrong, which matters enormously when the clock is measured in hours, not weeks.
Keep Your Financial Records Ready for Whatever Comes Next
A cyber incident investigation moves fast, and the businesses that handle it well are usually the ones whose records were already in order before anything happened. Beancount.io offers plain-text accounting that gives you a transparent, version-controlled, auditable history of your finances — no black box, no vendor lock-in, and nothing to untangle under pressure. Get started for free and keep your books as ready for scrutiny as the rest of your business needs to be.