<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="https://www.jain.com/assets/img/6adafce5-1.1"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cyber Incident Reporting &#8211; Jain.com</title>
	<atom:link href="/tag/cyber-incident-reporting/feed/" rel="self" type="application/rss+xml" />
	<link></link>
	<description>Data centers, connectivity, and security — news and analysis</description>
	<lastBuildDate>Thu, 24 Sep 2026 20:51:06 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>/wp-content/uploads/2026/08/jain-com-icon-512-150x150.png</url>
	<title>Cyber Incident Reporting &#8211; Jain.com</title>
	<link></link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>CISA&#8217;s Coming 72-Hour Rule Makes AI Data Center Incident Response a Contract Term</title>
		<link>/cisa-circia-final-rule-september-2026-72-hour-cyber-incident-reporting/</link>
		
		<dc:creator><![CDATA[Deepak Jain]]></dc:creator>
		<pubDate>Sat, 18 Jul 2026 16:00:00 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[CIRCIA]]></category>
		<category><![CDATA[CISA]]></category>
		<category><![CDATA[colocation]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[critical infrastructure]]></category>
		<category><![CDATA[Cyber Incident Reporting]]></category>
		<category><![CDATA[data center security]]></category>
		<category><![CDATA[ransomware]]></category>
		<guid isPermaLink="false">/cisa-circia-final-rule-september-2026-72-hour-cyber-incident-reporting/</guid>

					<description><![CDATA[CISA expects to finalize the CIRCIA cyber incident reporting rule in September 2026, requiring 72-hour incident reports and 24-hour ransom payment reports. For data centers hosting AI and other critical workloads, the harder work is contractual: customers' clocks depend on how fast providers tell them.]]></description>
										<content:encoded><![CDATA[<div class="jain-post-grid">
<div class="jain-post-main">
<section class="jain-tldr" aria-label="Plain-English summary">
<p class="jain-tldr-kicker">TL;DR · 30-second read</p>
<h2>The Short Version</h2>
<p>The US government&#8217;s cybersecurity agency plans to finish new rules in September 2026. They will require essential services, likely including hospitals, banks and power companies, to report serious hacks within three days and any ransom paid to hackers within one day.</p>
<p>The catch: many of these organizations run their computers inside buildings owned by someone else, including the huge data centers being built for artificial intelligence. A customer can only meet a three-day deadline if the building&#8217;s operator tells it about a break-in fast. Expect the contracts between them to get much stricter.</p>
</section>
<p>The Cybersecurity and Infrastructure Security Agency (CISA) expects to issue its final rule under the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) in September 2026, Hunton Andrews Kurth reported on July 17. The rule will require covered critical-infrastructure entities to report covered cyber incidents to CISA within 72 hours and ransom payments within 24 hours.</p>
<p>The date comes from a preview of the 2026 Unified Agenda, the federal government&#8217;s schedule of planned regulatory actions. CISA missed the statutory October 2025 deadline, then set an internal target of May 2026. Town halls originally planned for March and April were postponed by a lapse in Department of Homeland Security funding and held June 15 through 18, drawing more than 1,200 stakeholders over four days.</p>
<h2>Executive Summary</h2>
<p>CIRCIA is the first cross-sector federal mandate requiring critical-infrastructure operators to report cyberattacks to a single agency. After a proposed rule in April 2024 and more than a year of slippage, a final rule is now expected in September 2026, with the two headline obligations unchanged: 72 hours to report a covered cyber incident and 24 hours to report a ransom payment.</p>
<p>For the data center and cloud industry, the most immediate consequence may come less from whether operators are themselves covered and more from their customers&#8217; obligations. Hospitals, banks, utilities and other covered entities increasingly run critical systems in third-party facilities and clouds, and the statute explicitly contemplates incidents that begin with a compromised hosting provider. A customer&#8217;s 72-hour clock therefore depends on how quickly and completely its provider tells it what happened, which turns incident notification into a negotiated contract term.</p>
<p>The practical window is short. Organizations that may be in scope should assess coverage against the proposed criteria, align incident response plans with the reporting deadlines, and review provider and customer agreements before the final text lands.</p>
<h2>A Tenant&#8217;s 72-Hour Clock Runs Through Its Data Center</h2>
<p>Under CIRCIA, the reporting duty sits with the covered entity: the hospital system, bank, utility or other organization that meets the final rule&#8217;s criteria. The 72-hour window runs from the point that entity reasonably believes a covered incident has occurred. Much of that entity&#8217;s computing, however, no longer sits in buildings it owns. It runs in colocation facilities, where a tenant rents space, power and cooling inside someone else&#8217;s building, and in public and GPU clouds, where it rents the computers themselves. The 2022 statute anticipates this: among the incidents the rule is meant to capture, it lists unauthorized access facilitated through the compromise of a cloud service provider, managed service provider or other third-party data hosting provider.</p>
<p>That places the provider&#8217;s detection and notification speed directly on the customer&#8217;s compliance path. A covered tenant cannot report what it has not been told, and it needs enough detail from its provider (what was accessed, when and how) to file a report that meets CISA&#8217;s content requirements. Breach-notification clauses are not new, but a binding federal deadline gives customers a concrete number to negotiate against: notification windows well inside 72 hours, named incident contacts, and obligations to share forensic detail. If a provider is itself swept in by the final size- or sector-based criteria, it will be running its own clock in parallel with its customers&#8217;.</p>
<p>The AI buildout sharpens the problem. New AI capacity is often delivered in layers: a facility owner, a GPU cloud or managed-infrastructure provider operating inside that facility, and the enterprise or model developer consuming the compute. Each layer is a hand-off in the notification chain, and each hand-off consumes hours of the covered entity&#8217;s window. Operators whose customer lists include regulated industries should expect incident-notification terms to be negotiated with the same seriousness as power and uptime commitments.</p>
<h2>Three Targets, One Missed Deadline, No Final Text Yet</h2>
<p>The timeline explains why caution is warranted. The statute required a final rule by October 2025. CISA missed that date and set an internal target of May 2026, citing the volume of comments on the April 2024 proposal and an intent to streamline requirements. Town halls meant to inform the final text were then pushed from March and April into mid-June by a Homeland Security funding lapse. September 2026 is the third target date.</p>
<p>CISA has signalled that it wants to streamline the rule but has not said how. Streamlining could mean narrower coverage, fewer required data fields, clearer thresholds for what counts as a reportable incident, or some combination. Until the text is published, the April 2024 proposal remains the best available guide, which is why the practical advice is to assess coverage against its proposed sector-based and size-based criteria rather than wait. The turnout of more than 1,200 stakeholders at the June sessions suggests how many organizations believe they may be affected.</p>
<p>Unified Agenda dates are projections, not commitments, and this rule has slipped before. Publication of a final rule is also not the same as the start of reporting obligations; the effective date and any transition period will matter as much as the publication date. Operators should treat September as a planning anchor, not a certainty.</p>
<h2>The 24-Hour Ransom Report Tests Governance, Not Just Tooling</h2>
<p>The 24-hour window for reporting a ransom payment is the tighter of the two deadlines. Ransom decisions typically involve executives, legal counsel and cyber insurers, not the security team alone. A one-day reporting clock after payment means the documentation behind that decision (who approved it, how much was paid, to whom, and why) has to be assembled as the decision is made, not reconstructed afterward. Organizations without pre-assigned authority and a documented escalation path will find the deadline hard to meet.</p>
<p>CIRCIA also lands on top of existing obligations. Public companies already face the SEC&#8217;s requirement to disclose material cybersecurity incidents within four business days of determining materiality, and several sector regulators have their own notification rules. The statute provides an exception where an entity reports substantially similar information to another federal agency under an agreement with CISA, but how widely that exception applies will depend on agreements not yet described. A data center operator serving customers across several sectors may find that its customers each face a different combination of deadlines, and that each will expect its provider&#8217;s notification terms to fit.</p>
<p>The intended payoff is real. CISA&#8217;s stated purpose is to deploy help to victims quickly, analyze reports across sectors for patterns, and share warnings with other defenders. For infrastructure operators, better cross-sector visibility into attack trends is a genuine benefit; the cost is process discipline that has to be in place before the first incident, not after.</p>
<h2>Background</h2>
<p>The Cybersecurity and Infrastructure Security Agency is the component of the Department of Homeland Security responsible for coordinating the protection of US critical infrastructure against cyber and physical threats. Before CIRCIA, cyber incident reporting to the federal government was largely voluntary or governed by a patchwork of sector-specific rules. CIRCIA, signed in March 2022, directed CISA to create a single cross-sector reporting regime, and CISA published its proposed rule in April 2024, setting out proposed coverage criteria, the scope of reportable incidents, and required report contents.</p>
<p>Data centers and cloud platforms sit underneath much of that critical infrastructure, hosting systems for healthcare, finance, energy and government customers. As AI demand drives new capacity, more of those workloads run in shared facilities and layered provider arrangements, which is why the reporting rules matter to operators whether or not they end up directly covered.</p>
<section class="jain-sources" aria-label="Sources">
<h2>Sources</h2>
<p>Source: <a href="https://news.google.com/rss/articles/CBMi0AFBVV95cUxPbmNSd0hRWVB5RFJYeU5iTTZrMldTWFUwTW5mSDJYeGxFclNRS2xDTEl1T19JakV6UFBoYmtHcE95ZllrVHZzdkh1TlM0TnliWWdQaDdzNDFKSVFldzlTMFNkTWVrZEZLSjNQWVhfa2RJNlRlSnYtZGp4dEdaQjRnNy1idzFWMUlmTmY3UXRrWXBKSmFBNXU5cmp3bTZlQ2o3dnlKbm5qazdNbFJmQ29pd2E1ZHVRQ0R4TUoyVUVhUWZ4Q1NmSWstMzhYWkJ1YTZm?oc=5">CISA Plans to Finalize Cyber Incident Reporting Regulations in September 2026</a> (Hunton Andrews Kurth), on CISA&#8217;s expected timeline for the CIRCIA final rule and its 72-hour and 24-hour reporting requirements.</p>
</section>
</div>
<aside class="jain-rail">
<section class="jain-gaps" aria-label="What the release does not say">
<p class="jain-gaps-kicker">⚠ What They Aren’t Saying</p>
<h2>What the Release Doesn&#8217;t Say</h2>
<ul>
<li><strong>Scope:</strong> CISA has not said how its promised streamlining will change the proposed sector-based and size-based coverage criteria, or how colocation, cloud and GPU-cloud operators will be treated in the final rule.</li>
<li><strong>Timing:</strong> CISA has not published an effective date or transition period, so it remains unclear how much time covered entities will have between the final rule&#8217;s publication and the start of binding reporting obligations.</li>
<li><strong>Overlap:</strong> CISA has not described which existing federal reporting regimes, if any, will qualify for the substantially-similar-reporting exception, leaving multi-sector operators unsure how many parallel filings a single incident may require.</li>
<li><strong>Provider commitments:</strong> Colocation, cloud and managed-infrastructure providers have yet to say publicly how their customer-notification terms will align with a 72-hour reporting clock, and what forensic detail they will commit to share with covered tenants.</li>
</ul>
</section>
<section class="jain-faq">
<h2>Frequently Asked Questions</h2>
<h3>What is CIRCIA?</h3>
<p>The Cyber Incident Reporting for Critical Infrastructure Act of 2022 is a US law signed in March 2022. It directs CISA to write regulations requiring covered critical-infrastructure entities to report significant cyber incidents and ransom payments to the agency.</p>
<h3>When will the CIRCIA final rule be published?</h3>
<p>A preview of the 2026 Unified Agenda indicated that a final rule can be expected in September 2026. That is a projection, and the rule has already slipped past an October 2025 statutory deadline and a May 2026 internal target.</p>
<h3>What are the CIRCIA reporting deadlines?</h3>
<p>Covered entities will have to report covered cyber incidents to CISA within 72 hours and report ransom payments within 24 hours. The final rule will set out exactly what counts as a covered incident and what each report must contain.</p>
<h3>When does the 72-hour clock start?</h3>
<p>Under the statute, the 72 hours run from when a covered entity reasonably believes a covered cyber incident has occurred, not from when the attack began. That makes fast detection, and fast notice from any hosting provider involved, central to compliance.</p>
<h3>Are data centers covered by CIRCIA?</h3>
<p>That depends on the final rule&#8217;s sector-based and size-based criteria, which CISA has said it intends to streamline. Even if an operator is not directly covered, its customers may be, and they will need timely incident notice from their provider.</p>
<h3>Why does a hosting provider matter to a customer&#x27;s CIRCIA obligations?</h3>
<p>The statute lists incidents facilitated through the compromise of a cloud service provider, managed service provider or other third-party data hosting provider among those the rule should capture. A covered customer cannot report such an incident until its provider tells it.</p>
<h3>Why did CISA miss its October 2025 deadline?</h3>
<p>CISA missed the statutory deadline and later set a May 2026 target, citing the large volume of comments on its April 2024 proposal and an intent to streamline the requirements. A lapse in Homeland Security funding then delayed planned town halls.</p>
<h3>What happened at the CIRCIA town halls?</h3>
<p>CISA announced sector-specific and general town halls in February 2026. Originally set for March and April, they were postponed by a funding lapse and held June 15 through 18, 2026, with more than 1,200 stakeholders taking part over four days.</p>
<h3>Why does CISA want these reports?</h3>
<p>CISA says reporting lets it rapidly deploy assistance to attack victims, analyze reports across sectors to spot trends, and share that information with network defenders so others can protect themselves against similar attacks.</p>
<h3>Can a third party submit a CIRCIA report on an entity&#x27;s behalf?</h3>
<p>The statute allows a covered entity to use a third party, such as an incident response firm or law firm, to submit a report. The obligation to report still belongs to the covered entity, so it needs to confirm that the filing is made on time.</p>
<h3>How does CIRCIA differ from the SEC&#x27;s cyber disclosure rule?</h3>
<p>The SEC rule requires public companies to disclose material cybersecurity incidents to investors within four business days of determining materiality. CIRCIA requires reports to CISA on a 72-hour clock, whether or not the company is publicly traded.</p>
<h3>What should data center and cloud operators do now?</h3>
<p>Assess likely coverage under the proposed criteria, align incident response and reporting plans with the 72-hour and 24-hour deadlines, review customer-notification terms in contracts, and monitor CISA&#8217;s CIRCIA webpage for the final text.</p>
<h3>What should enterprise tenants ask their colocation or cloud provider?</h3>
<p>Ask how quickly the provider will notify you of an incident affecting your systems, who the named contacts are on both sides, and what forensic detail the provider will share so you can file a complete report within your own deadline.</p>
<h3>Will the September 2026 date hold?</h3>
<p>No one can say for certain. Unified Agenda dates are projections, and this rule has missed two earlier dates. Organizations that may be covered are better served preparing now than waiting for publication.</p>
</section>
</aside>
</div>
<p><script type="application/ld+json">{"@context": "https://schema.org", "@graph": [{"@type": "NewsArticle", "headline": "CISA's Coming 72-Hour Rule Makes AI Data Center Incident Response a Contract Term", "description": "CISA expects to finalize the CIRCIA cyber incident reporting rule in September 2026, requiring 72-hour incident reports and 24-hour ransom payment reports. For data centers hosting AI and other critical workloads, the harder work is contractual: customers' clocks depend on how fast providers tell them.", "image": ["/wp-content/uploads/2026/09/cisa-circia-72-hour-incident-reporting-data-centers.webp"], "author": {"@type": "Organization", "name": "jain.com Editorial"}, "datePublished": "2026-09-24T20:50:59.195669+00:00"}, {"@type": "FAQPage", "mainEntity": [{"@type": "Question", "name": "What is CIRCIA?", "acceptedAnswer": {"@type": "Answer", "text": "The Cyber Incident Reporting for Critical Infrastructure Act of 2022 is a US law signed in March 2022. It directs CISA to write regulations requiring covered critical-infrastructure entities to report significant cyber incidents and ransom payments to the agency."}}, {"@type": "Question", "name": "When will the CIRCIA final rule be published?", "acceptedAnswer": {"@type": "Answer", "text": "A preview of the 2026 Unified Agenda indicated that a final rule can be expected in September 2026. That is a projection, and the rule has already slipped past an October 2025 statutory deadline and a May 2026 internal target."}}, {"@type": "Question", "name": "What are the CIRCIA reporting deadlines?", "acceptedAnswer": {"@type": "Answer", "text": "Covered entities will have to report covered cyber incidents to CISA within 72 hours and report ransom payments within 24 hours. The final rule will set out exactly what counts as a covered incident and what each report must contain."}}, {"@type": "Question", "name": "When does the 72-hour clock start?", "acceptedAnswer": {"@type": "Answer", "text": "Under the statute, the 72 hours run from when a covered entity reasonably believes a covered cyber incident has occurred, not from when the attack began. That makes fast detection, and fast notice from any hosting provider involved, central to compliance."}}, {"@type": "Question", "name": "Are data centers covered by CIRCIA?", "acceptedAnswer": {"@type": "Answer", "text": "That depends on the final rule's sector-based and size-based criteria, which CISA has said it intends to streamline. Even if an operator is not directly covered, its customers may be, and they will need timely incident notice from their provider."}}, {"@type": "Question", "name": "Why does a hosting provider matter to a customer's CIRCIA obligations?", "acceptedAnswer": {"@type": "Answer", "text": "The statute lists incidents facilitated through the compromise of a cloud service provider, managed service provider or other third-party data hosting provider among those the rule should capture. A covered customer cannot report such an incident until its provider tells it."}}, {"@type": "Question", "name": "Why did CISA miss its October 2025 deadline?", "acceptedAnswer": {"@type": "Answer", "text": "CISA missed the statutory deadline and later set a May 2026 target, citing the large volume of comments on its April 2024 proposal and an intent to streamline the requirements. A lapse in Homeland Security funding then delayed planned town halls."}}, {"@type": "Question", "name": "What happened at the CIRCIA town halls?", "acceptedAnswer": {"@type": "Answer", "text": "CISA announced sector-specific and general town halls in February 2026. Originally set for March and April, they were postponed by a funding lapse and held June 15 through 18, 2026, with more than 1,200 stakeholders taking part over four days."}}, {"@type": "Question", "name": "Why does CISA want these reports?", "acceptedAnswer": {"@type": "Answer", "text": "CISA says reporting lets it rapidly deploy assistance to attack victims, analyze reports across sectors to spot trends, and share that information with network defenders so others can protect themselves against similar attacks."}}, {"@type": "Question", "name": "Can a third party submit a CIRCIA report on an entity's behalf?", "acceptedAnswer": {"@type": "Answer", "text": "The statute allows a covered entity to use a third party, such as an incident response firm or law firm, to submit a report. The obligation to report still belongs to the covered entity, so it needs to confirm that the filing is made on time."}}, {"@type": "Question", "name": "How does CIRCIA differ from the SEC's cyber disclosure rule?", "acceptedAnswer": {"@type": "Answer", "text": "The SEC rule requires public companies to disclose material cybersecurity incidents to investors within four business days of determining materiality. CIRCIA requires reports to CISA on a 72-hour clock, whether or not the company is publicly traded."}}, {"@type": "Question", "name": "What should data center and cloud operators do now?", "acceptedAnswer": {"@type": "Answer", "text": "Assess likely coverage under the proposed criteria, align incident response and reporting plans with the 72-hour and 24-hour deadlines, review customer-notification terms in contracts, and monitor CISA's CIRCIA webpage for the final text."}}, {"@type": "Question", "name": "What should enterprise tenants ask their colocation or cloud provider?", "acceptedAnswer": {"@type": "Answer", "text": "Ask how quickly the provider will notify you of an incident affecting your systems, who the named contacts are on both sides, and what forensic detail the provider will share so you can file a complete report within your own deadline."}}, {"@type": "Question", "name": "Will the September 2026 date hold?", "acceptedAnswer": {"@type": "Answer", "text": "No one can say for certain. Unified Agenda dates are projections, and this rule has missed two earlier dates. Organizations that may be covered are better served preparing now than waiting for publication."}}]}]}</script></p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
