CIRCIA and State Government: Why Mandatory Incident Reporting Is an Organizational Problem Before It's a Technical One
Back to Signal
State & LocalCybersecurityComplianceGovernment

CIRCIA and State Government: Why Mandatory Incident Reporting Is an Organizational Problem Before It's a Technical One

October 7, 2026Jess Loban

What CIRCIA Requires

Congress enacted CIRCIA on March 15, 2022 (Pub. L. 117-103, codified at 6 U.S.C. §§ 681–681g), directing CISA to issue regulations establishing two mandatory reporting requirements for covered critical infrastructure entities:

  • Covered cyber incidents: report to CISA within 72 hours of reasonably believing a covered cyber incident has occurred.
  • Ransomware payments: report to CISA within 24 hours of making any ransom payment, whether or not the underlying incident meets the broader reporting threshold.
  • Supplemental reports: submit updated reports when substantially new or different information is available, or when a ransom payment follows an initial incident report.

CISA published a Notice of Proposed Rulemaking on April 4, 2024 (89 Fed. Reg. 23644). The proposed rule defines a "covered cyber incident" as a substantial cyber incident meeting at least one of four threshold conditions: substantial loss of confidentiality, integrity, or availability of an information system; serious impact on the safety or resiliency of an operational technology system; disruption of business or industrial operations; or unauthorized access through a third-party provider, cloud service, managed service provider, or supply chain compromise. These are the proposed definitions; the final rule's precise language may differ.

These are not voluntary information-sharing arrangements. Covered entities that fail to respond to CISA information requests face subpoenas, and failure to comply with a subpoena can be enforced through civil proceedings in federal district court. The enforcement mechanism is real.

Why State Government Is Covered

Presidential Policy Directive 21 (PPD-21), issued February 12, 2013, established the 16 critical infrastructure sectors that CIRCIA uses to define covered entities. The Government Facilities Sector — one of those 16 — explicitly encompasses federal, state, local, tribal, and territorial government facilities: state capitols, courthouses, government office buildings, and public schools.

State agencies are not peripheral to this framework. They are definitionally inside it. CISA held sector-specific stakeholder engagement sessions for the Government Facilities Sector in June 2026 as part of the CIRCIA rulemaking process, treating state and local entities as a primary audience, not an edge case.

The exposure runs beyond the Government Facilities Sector. Many state agencies independently qualify in other sectors:

  • Emergency Services Sector: state emergency management agencies, state fusion centers, public safety answering points (PSAPs)
  • Healthcare and Public Health Sector: state health departments with operational public health IT, Medicaid agency systems, state hospital authorities
  • Water and Wastewater Systems Sector: state water authorities with operational technology systems, state drinking water regulatory programs with connected monitoring systems
  • Transportation Systems Sector: state departments of transportation operating traffic management, bridge management, and freight systems

A state with 40 principal executive agencies may have a dozen that independently qualify as covered entities across multiple sectors, each potentially subject to different Sector Risk Management Agency guidance on top of CIRCIA's baseline requirements.

The Governance Architecture That Does Not Fit

CIRCIA's compliance model assumes a covered entity is an organization with a CISO who has operational authority over its information systems and can represent it as a reporting entity. That describes a private utility. It does not describe a state government.

In most states, the CISO sits in the governor's office, the budget agency, or a central IT department, with policy authority but without direct operational access to agency-level IT environments. Agency CIOs run their own infrastructure under their own agency leadership. The state CISO may not know, in real time, whether the Department of Revenue's tax filing system has experienced a qualifying incident unless the agency decides to report it upward.

To illustrate the risk, consider a hypothetical scenario: ransomware hits a state Department of Motor Vehicles on a Friday evening. The agency's IT team spends 48 hours in containment mode before briefing the agency director. The agency director calls the state CISO on Monday morning. If CISA's 72-hour clock runs from the DMV's team's initial assessment — which is when the covered entity "reasonably believed" the incident occurred — the reporting window may already be closed before the state CISO's office knows the incident happened.

This is not a technology problem. No SIEM integration resolves the question of whether a state agency IT team will treat the first 48 hours as an internal response exercise or as a compliance event requiring immediate upward notification. That is an organizational design problem requiring explicit policy, executive authority, and rehearsal.

A Decision Sequence for State CISOs

Readiness work divides into three categories: scoping, structure, and procedure. The first two do not wait for the final rule.

Scoping (start now, refine after final rule):

  1. Inventory state agencies and identify which critical infrastructure sectors each operates within. Begin with a presumption that every principal executive agency qualifies under the Government Facilities Sector; add sector-specific exposure where it clearly applies. Document the basis.
  2. Map existing sector-specific reporting obligations. CIRCIA adds to existing requirements, it does not replace them. If your Medicaid agency already reports incidents to HHS under HIPAA Security Rule, that obligation remains; CIRCIA adds a separate CISA reporting requirement. Identify where these overlap and where they conflict.
  3. Identify gaps in current reporting authority. Ask specifically: if an incident qualifying under CIRCIA's thresholds occurred at Agency X tonight, who has authority to submit the CISA report on behalf of that agency? If there is no clear answer, that gap is your highest-priority finding.

Structure (requires executive sponsorship):

  1. Designate a CIRCIA Reporting Official with documented backup coverage. This person needs either direct authority to submit reports to CISA across state government or a defined escalation path with explicit time constraints.
  2. Decide between centralized, distributed, and hybrid reporting architectures. Centralized reporting — state CISO submits for all agencies — requires reliable agency-to-CISO notification well within the 72-hour window, since the state CISO needs time to assess and prepare the report. Distributed reporting — each agency submits for its own qualifying incidents — requires consistent incident classification criteria across agencies with widely varying technical staff and resources. Hybrid approaches assign reporting authority based on the type of agency or the nature of the incident. There is no architecture without failure modes; the question is which failure modes your organization can actually manage.
  3. Brief the governor's office and agency heads before the final rule takes effect. CIRCIA's 72-hour clock will not pause for executive awareness-building after an incident. Leadership needs to understand the reporting obligation before an incident, not during one.

Procedure (operational, can be tested now):

  1. Write incident classification criteria aligned to CIRCIA's four threshold conditions in language that an agency security team can apply without calling the state CISO first. The goal is consistent, independent classification across agencies.
  2. Build inter-agency notification protocols that route qualifying incidents to the state CISO's office within 24 hours of the agency's own initial assessment. That leaves time for state-level triage, incident characterization, and report preparation within the 72-hour window.
  3. Run a tabletop exercise with a realistic scenario before the final rule takes effect. A ransomware attack that hits two agencies simultaneously, on a weekend, with conflicting initial assessments about whether a threshold condition has been met, is a better test than a clean single-agency scenario during business hours. The scenario that surfaces organizational gaps is more valuable than the scenario that confirms your procedures work smoothly.

Why Waiting for the Final Rule Is the Wrong Frame

The wait-for-the-final-rule posture has a legitimate application: technical implementation decisions, particularly around reporting system integrations, benefit from waiting for the final rule's specific technical requirements. Some details of the proposed rule will change.

The organizational design steps above do not depend on the final rule's precise definitions. Whether the final rule's threshold for "substantial loss of confidentiality" is somewhat narrower or broader than the NPRM's proposal does not change the structural answer to the question of who holds reporting authority across 40 agencies.

CIRCIA's statute does not specify a post-final-rule compliance window for covered entities; the 18-month and 24-month figures in the law are CISA's rulemaking deadlines (24 months from enactment to publish the NPRM, 18 months after the NPRM to publish the final rule), not grace periods for covered entities. State CISOs should not assume a lengthy runway between the final rule's effective date and the moment reporting obligations apply. The organizational work takes months regardless — but that time comes from what the work actually requires, not from statutory permission to delay.

The Government Facilities Sector town hall CISA conducted in June 2026 was an indicator: CISA treats state and local entities as a population with specific compliance challenges distinct from private critical infrastructure operators. That is an accurate assessment. The compliance challenge is organizational before it is technical, and the organizational work has no shortcut.

Sources and further reading

Spartan X's advisory work with state government clients has focused on precisely this architecture problem — building governance frameworks and operational protocols that account for decentralized IT structures while meeting centralized accountability requirements. The organizational design questions CIRCIA raises for state CISOs are structurally similar to the whole-of-state governance and platform delivery challenges that state technology leaders already navigate. The compliance deadline sharpens the timeline; it does not change the underlying work.

Share this article
LinkedIn

BUILD WITH US

Ready to Solve Hard Problems?

Spartan X builds AI systems, autonomous platforms, and cybersecurity solutions for defense and national security.