Nysernet | Articles and Insights

CIRCIA Is Coming. Are Mission-Driven Organizations Ready for the Decisions Behind the Deadline?

Written by nysernet | Sep 17, 2026, 9:59:59 AM

Sept. 17, 2026

 

For research institutions, colleges and universities, schools, museums, cultural organizations and other nonprofits, preparing for CIRCIA is more complicated than adding another reporting requirement to an incident response plan.

It will likely require looking closely at how an incident actually moves through your organization.

Who discovers it? How quickly does central IT or security learn about it? When does legal counsel become involved? Who has the authority to make a reporting decision? And what happens when the incident begins with a vendor, cloud provider or system that your cybersecurity team doesn't directly control?

Those questions matter because the Cyber Incident Reporting for Critical Infrastructure Act of 2022, or CIRCIA, could introduce new federal reporting obligations for covered organizations.

Under CISA's proposed rule, a covered entity that reasonably believes it has experienced a covered cyber incident would have up to 72 hours to report it to CISA. A covered entity that makes a ransom payment following a ransomware attack would have 24 hours to report the payment. CISA's proposed framework also includes supplemental reporting and certain data and records preservation requirements.

The details of the regulation matter. But for mission-driven institutions, there is another important question:

Is your organization structured to make the decisions CIRCIA could require?

CIRCIA readiness looks different in mission-driven environments

Nysernet works alongside institutions with unique technology environments where complexities take many forms: 

  • A university may have central IT alongside distributed research environments, departmental systems and independently selected cloud platforms.
  • A museum may have a small technology team responsible for everything from administrative systems and collections data to ticketing, visitor services and public-facing technology.
  • A school system may be managing aging infrastructure, limited cybersecurity staffing, thousands of users and a growing collection of third-party platforms.
  • And across nonprofit organizations, technology teams are often being asked to manage significant cybersecurity risk while working within very real staffing, budget and operational constraints.

That context changes the CIRCIA readiness conversation. The challenge isn't simply knowing that a clock exists. For mission-driven organizations, it's making sure information, authority and expertise can move through the organization quickly enough for the right people to make informed decisions while an incident is still unfolding.

“For the organizations we serve, CIRCIA readiness isn't just about understanding a reporting deadline. It's about making sure the people who need to act can get the right information, involve the right stakeholders and make decisions quickly, often while an incident is still unfolding.”
Emilyann Fogarty, CISO, Nysernet

Here are five questions research, education, cultural and nonprofit organizations should be asking now, before CIRCIA takes effect.

1. Will your cybersecurity team know about an incident quickly enough?

The first challenge may happen before anyone starts thinking about CIRCIA.

Someone has to recognize that an incident occurred and get that information to the right people.

That can be complicated in decentralized environments.

Consider a university researcher using a specialized cloud platform purchased by a department. A museum relying on a third party for ticketing or visitor services. A school using dozens of instructional applications. Or a nonprofit whose managed service provider administers critical parts of its infrastructure.

The people who first see suspicious activity may not be the same people responsible for evaluating the incident and coordinating your organization's response. 

That creates an important readiness question:

How does a potentially significant incident move from a department, researcher, employee or vendor to the people responsible for organization-wide incident response?

Under CISA's proposal, the 72-hour timeline would be tied to when the covered entity reasonably believes a covered cyber incident has occurred.

You don't want to spend any of that window discovering that critical information was sitting somewhere else in the organization.

2. Are your vendor relationships built for time-sensitive incident decisions?

Across the mission-driven organizations Nysernet serves, third-party technology has become an important part of delivering essential services.

Cloud infrastructure. Managed services. Learning platforms. Ticketing systems. Research applications. Fundraising platforms. Payroll systems. Software-as-a-service providers.

Third parties make it possible for institutions with limited internal resources to deliver sophisticated services. They also make incident response more complicated.

CISA's proposed framework specifically contemplates incidents involving third-party providers; its examples include unauthorized access using compromised credentials from a managed service provider.

If a critical vendor experiences an incident, your team may need more than a notification saying, ‘We're investigating.’

You may need enough information to understand whether your organization has experienced an incident, which systems and data are affected and what your own obligations may be.

That makes vendor management part of incident readiness.

Ask:

  • How quickly are critical vendors required to notify us?

  • Who receives those notifications?

  • What information are they required to provide?

  • Can we escalate when the initial information isn't enough to make a decision?

A contract negotiated for uptime and pricing may not necessarily provide what a cybersecurity team needs during a fast-moving incident.

3. Who can make a reporting decision when the investigation isn't finished?

Cyber incidents rarely arrive with complete information.

In the first hours, your team may still be determining how an attacker gained access, which systems were affected, whether sensitive information was accessed and whether the incident is ongoing.

Meanwhile, a reporting decision may require participation from people outside cybersecurity.

Legal counsel may need to interpret regulatory obligations. Executive leadership may need to evaluate institutional risk. Communications, privacy, compliance, risk management and other teams may also need to participate.

In the collaborative and sometimes decentralized environments we see across the Nysernet community, that raises a practical issue: 

Who has the authority to make the call when the facts are still developing?

An incident response plan can identify roles on paper. The more useful test is whether those people understand their roles before the organization is under pressure.

4. Can you investigate the incident, preserve evidence and keep your mission moving?

For mission-driven organizations, incident response doesn’t happen in isolation.

  • Classes still need to happen.
  • Researchers may be working against grant deadlines or time-sensitive experiments.
  • Visitors may still be arriving.
  • Students, patients, staff or community members may depend on digital services.

At the same time, the cybersecurity team may be containing an incident, preserving evidence, coordinating with vendors, working with counsel and documenting what happened.

CISA's proposed framework would also require covered entities that submit CIRCIA reports to preserve certain data and records related to the incident.

That creates competing priorities at exactly the moment when resources are most constrained.

The question isn't simply:  Can we respond to an incident?

It's: Can we respond, preserve what we need, support decisionmakers and maintain the services our mission depends on at the same time?

5. Does your incident response plan reflect how your institution actually operates?

In our work with members, we've learned that having an incident response plan is only part of being prepared. The more important question is whether that plan reflects how your organization actually operates. 

  • Does it account for decentralized technology ownership?
  • Does it include critical vendors and managed service providers?
  • Does everyone know when legal counsel should be involved?
  • Does it establish a path for quickly reaching executive decisionmakers?
  • Does it identify who preserves incident records and evidence?
  • Does it reflect the services your organization cannot afford to lose during an incident?
  • And has anyone tested whether all of that actually works?

Cybersecurity preparedness is a shared responsibility rather than something that belongs exclusively to one department. But having a plan is not enough. You must pressure test the plan to ensure that the assumptions you’ve defined match reality, before you ever put them to use in a real incident.

A CIRCIA readiness check for mission-driven organizations

Before a significant incident occurs, prepare your organization by answering these questions:

  • How does an incident outside central IT reach the cybersecurity team?
  • Who determines whether an incident may trigger a reporting obligation?
  • Who has authority to involve legal counsel and executive leadership?
  • Which third-party providers are critical to incident response?
  • What are those providers required to tell you and how quickly?
  • Where will incident evidence and records be preserved?
  • Which services must continue while the investigation is underway?
  • Who has authority to make the final reporting decision?
  • Has your organization practiced making these decisions under realistic conditions?

If several answers begin with “It depends” or “I'm not sure,” that doesn't necessarily mean your organization is unprepared.

It tells you where the next conversation needs to happen.

Preparation starts now

While CIRCIA's regulatory details are still pending, many of the preparations that matter most are relevant regardless of the final CIRCIA ruling.

  • Clear escalation paths
  • Strong vendor communication
  • Defined decision-making authority
  • Evidence preservation
  • Executive involvement
  • Tested incident response processes

Those are fundamentals of cyber resilience regardless of what the final regulation ultimately requires.

And they are particularly important for organizations whose cybersecurity teams are already working with limited resources.

Nysernet helps organizations supplement capabilities they may not have the staff or expertise to address internally. We serve institutions that serve others. And we believe strengthening cybersecurity is easier when organizations can draw on trusted expertise and learn alongside peers facing many of the same challenges.

Join the conversation: What does CIRCIA mean for your organization?

The proposed rule may be federal, but the readiness questions are highly specific to your organization.

On Oct. 1, Nysernet will bring cybersecurity and legal perspectives together to look specifically at what CIRCIA could mean for education, research, cultural and nonprofit organizations.

Join Nysernet Chief Information Security Officer Emilyann Fogarty and experts from The Beckage Firm for a virtual fireside chat:

CIRCIA Is Coming — What Education, Cultural and Nonprofit Organizations Need to Know

Thursday, Oct. 1 | 1 p.m. ET | Virtual | Register Now

We'll explore:

  • Whether your organization may be covered
  • Which incidents could trigger the proposed 72-hour reporting requirement
  • The separate proposed 24-hour ransom-payment reporting timeline
  • How vendor and third-party incidents could affect reporting decisions
  • What CIRCIA could mean for escalation, evidence preservation and executive decision-making
  • What your organization can prepare now — and which decisions should wait until the rule is final

The goal isn't simply to understand another regulation.

It's to help your organization be better prepared to make the decisions that may come with it.

Save Your Seat

Expertise for What Comes Next

Nysernet + The Beckage Firm Partnership

The Beckage Firm is an expert partner to Nysernet, delivering legal, regulatory and cybersecurity expertise to help our members better understand and manage cyber risk. The boutique security and privacy law firm brings together attorneys and technologists with experience in data security and privacy compliance, security and risk assessments, incident response and cyber insurance.

Through our partnership, The Beckage Firm works alongside Nysernet’s cybersecurity team to support members through services including Cyber Risk Maturity Blueprints, Cyber Insurance Review and Advisement, and other cybersecurity and risk-management needs. This integrated approach gives members access to both technical and legal perspectives as they evaluate risk, navigate changing requirements and make decisions about strengthening their cybersecurity programs.

Learn more about Nysernet's cybersecurity services >>

For additional background on CIRCIA and the rulemaking process, visit CISA's CIRCIA resources >>