6 MIN READ
October 2, 2026
CIRCIA is still developing, but organizations do not need to wait for a final rule to strengthen their incident readiness.
For research institutions, colleges and universities, K-12 schools, museums and other mission-driven organizations, the most important preparation may be less about memorizing a reporting deadline and more about understanding how quickly your organization can recognize an incident, gather facts, make decisions and act.
That means looking closely at:
- Whether your organization may be covered
- Who owns escalation and reporting decisions
- How quickly critical vendors can provide information
- Whether logs and other evidence can be preserved
- What happens when an incident unfolds outside normal business hours
- Whether your incident response plan works in practice
Our recent Fireside Chat on CIRCIA explored these issues in depth, including sector-specific scenarios for higher education, K-12 and museums.
Watch the full Fireside Chat:
Start by understanding whether CIRCIA may apply to you
One of the first practical steps is determining whether your organization is likely to be covered.
The proposed framework considers both size and sector. That means organizations should not assume that being small automatically puts them outside the rule. Small nonprofits, museums and educational institutions may still need to evaluate whether the requirements apply.
Jennifer Beckage, ESQ., CIPP/US, CIPP/E, IR/litigation attorney at The Beckage Firm, put it plainly:
“We don't want to wait for an incident to happen to try to identify whether we're the covered entity. There's just not enough time under these time clocks.”
That does not mean rewriting policies before the final rule is clear. It does mean understanding your likely exposure and being ready to act once the requirements are settled.
Look closely at the first 72 hours
The first hours of an incident are often the least certain.
Facts are still developing. Technical teams may be collecting logs. Legal counsel may be evaluating obligations. Leadership may be deciding how to respond. A vendor may still be investigating.
This is where preparedness matters.
Scott Morris, CISM, CISSP, SVP of technology & security at The Beckage Firm, recommended focusing on whether timelines and escalation processes are actually understood:
“Really focusing on making sure that your timelines and escalation processes are understood. What are your barriers to progress and decision making?”
For organizations with an incident response plan, the goal is not to start over. It is to make sure the plan can support fast escalation, clear decision-making and action during the first 72 hours.
That includes nights, weekends and holidays.
Make decision authority clear
A strong incident response plan should identify who has authority to make decisions when facts are incomplete.
That can be especially important in education and nonprofit environments where boards, legal counsel, executives, technology leaders and other stakeholders may all need to be involved.
The plan should identify roles clearly. It should also identify backups in case the primary person is unavailable.
A tabletop exercise can help reveal whether that authority is actually understood.
Jennifer described the difference she sees when organizations have already worked through these scenarios. Teams know their roles, alternates are identified and decisions are less likely to stall while people figure out who should act.
Review your vendor relationships
Third-party incidents were a recurring theme throughout the Fireside Chat because they are a common part of modern incident response.
A university may rely on a cloud identity provider. A school may depend on outside systems for transportation, attendance, payroll or special education. A museum may rely on a vendor for ticketing, membership or donor data.
If one of those providers experiences an incident, your team may need information quickly.
That makes vendor contracts part of incident readiness.
Ask:
- How quickly must a vendor notify you?
- Who receives the notification?
- What information must they provide?
- Can your team reach the vendor outside normal business hours?
- Does the contract allow the vendor to wait until its investigation is complete before notifying you?
Jennifer warned that delayed notification language in a contract can leave an organization without the information it needs when timelines matter. Scott also recommended mapping critical vendors and knowing how to reach them when an incident happens at an inconvenient time.
Know your data and preserve what matters
Emilyann Fogarty, CISSP, PMP, chief information security officer at Nysernet, emphasized one preparedness step that matters whether or not CIRCIA applies:
“Whether you're subject to CIRCIA or not — data governance. Know what kind of data you have, what classification your data has. Cannot emphasize that enough.”
That knowledge helps teams understand the significance of an incident more quickly.
Evidence preservation matters too.
Logs, tickets, devices, forensic images and alerts may all become important during an investigation. Some logs may only be available for a short period, which means organizations should know what is retained and how to preserve it before an incident begins.
A useful question to ask now is:
If your team needed those records tonight, could you get them?
Prepare for overlapping obligations
CIRCIA may be only one of several obligations involved in an incident.
Federal requirements, state breach laws, contracts and other regulatory frameworks may all apply at the same time. The relevant legal tests and timelines may differ.
That makes advance preparation important.
Organizations should understand which obligations may apply before an incident so they are not trying to perform the full analysis under pressure.
For teams with limited time and resources, that preparation can help focus attention on the information that matters most.
What can your organization do now?
You do not need the final CIRCIA rule to strengthen the fundamentals of incident readiness.
Consider these steps:
- Review whether your organization is likely to be covered
- Revisit your incident response plan
- Confirm who owns escalation and decision-making
- Identify backups for key incident roles
- Test the plan through a tabletop exercise
- Map critical vendors and review notification requirements
- Understand what data your systems hold and how it is classified
- Confirm that important logs and incident records can be preserved
- Document the regulatory and contractual obligations your organization may face
These steps can improve incident readiness regardless of whether CIRCIA ultimately applies to your organization.
Want more information?
For a deeper look at how these issues can play out in higher education, K-12 and museum environments, watch the full Fireside Chat here.
If your organization would benefit from help reviewing incident readiness, vendor dependencies or response planning, contact Nysernet. We can connect you with the right resources and expertise.