October 2, 2026
CIRCIA is still developing, but organizations do not need to wait for a final rule to strengthen their incident readiness.
For research institutions, colleges and universities, K-12 schools, museums and other mission-driven organizations, the most important preparation may be less about memorizing a reporting deadline and more about understanding how quickly your organization can recognize an incident, gather facts, make decisions and act.
That means looking closely at:
Our recent Fireside Chat on CIRCIA explored these issues in depth, including sector-specific scenarios for higher education, K-12 and museums.
One of the first practical steps is determining whether your organization is likely to be covered.
The proposed framework considers both size and sector. That means organizations should not assume that being small automatically puts them outside the rule. Small nonprofits, museums and educational institutions may still need to evaluate whether the requirements apply.
Jennifer Beckage, ESQ., CIPP/US, CIPP/E, IR/litigation attorney at The Beckage Firm, put it plainly:
“We don't want to wait for an incident to happen to try to identify whether we're the covered entity. There's just not enough time under these time clocks.”
That does not mean rewriting policies before the final rule is clear. It does mean understanding your likely exposure and being ready to act once the requirements are settled.
The first hours of an incident are often the least certain.
Facts are still developing. Technical teams may be collecting logs. Legal counsel may be evaluating obligations. Leadership may be deciding how to respond. A vendor may still be investigating.
This is where preparedness matters.
Scott Morris, CISM, CISSP, SVP of technology & security at The Beckage Firm, recommended focusing on whether timelines and escalation processes are actually understood:
“Really focusing on making sure that your timelines and escalation processes are understood. What are your barriers to progress and decision making?”
For organizations with an incident response plan, the goal is not to start over. It is to make sure the plan can support fast escalation, clear decision-making and action during the first 72 hours.
That includes nights, weekends and holidays.
A strong incident response plan should identify who has authority to make decisions when facts are incomplete.
That can be especially important in education and nonprofit environments where boards, legal counsel, executives, technology leaders and other stakeholders may all need to be involved.
The plan should identify roles clearly. It should also identify backups in case the primary person is unavailable.
A tabletop exercise can help reveal whether that authority is actually understood.
Jennifer described the difference she sees when organizations have already worked through these scenarios. Teams know their roles, alternates are identified and decisions are less likely to stall while people figure out who should act.
Third-party incidents were a recurring theme throughout the Fireside Chat because they are a common part of modern incident response.
A university may rely on a cloud identity provider. A school may depend on outside systems for transportation, attendance, payroll or special education. A museum may rely on a vendor for ticketing, membership or donor data.
If one of those providers experiences an incident, your team may need information quickly.
That makes vendor contracts part of incident readiness.
Ask:
Jennifer warned that delayed notification language in a contract can leave an organization without the information it needs when timelines matter. Scott also recommended mapping critical vendors and knowing how to reach them when an incident happens at an inconvenient time.
Emilyann Fogarty, CISSP, PMP, chief information security officer at Nysernet, emphasized one preparedness step that matters whether or not CIRCIA applies:
“Whether you're subject to CIRCIA or not — data governance. Know what kind of data you have, what classification your data has. Cannot emphasize that enough.”
That knowledge helps teams understand the significance of an incident more quickly.
Evidence preservation matters too.
Logs, tickets, devices, forensic images and alerts may all become important during an investigation. Some logs may only be available for a short period, which means organizations should know what is retained and how to preserve it before an incident begins.
A useful question to ask now is:
If your team needed those records tonight, could you get them?
CIRCIA may be only one of several obligations involved in an incident.
Federal requirements, state breach laws, contracts and other regulatory frameworks may all apply at the same time. The relevant legal tests and timelines may differ.
That makes advance preparation important.
Organizations should understand which obligations may apply before an incident so they are not trying to perform the full analysis under pressure.
For teams with limited time and resources, that preparation can help focus attention on the information that matters most.
You do not need the final CIRCIA rule to strengthen the fundamentals of incident readiness.
Consider these steps:
These steps can improve incident readiness regardless of whether CIRCIA ultimately applies to your organization.
For a deeper look at how these issues can play out in higher education, K-12 and museum environments, watch the full Fireside Chat here.
If your organization would benefit from help reviewing incident readiness, vendor dependencies or response planning, contact Nysernet. We can connect you with the right resources and expertise.