CISA’s current regulatory agenda targets September 2026 for the final rule implementing the Cyber Incident Reporting for Critical Infrastructure Act, better known as CIRCIA. The statutory deadline was October 2025. That date passed, as did a revised May 2026 target, so treat September as a plan rather than a certainty.
The scale is worth establishing first. CISA’s own analysis put 316,244 entities in scope. More than 1,200 stakeholders attended four days of town halls in June 2026, held specifically to refine scope and burden after the volume of public comment. A study conducted under CIRCIA counted 52 in-effect or proposed federal incident reporting requirements before anyone starts counting state law. Views on whether this is the right instrument vary considerably. The rulemaking has continued through all of it.
Before the deadlines and the report contents, one of the more important things an organization can establish is whether the rule applies to it at all. In other words, tis your organization a CIRCIA covered entity. That’s what this article covers. Part two covers what the requirements ask for once you land inside the scope.
Sources are the Notice of Proposed Rulemaking published April 4, 2024, and CISA’s own informational overview of it. Scope drew heavy comment and the final rule may differ from what has been published so far.
Two Paths, Either One Sufficient
The NPRM proposes that an entity in one of the sixteen critical infrastructure sectors named in Presidential Policy Directive 21 is a covered entity if it either:
- Exceeds the Small Business Administration size standard for its industry, or
- Meets one or more of the sector-based criteria, regardless of size
An entity doesn’t need to satisfy both. Meeting neither means the requirements don’t apply. A CIRCIA covered entity is an organization that falls within one of the sixteen critical infrastructure sectors and meets either the applicable size threshold or at least one sector-based criterion.
Two results follow from that structure.
Being small is not an exemption. A small business that meets a sector-based criterion is a covered entity even when it falls below the SBA threshold for its industry.
A criterion can reach you from a sector you don’t identify with. CISA states this plainly: meeting a sector-based criterion makes an entity covered even if the entity doesn’t consider itself part of that sector.
What Counts As An Entity
CISA reads the term broadly. Its stated interpretation covers any person, partnership, business, association, corporation, or other organization, whether for-profit, not-for-profit, nonprofit, or government, provided the structure carries legal presence or standing in the United States.
A second breadth point sits alongside it. Covered entities are not limited to owners and operators of critical infrastructure. CISA’s position in the NPRM is that entities actively participating in a critical infrastructure sector may be considered in that sector even where the entity itself is not critical infrastructure.
Read together, those two points mean a municipal department, a rural cooperative, a nonprofit utility, and a small private vendor can each land inside scope through different doors.
The Size Path
The first path runs through the Small Business Administration size standards at 13 CFR Part 121. Those standards are industry-specific and expressed either as an employee count or as average annual receipts, depending on the NAICS code.
Two practical notes. The standard that applies is the one for your industry, not a general figure, so the threshold for a water utility differs from the one for a manufacturer. And the determination is made against your own organization, so status can change as headcount or revenue changes.
Exceeding the standard for your industry makes you a covered entity regardless of whether any sector-based criterion applies.
The Sector Path
The sector-based criteria catch organizations that the size test would miss. These are the proposed criteria most relevant to industrial environments:
| Sector | Proposed criterion |
|---|---|
| Water and Wastewater | Owns or operates a community water system or publicly owned treatment works serving 3,300 or more individuals |
| Energy | Required to report to NERC, or to DOE under OE-417 |
| Critical Manufacturing | Owns or operates a Critical Manufacturing Sector entity |
| Chemical | Owns or operates a CFATS covered chemical facility, or an EPA Risk Management Program facility |
| Transportation | Required by TSA to report cyber incidents |
| Transportation, Maritime | Owns or operates a vessel, facility, or outer continental shelf facility subject to USCG Maritime Transportation Security Act regulations |
| Government Facilities | An SLTT government entity for a jurisdiction of 50,000 or more individuals |
| Emergency Services | Provides emergency services or functions to a population of 50,000 or more individuals |
| Information Technology | Among other things, is an original equipment manufacturer or vendor of operational technology hardware or software components |
| Nuclear | Owns or operates a commercial nuclear power reactor or fuel cycle facility |
The full regulatory text carries additional criteria and more precise language than a summary table can hold. Check the NPRM for the exact wording of any criterion you think might reach you.
Three sectors have no proposed sector-based criteria at all: Commercial Facilities, Dams, and Food and Agriculture. Entities there would be covered through the size threshold, or through a criterion belonging to another sector.
The Information Technology Criteria Reach OT Vendors
As proposed, that criterion makes an OT hardware or software vendor a covered entity under the Information Technology sector. Regardless of size. Regardless of which sector it identifies with.
The practical effect is that an organization can be a covered entity by supplying equipment into critical infrastructure, without owning or operating any critical infrastructure itself. Integrators, panel builders, systems houses, and automation vendors fall within reach of that criterion as drafted.
The Information Technology criteria also cover entities that knowingly provide or support IT hardware, software, systems, or services to the federal government, entities that develop or sell, license, or maintain critical software, and entities performing functions related to domain name operations.
If your company builds, resells, integrates, or maintains OT components, this is the row to take to your counsel.
The Water Threshold, and the Question Underneath It
Set the 3,300 figure against the shape of the sector. Congressional Research Service analysis puts 81 percent of community water systems at 3,300 or fewer individuals served, roughly 40,000 of the nearly 50,000 systems operating nationally. Among privately owned systems the share is higher, above 95 percent.
The criterion as drafted catches systems at 3,300 and above, which places the large majority of community water systems below the line. Those systems would be covered only by exceeding the SBA size standard. Where the final rule draws that boundary is an open question for the sector.
Either way, falling outside CIRCIA doesn’t remove state reporting obligations, sector requirements, or the practical need to understand what happened in your own environment.
Working Out Your CIRCIA Covered Entity Status
When attempting to determine CIRCIA covered entity status, start with the SBA size standard for your NAICS code, then review every sector-based criterion that could apply to your organization.
Check the size path first. Find the SBA size standard for your NAICS code and compare it against your current employee count or average annual receipts. This is the fastest determination to make and it resolves a lot of cases on its own.
Then read every sector criterion, not just yours. The criteria aren’t confined to the sector you identify with. The Information Technology row in particular reaches organizations well outside the sector it names.
Check the specific numbers against your own. Population served, jurisdiction size, and facility designations are the pivots in several criteria. A community water system serving 3,290 people and one serving 3,310 land differently.
Note any federal reporting you already do. Obligations to NERC, DOE under OE-417, TSA, or the Coast Guard both trigger sector criteria and may matter later for the reporting exception covered in part two.
Write down the determination and the date. Coverage status can change with headcount, revenue, service population, or a new facility designation. A dated record of how you reached your answer makes the next review a revision rather than a fresh start.
Ask CISA if you are genuinely unsure. CISA has invited outreach from organizations uncertain whether they are part of a critical infrastructure sector, and maintains a mailbox at circia@cisa.dhs.gov for questions.
What Comes Next
If you land outside scope on both paths, the CIRCIA obligations don’t apply to you as proposed, and the remaining question is whether the final rule redraws any of the lines above.
If you land inside scope and are a CIRCIA covered entity (or you think you might be), part two next week will cover the substance: what counts as a reportable incident, the 72-hour and 24-hour clocks, what a report has to contain, and the two-year data and records preservation obligation that runs alongside it.
We’ll also publish an update when the final rule lands, covering what changed from the proposal and what it means for OT environments specifically. If you’re working through a coverage determination and want a second set of eyes on it, we’re happy to talk it through without it turning into a sales call.
Become a Subscriber
EMBEROT WILL NEVER SELL, RENT, LOAN, OR DISTRIBUTE YOUR EMAIL ADDRESS TO ANY THIRD PARTY. THAT’S JUST PLAIN RUDE.
