Cybersecurity requirements in the United States are always changing. One important update on the horizon is the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA). The Final Rule is expected in September 2026 and will likely bring new reporting requirements for organizations in U.S. critical infrastructure. So, what does CIRCIA mean for your organization, and how does secure data erasure play a role?

What Is CIRCIA?
CIRCIA is a U.S. federal law designed to improve visibility into cyber threats affecting critical infrastructure. It requires CISA to establish reporting requirements for covered cyber incidents and ransom payments. Under the proposed requirements, covered organizations would need to report certain cyber incidents to CISA within 72 hours and ransom payments within 24 hours. The Final Rule will determine the final reporting requirements and exactly which organizations are covered.
If your organization might be affected, it’s important to know where your sensitive data is stored, how you identify and document incidents, and what information you need to keep after an incident.
Where Does Data Erasure Fit In?
CIRCIA does not specifically require data erasure, but it highlights how important it is to control sensitive information at every stage of its lifecycle. Devices often still hold sensitive information when they are replaced, returned, repaired, reused, resold, or recycled.
Once you no longer need this data for business, legal, or regulatory reasons, secure data erasure makes sure it cannot be accessed on devices that leave your organization. Simply deleting files or formatting a drive is not enough. A controlled data sanitization process securely sanitizes the device and provides documentation of the process.
Add Assurance with Data Erasure Verification
You can take data security a step further with data erasure verification. This process independently confirms that your devices have been properly sanitized and contain no recoverable data. With detailed reporting, you have clear evidence of the process and a strong audit trail.
As cybersecurity requirements change, it’s important to look beyond just protecting active systems. Knowing what data to keep, what to securely erase, and how to document and verify the process is key to responsible data management. With Certus, you can securely erase your data, verify the results with Certus VerifyDrive™, and create detailed reports every step of the way.
Secure data erasure solutions for ITADs, OEMs, IT recyclers, and refurbishers.
Secure data sanitization solutions for corporate IT teams focused on compliance, remote capabilities, and device lifecycle management.
Copyright All Rights Reserved © 2026 - Cookie policy