CIRCIA Is Coming: What U.S. Organizations Need to Know

Cybersecurity requirements in the United States are always changing. One important update on the horizon is the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA). The Final Rule is expected in September 2026 and will likely bring new reporting requirements for organizations in U.S. critical infrastructure. So, what does CIRCIA mean for your organization, and how does secure data erasure play a role?

20-8-2026
CIRCIA

What Is CIRCIA?

CIRCIA is a U.S. federal law designed to improve visibility into cyber threats affecting critical infrastructure. It requires CISA to establish reporting requirements for covered cyber incidents and ransom payments. Under the proposed requirements, covered organizations would need to report certain cyber incidents to CISA within 72 hours and ransom payments within 24 hours. The Final Rule will determine the final reporting requirements and exactly which organizations are covered.

If your organization might be affected, it’s important to know where your sensitive data is stored, how you identify and document incidents, and what information you need to keep after an incident.

Where Does Data Erasure Fit In?

CIRCIA does not specifically require data erasure, but it highlights how important it is to control sensitive information at every stage of its lifecycle. Devices often still hold sensitive information when they are replaced, returned, repaired, reused, resold, or recycled.

Once you no longer need this data for business, legal, or regulatory reasons, secure data erasure makes sure it cannot be accessed on devices that leave your organization. Simply deleting files or formatting a drive is not enough. A controlled data sanitization process securely sanitizes the device and provides documentation of the process.

Add Assurance with Data Erasure Verification

You can take data security a step further with data erasure verification. This process independently confirms that your devices have been properly sanitized and contain no recoverable data. With detailed reporting, you have clear evidence of the process and a strong audit trail.

As cybersecurity requirements change, it’s important to look beyond just protecting active systems. Knowing what data to keep, what to securely erase, and how to document and verify the process is key to responsible data management. With Certus, you can securely erase your data, verify the results with Certus VerifyDrive™, and create detailed reports every step of the way.

Let Certus help you securely erase, verify, and document your data throughout the entire IT asset lifecycle.

Original Logo (Horizontal)

We simplify certified data erasure with solutions for every industry.

Solutions

Secure data erasure solutions for ITADs, OEMs, IT recyclers, and refurbishers.

Secure data sanitization solutions for corporate IT teams focused on compliance, remote capabilities, and device lifecycle management.

Industry standard compliancy

Certus is a member of

Software Made in Germany 2026 english bleu

Copyright All Rights Reserved © 2026 - Cookie policy