Vulnerabilities

CIRCIA Cyber Incident Reporting

July 25, 2026 00:00 · 12 min read
CIRCIA Cyber Incident Reporting

Industry groups who participated in town halls hosted by the Cybersecurity and Infrastructure Security Agency (CISA) about the pending cyber incident notification regulation had a few consistent messages: they want the regulation to apply to fewer companies, they don't want to report as many incidents, and they want to provide less information when they do report.

CISA's Rulemaking Process

CISA published transcripts from the town halls, where the agency sought feedback on the delayed rule for the 2022 Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA). The law requires critical infrastructure owners to report major cyberattacks to the federal government within 72 hours and ransomware payments within 24 hours. The law was designed to let the feds share information about significant incidents more widely to prepare other potential victims.

CISA published a proposed rule on the law in 2024 to define terms like “covered cyber incident” and more, and industry groups have persistently registered their objections since then. CISA missed the October 2025 deadline for finalizing the rule, then missed a May reset target date, and now the administration says the rule will be completed in September.

Industry Concerns

Companies and industry groups are concerned about the scope and burden of the regulation. Grant MacIntyre, director of regulatory affairs and senior attorney at the Auto Care Association, said, “The rule includes too many companies.” CISA estimated that more than 300,000 entities will be subject to its requirements.

Some industries, such as the insurance sector, advocated for their removal entirely from the regulation. Others, like the Nuclear Energy Institute, sought to reduce the number of affected entities within their sector. The Alliance for Chemical Distribution expressed concerns that small businesses could be swept in under multiple cyber categories, despite CISA's intention to avoid overburdening them.

Reporting Requirements

Industry groups also pushed back against the reporting requirements, arguing that they should not have to provide too much information. Samantha Burch, vice president of technology public policy at government affairs at AHIP, said, “CISA should seek to collect the least amount of information possible in the easiest to report fashion to facilitate information accuracy and reporting speed.”

Others worried about what kind of incidents would trigger reporting requirements. Tim Pospisil, chief security officer for Nebraska Public Power District, said, “My big concern is that you’re going to be asking us to report incidents on every time some foreign entity tickles our firewall, whether they do anything or not, if they just do a ping or a search. And that could be extremely burdensome.”

Next Steps

Nick Andersen, the acting director of CISA, talked about his overarching intentions with CIRCIA at the town halls. “CISA does not view CIRCIA as simply a check-the-box compliance exercise,” Andersen said. “CIRCIA will enhance visibility into the cyberthreat landscape to enable a robust national early warning capability for critical infrastructure.”

A CISA spokesperson said, “CISA recognizes the importance of CIRCIA, however, multiple funding lapses impacted CISA’s ability to conduct rulemaking activity for CIRCIA. CISA continues to work on the final rule.” The agency will continue to communicate updates on the CIRCIA rulemaking process and timeline through CISA.gov/CIRCIA and the Office of Information and Regulatory Affairs’ Unified Agenda of Regulatory and Deregulatory Actions.

Industry sources expressed skepticism about CISA's ability to meet the September target date, given past delays and the complexity of the issue. One source said, “AI has fundamentally changed the playing field... We’re now in a mythos class environment.”

Despite the challenges, industry representatives remain optimistic that CISA will simplify the regulation and focus on the most important pieces of information. Henry Young, senior director of policy for the Business Software Alliance, said, “In general, industry is optimistic that what we’ll end up with are a few of the most important pieces of information, so that in the emergency, companies can act quickly and actually respond to an incident rather than completing lots of paperwork.”


Source: CyberScoop

Source: CyberScoop

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free