During recent town halls, industry groups told the Cybersecurity and Infrastructure Security Agency (CISA) that they want the pending CIRCIA cyber incident reporting rule to cover fewer companies, require fewer reported incidents, and demand less information per report.

 

What happened

CISA published transcripts last week from town halls it held to gather feedback on the delayed rule implementing the 2022 Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA). The law requires critical infrastructure owners to report major cyberattacks to the federal government within 72 hours and ransomware payments within 24 hours.

CISA proposed a rule on the law in 2024 to define key terms, and industry groups have objected ever since. The agency missed an October 2025 deadline and a May reset date for finalizing the rule, and the administration now targets September 2026 for completion. CISA estimates more than 300,000 entities will fall under the rule's requirements. Some industry sources doubt CISA will meet the new deadline, and most say they have not received signals about which town hall feedback CISA plans to adopt.

 

Going deeper

Industry representatives raised several concerns during the town halls:

  • Some sectors, including two insurance industry groups, asked CISA to remove their sector from the rule entirely.
  • The Nuclear Energy Institute asked CISA to limit coverage to entities already subject to Nuclear Regulatory Commission cybersecurity reporting requirements.
  • The Alliance for Chemical Distribution warned that the rule's size-or-sector qualification structure could still sweep in small businesses despite CISA's stated intent to avoid overburdening them.
  • AHIP, a health insurance trade association, asked CISA to collect the least amount of information possible and make reporting as easy as possible.
  • Many industry commenters argued reports should exclude information about an affected entity's security measures.
  • Nebraska Public Power District raised concerns that low-level activity, such as a firewall ping or scan, could trigger reporting obligations and create unnecessary burden.

 

What was said

Nick Andersen, acting director of CISA, said the agency does not see CIRCIA as a "check-the-box compliance exercise," and said the rule will support a national early warning capability by enabling CISA to share "actionable defensive and eviction measures" with network defenders.

 

By the numbers

  • CISA estimates the rule will apply to more than 300,000 entities.
  • The town halls took place over four dates in June.
  • 1,200 critical infrastructure stakeholders attended the town halls, according to CISA.
  • CISA has missed two prior deadlines (October 2025 and May 2026) and now targets September 2026.

 

In the know

CIRCIA, the Cyber Incident Reporting for Critical Infrastructure Act, passed in 2022 and directs CISA to collect timely reports of major cyberattacks and ransomware payments from critical infrastructure owners and operators. CISA proposed a draft rule in 2024 to define which entities and incidents the law covers but has not yet finalized it.

 

Why it matters

This rule will decide how much visibility the federal government has into cyberattacks affecting power, water, healthcare, and other services. If CISA narrows the rule the way some industry members are asking, fewer companies will have to report incidents, and the reports that do come in will contain less detail on affected systems and security measures. This could create a trade-off because CISA hopes to build a national early warning system, but that could take a hit if the data it receives becomes more limited. A narrower rule could ease the compliance burden on small businesses, but it could also result in CISA and other potential victims learning about possible threats later than the law originally intended.

 

The bottom line

CISA now says it will finalize the CIRCIA rule in September 2026, but two missed deadlines and continued uncertainty about how much industry feedback the agency will adopt make that date uncertain. Companies that will fall under the rule should watch for a published proposal rather than assume the scope or reporting requirements are settled.

 

FAQs

What is CISA?

The Cybersecurity and Infrastructure Security Agency (CISA) is the federal agency responsible for protecting the nation's critical infrastructure from cyber and physical threats.

 

What counts as critical infrastructure?

Critical infrastructure refers to the systems and sectors, such as energy, water, healthcare, and financial services, that a country depends on for public safety and economic stability.

 

Why does the government want companies to report cyberattacks?

Incident reporting helps regulators identify emerging threats and warn other potential targets before an attack spreads further.