CIRCIA Rule Faces September Deadline As Industry Seeks Narrower Filings
CISA is working toward a September target for the delayed CIRCIA rule as industry groups seek fewer covered entities, narrower incident triggers and leaner reporting requirements. The law sets 72-hour incident and 24-hour ransomware-payment reporting deadlines, while the proposed rule could cover more than 300,000 entities.

The US Cybersecurity and Infrastructure Security Agency is working toward a September target for its delayed cyber incident reporting rule as industry groups press for fewer covered organisations, narrower incident triggers and less information in each filing.
The rule implements the 2022 Cyber Incident Reporting for Critical Infrastructure Act, known as CIRCIA.
The law requires covered critical infrastructure operators to notify the federal government of major cyber incidents within 72 hours and report ransomware payments within 24 hours.
Reporting Scope Remains Contested
CISA's 2024 proposal estimated that more than 300,000 entities could fall within the rule.
Industry representatives told four agency town halls in June that the proposed scope could include too many organisations and incidents.
Grant MacIntyre of the Auto Care Association argued that the rule reaches too many companies.
Insurance representatives sought exclusions for parts of their sector, while the Nuclear Energy Institute wanted coverage limited to operators already subject to Nuclear Regulatory Commission cyber-reporting requirements.
Small-business treatment is another point of dispute.
According to Douglas Leigh of the Alliance for Chemical Distribution, the proposed size-or-sector test could still pull small chemical distributors into several covered categories.
Samantha Burch of the health insurance association AHIP urged CISA to collect only the information needed for accurate and rapid reporting.
Industry Seeks Narrower Incident Triggers
Participants also questioned which events should trigger a filing.
Tim Pospisil of Nebraska Public Power District warned that broad language could require reports for routine probes of a firewall even when no compromise occurs.
Several groups opposed requirements to disclose details about an affected organisation's security controls.
Their comments frame the central implementation choice: how much information CISA needs for national warning and defensive action without diverting incident-response teams into excessive paperwork.
September Target Follows Earlier Delays
CISA missed the original October 2025 deadline and a later May target.
The administration's regulatory agenda now lists September for completion, although several industry sources told CyberScoop they doubted that schedule would hold.
Congress has also pressed the agency to finish.
In its fiscal 2027 Department of Homeland Security report, the House Appropriations Committee expressed concern about the delays and urged publication after stakeholder review.
The timetable follows a process that began with the 2022 law and moved to a proposed rule in 2024.
That proposal was intended to define covered entities, covered incidents and the information required in a report before the obligations take effect.
CISA Says Rulemaking Continues
Acting CISA director Nick Andersen told a town hall that the agency does not view CIRCIA as a compliance checklist.
He said faster reporting is intended to improve visibility into cyber threats and support warnings and defensive measures for critical infrastructure.
A CISA spokesperson attributed the rulemaking delays partly to funding lapses and confirmed that work on the final rule continues.
The agency also said 1,200 critical infrastructure stakeholders attended its town halls and directed future updates to CISA.gov/CIRCIA and the federal regulatory agenda.
CISA does not identify which industry requests it will accept and has not confirmed that the September target will hold.
The unresolved items are the final coverage threshold, the incidents that trigger a filing and the information affected organisations must provide.




















