Funding
REGULATION WATCH:

CIRCIA Rule Faces September Deadline As Industry Seeks Narrower Filings

Newsroom brief

CISA is working toward a September target for the delayed CIRCIA rule as industry groups seek fewer covered entities, narrower incident triggers and leaner reporting requirements. The law sets 72-hour incident and 24-hour ransomware-payment reporting deadlines, while the proposed rule could cover more than 300,000 entities.

Verified against source materialEdited by SendTech Times Capital & Policy Desk
CIRCIA Rule Faces September Deadline As Industry Seeks Narrower Filings

The US Cybersecurity and Infrastructure Security Agency is working toward a September target for its delayed cyber incident reporting rule as industry groups press for fewer covered organisations, narrower incident triggers and less information in each filing.

The rule implements the 2022 Cyber Incident Reporting for Critical Infrastructure Act, known as CIRCIA.

The law requires covered critical infrastructure operators to notify the federal government of major cyber incidents within 72 hours and report ransomware payments within 24 hours.

Reporting Scope Remains Contested

CISA's 2024 proposal estimated that more than 300,000 entities could fall within the rule.

Industry representatives told four agency town halls in June that the proposed scope could include too many organisations and incidents.

Grant MacIntyre of the Auto Care Association argued that the rule reaches too many companies.

Insurance representatives sought exclusions for parts of their sector, while the Nuclear Energy Institute wanted coverage limited to operators already subject to Nuclear Regulatory Commission cyber-reporting requirements.

Small-business treatment is another point of dispute.

According to Douglas Leigh of the Alliance for Chemical Distribution, the proposed size-or-sector test could still pull small chemical distributors into several covered categories.

Samantha Burch of the health insurance association AHIP urged CISA to collect only the information needed for accurate and rapid reporting.

Industry Seeks Narrower Incident Triggers

Participants also questioned which events should trigger a filing.

Tim Pospisil of Nebraska Public Power District warned that broad language could require reports for routine probes of a firewall even when no compromise occurs.

Several groups opposed requirements to disclose details about an affected organisation's security controls.

Their comments frame the central implementation choice: how much information CISA needs for national warning and defensive action without diverting incident-response teams into excessive paperwork.

September Target Follows Earlier Delays

CISA missed the original October 2025 deadline and a later May target.

The administration's regulatory agenda now lists September for completion, although several industry sources told CyberScoop they doubted that schedule would hold.

Congress has also pressed the agency to finish.

In its fiscal 2027 Department of Homeland Security report, the House Appropriations Committee expressed concern about the delays and urged publication after stakeholder review.

The timetable follows a process that began with the 2022 law and moved to a proposed rule in 2024.

That proposal was intended to define covered entities, covered incidents and the information required in a report before the obligations take effect.

CISA Says Rulemaking Continues

Acting CISA director Nick Andersen told a town hall that the agency does not view CIRCIA as a compliance checklist.

He said faster reporting is intended to improve visibility into cyber threats and support warnings and defensive measures for critical infrastructure.

A CISA spokesperson attributed the rulemaking delays partly to funding lapses and confirmed that work on the final rule continues.

The agency also said 1,200 critical infrastructure stakeholders attended its town halls and directed future updates to CISA.gov/CIRCIA and the federal regulatory agenda.

CISA does not identify which industry requests it will accept and has not confirmed that the September target will hold.

The unresolved items are the final coverage threshold, the incidents that trigger a filing and the information affected organisations must provide.

Share this article
inXf

Related articles

More
OpenAI Backs State AI Safety Baseline As Federal Cyber Tests Near
Capital & Policy

OpenAI Backs State AI Safety Baseline As Federal Cyber Tests Near

OpenAI said California, New York and Illinois have advanced frontier AI safety legislation with shared disclosure, incident-reporting and audit elements, while a federal cyber-testing framework is still targeted for early August.

Khalifa Fund Cybersecurity Program Starts Without Funding Or Cohort Details
Capital & Policy

Khalifa Fund Cybersecurity Program Starts Without Funding Or Cohort Details

Khalifa Fund and the UAE Cyber Security Council have launched a national program for cybersecurity startups with CyberE71 support. The announcement names mentorship, investor access and partnership support, but gives no funding amount, cohort size or application timetable.

US Visa Restrictions Extend Cyber Scam Crackdown To Family Members
Capital & Policy

US Visa Restrictions Extend Cyber Scam Crackdown To Family Members

The State Department is using visa restrictions against people linked to cyber-enabled scams and sextortion, with CyberScoop reporting that immediate family members can also face limits under the new policy.

India Tells WhatsApp To Pause Usernames Rollout During Fraud Review
Capital & Policy

India Tells WhatsApp To Pause Usernames Rollout During Fraud Review

India's electronics ministry has told WhatsApp not to launch usernames in India until consultations finish. The notice gives the Meta-owned platform three days to explain how the feature would address fraud and impersonation risks.

Taktile Raises $110 Million As Banks Test AI Agent Oversight
Fintech & Digital Payments

Taktile Raises $110 Million As Banks Test AI Agent Oversight

Taktile raised $110 million for financial-services AI agents, PYMNTS reported. Bank customers, valuation, benchmark methodology or regulator-reviewed deployment evidence remain outside the public record.

Ramp’s $750M Round Turns AI Spend Controls Into a Fintech Growth Test
Fintech & Digital Payments

Ramp’s $750M Round Turns AI Spend Controls Into a Fintech Growth Test

Ramp raised $750 million at a $44 billion valuation as the corporate expense platform broadens from spend management into payments, procurement, fraud detection and accounting. The company said it has more than $1 billion in annualized revenue, over 70,000 customers and more than $3 billion raised in total. The practical question is whether token-spend controls and AI-agent payments become durable revenue lines rather than investor-friendly positioning.

NPCI Sees AI In UPI Growth While App-Concentration Deadline Still Looms
Fintech & Digital Payments

NPCI Sees AI In UPI Growth While App-Concentration Deadline Still Looms

NPCI chief Dilip Asbe said AI could help UPI reach new users, detect fraud and support credit, while India’s payment ecosystem still faces a December 31, 2026 app-concentration deadline.

Private Equity Pushes India GCCs From Cost Centers Into AI Buildouts
Economy

Private Equity Pushes India GCCs From Cost Centers Into AI Buildouts

Private equity-backed and mid-market companies are driving a new wave of India global capability centres, using them for AI, product engineering, cybersecurity and platform work rather than only cost arbitrage.

Keep Reading

More Stories

Latest
Ropedia Raises US$22 Million For Physical AI Data LayerAIJul 26, 2026Ropedia Raises US$22 Million For Physical AI Data LayerSingapore-based Ropedia has raised US$22 million in pre-Series A funding, e27 reported, as robotics developers look for data that records motion, depth, audio and human interaction rather than only online text.Azure West US Outage Exposes Fiber-Maintenance Routing RiskCloud & Data CentersJul 26, 2026Azure West US Outage Exposes Fiber-Maintenance Routing RiskThe Register reported that Microsoft’s West US Azure region was disrupted for almost five hours after routine fiber-related maintenance removed more routes than intended. Microsoft’s preliminary review said 27 services were affected before full recovery at 19:41 UTC on July 23.Coinbase Adds x402 Payments For AI Agent TransactionsFintech & Digital PaymentsJul 26, 2026Coinbase Adds x402 Payments For AI Agent TransactionsCoinbase Business users will be able to accept payments from AI agents through x402, while exchange users get live order views and developers get an SDK.Microsoft Azure AI Deals Add Cobalt Chips And French CapacityCloud & Data CentersJul 26, 2026Microsoft Azure AI Deals Add Cobalt Chips And French CapacityMicrosoft expanded Azure AI agreements with Databricks and Mistral, combining Cobalt processor adoption, Microsoft product integrations and Mistral-operated French data-centre capacity for customers with control and residency requirements.AI Kill Switch Bill Would Give Homeland Security Emergency Model ControlCapital & PolicyJul 26, 2026AI Kill Switch Bill Would Give Homeland Security Emergency Model ControlThe proposed AI Kill Switch Act would give Homeland Security emergency authority to slow, limit or shut down covered frontier AI systems, while exempting red-team incidents such as the OpenAI sandbox escape that triggered the debate.Japan Funds Noetra’s 140MW Physical AI Data CentreCloud & Data CentersJul 26, 2026Japan Funds Noetra’s 140MW Physical AI Data CentreTech Wire Asia reported that Japan is funding Noetra to build domestic physical AI models around a 140MW FRONTia facility using Nvidia Rubin GPUs, while model access terms remain open.Etched Raises $300 Million As $1 Billion Pre-Orders Test Inference Rack PlanChips & SemiconductorsJul 26, 2026Etched Raises $300 Million As $1 Billion Pre-Orders Test Inference Rack PlanEE Times reported that Etched raised $300 million at a $10 billion pre-money valuation and has $1 billion in pre-orders, but the AI chip startup has not made public performance figures for racks due to ship this summer.Nvidia-SK AI Deal Carries $500 Billion Value With Few Build DetailsChips & SemiconductorsJul 26, 2026Nvidia-SK AI Deal Carries $500 Billion Value With Few Build DetailsTom's Hardware reported that Nvidia and SK Group signed letters of intent for a strategic relationship valued at more than $500 billion, anchored by SK Telecom's planned 2-gigawatt South Korea AI data centre and a long-term SK hynix memory supply agreement.Upstart Bank Charter Approval Leaves Fed And FDIC Steps PendingFintech & Digital PaymentsJul 25, 2026Upstart Bank Charter Approval Leaves Fed And FDIC Steps PendingUpstart received conditional OCC approval to form a national bank, but the AI lending marketplace still needs deposit-insurance and bank-holding-company approvals before the charter can operate.US Tech Letter Warns Against Broad Open-Weight AI RestrictionsCapital & PolicyJul 25, 2026US Tech Letter Warns Against Broad Open-Weight AI RestrictionsCNBC coverage identified Nvidia, Microsoft, Meta, Palantir and more than 20 other companies urging policymakers to avoid broad restrictions on open-weight AI models as Chinese systems and distillation claims draw White House scrutiny.Ajman Uses Agentic AI For Headless Trade Licence RenewalAIJul 25, 2026Ajman Uses Agentic AI For Headless Trade Licence RenewalEconomy Middle East reported that Ajman completed the UAE’s first government transaction to renew a trade licence using Agentic AI, starting with AjmanOne notifications, cross-entity lease checks and a headless service model.Bond Investors Price AI Capex As Credit RiskCapital & PolicyJul 25, 2026Bond Investors Price AI Capex As Credit RiskCNBC reported that bond-market anxiety is rising around AI capital spending, with hyperscaler spreads widening, Oracle CDS trading at a multi-year high and Meta data-center financing facing higher borrowing costs.