Cybersecurity Policy Report, CISA Restarts Stakeholder Engagement on Cyber Incident Reporting Rules, (May 26, 2026)
The Cybersecurity and Infrastructure Security Agency will hold four virtual “town hall” meetings next month to gather additional stakeholder input as the agency attempts to finish work on a cyber incident reporting rulemaking, CISA announced today.
The town halls were originally scheduled for March and April but were canceled due to CISA’s 77-day shutdown (CPR, March 10). The rescheduled meetings will give “external stakeholders a limited additional opportunity to provide input on refining the scope and burden” of a rulemaking required by the 2022 Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), CISA said in a notice published in today’s Federal Register (91 Fed Reg 30498).
CIRCIA required CISA to issue final rules by Oct. 4, 2025, but CISA missed that deadline and said it would issue rules by the end of this month, which now seems unlikely.
One reason for the delay, other than the shutdown, is that the notice of proposed rulemaking issued for public comment in 2024 was widely criticized by members of Congress and the private sector for its overly broad definitions of the entities that would be subject to the rules and the types of cyber incidents that would be reportable.
CIRCIA generally requires critical infrastructure entities to disclose significant cyber incidents within 72 hours and ransomware payments within 24 hours. The disclosures would be confidential but would help CISA track cyber attack campaigns and warn critical infrastructure operators about imminent threats.
Under the revised town hall schedule, CISA will hold two general town halls on June 15 and 17 and sector-specific town halls on other dates, including the communications and health care sectors on June 16 and the financial services sector on June 18. “All town hall meetings are tentatively scheduled to take place from 11:30 a.m. to 3:30 p.m. Eastern Time,” CISA said. Participants will be required to register at least two days prior to each town hall at www.cisa.gov/circia.
“CISA received a significant number of public comments on the proposed rule, many of which emphasized the need to reduce the scope and burden, improve harmonization of CIRCIA with other federal cyber incident reporting requirements, and ensure clarity,” CISA noted on its CIRCIA rulemaking web page.
“During the town hall meetings, CISA welcomes any specific, actionable improvements that CISA could implement in the Final Rule to clarify or reduce the burden of CIRCIA’s regulatory requirements while enhancing the federal government’s visibility into the cyber threat landscape for critical infrastructure sectors,” it added.
News: FederalLegislation DataSecurity ESGNews