Cybersecurity Policy Report, Comment Deadline Extended for Cyber Incident Reporting NPRM, (May 3, 2024)
The deadline for comments on proposed cyber incident reporting rules will be extended by 30 days, from June 3 to July 3, according to a Federal Registernotice due to be published Monday.
Several business groups had requested an extension, arguing that the complexity and scope of the proposed rules warranted a longer comment period (CPR, April 5).
“Requesters cited the complexity inherent in addressing cybersecurity within critical infrastructure sectors, the potential impact of this rulemaking on each critical infrastructure sector, and the need for additional time to sufficiently review and comment,” according to the Federal Register notice.
The Cybersecurity and Infrastructure Security Agency (CISA) recently published a notice of proposed rulemaking to implement the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), offering expansive definitions of entities and incidents that should be covered by the rules (CPR, March 27).
Representatives of trade associations for the telecom, electricity, and financial services sectors this week told the House Homeland Security Committee’s cybersecurity and infrastructure protection subcommittee that the proposed rules went too far (CPR, May 1). CISA is due to publish the final rules next August.
News: DataSecurity FederalLegislation