VYPR
advisoryPublished Oct 2, 2026· 1 source

CISA Finalizes Critical Infrastructure Cyber Incident Reporting Rule, Sends to White House

CISA has submitted its final rule for the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) to the White House for review, aiming to standardize cyberattack reporting for essential services.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has taken a significant step towards implementing the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) by submitting its final rule to the White House Office of Management and Budget (OMB) for review. This submission, which occurred on Thursday, follows a missed September target and marks a crucial milestone in establishing federal reporting requirements for cyberattacks impacting the nation's critical infrastructure.

The CIRCIA rule, mandated by Congress in 2022, aims to create a unified framework for reporting substantial cyber incidents and ransom payments within 72 and 24 hours, respectively. The proposed rule, initially released in 2024, was expected to affect nearly 300,000 organizations across 16 critical infrastructure sectors. CISA has faced delays in finalizing the rule, partly due to extensive stakeholder feedback and a desire to minimize unnecessary burdens on covered entities.

Industry stakeholders, particularly defense contractors, are closely watching the rule's finalization. These entities already face stringent reporting obligations to the Pentagon, often within a similar 72-hour timeframe. The primary concern is whether existing defense reporting mechanisms will satisfy the new federal mandates under CIRCIA, or if a duplicative reporting regime will be imposed. The current proposal allows for reports filed with other federal agencies to satisfy CIRCIA requirements, but only if formal agreements are established between CISA and those agencies.

Experts like Jacob Horne, chief cybersecurity evangelist at Summit 7, note that there is currently "zero indication that such an agreement has been or will be reached" with the Department of Defense. Existing defense reporting requirements are narrowly focused on incidents involving controlled unclassified information, potentially differing significantly from the broader scope of CIRCIA. This divergence raises concerns that a single report may not adequately meet both sets of obligations.

Furthermore, CIRCIA mandates follow-up reporting as new details emerge and requires two years of incident data retention, contrasting with the 90-day retention period under the Defense Federal Acquisition Regulation Supplement (DFARS). These differences highlight the potential for increased compliance overhead for defense contractors, many of whom are still grappling with existing cybersecurity certifications like the Cybersecurity Maturity Model Certification (CMMC).

CISA has acknowledged the concerns regarding overlap and burden, with Acting Director Nick Andersen stating the agency values feedback aimed at implementing the rule with "minimal unnecessary burden." The White House's National Cyber Director, Sean Cairncross, has also emphasized a "tremendous partnership" with CISA on the rule, aiming to provide clarity to industry.

The submission to OMB suggests that the final rule could be published before the end of the year, according to legal experts. The extensive review process, involving input from numerous sectors and congressional members, underscores the complexity of harmonizing federal cybersecurity reporting requirements. The success of CIRCIA will hinge on CISA's ability to effectively integrate with existing reporting structures and provide clear guidance to critical infrastructure operators.

Synthesized by Vypr AI