Industry’s message on CIRCIA: Please ask us fewer questions about cyberattacks
Industry groups who spoke at town halls hosted by the Cybersecurity and Infrastructure Security Agency about a pending cyber incident notification regulation had a few consistent messages:
We want this to apply to fewer of us. We don’t want to report to you on as many incidents. We want to give you less information when we do.
CISA last week published transcripts from the town halls, where the agency sought feedback on the delayed rule for the 2022 Cyber Incident Reporting for Critical Infrastructure Act — perhaps the most significant cyber legislation Congress has ever passed. That law required critical infrastructure owners to report major cyberattacks to the federal government within 72 hours, and ransomware payments within 24 hours.
The law was designed to let the feds share information about significant incidents more widely to prepare other would-be victims. CISA published a proposed rule on the law in 2024 to define terms like “covered cyber incident” and more, and industry groups have persistently registered their objections since then.
CISA missed the October 2025 deadline for finalizing the rule, then missed a May reset target date, and now the administration says the rule will be completed in September.
Some industry sources told CyberScoop they consider that unlikely. Most also haven’t received any indications from CISA about how much of the town hall feedback it intends to embrace, they said.
Companies, incidents, information
Those town hall comments over the course of four June dates were often very direct.
“The rule includes too many companies,” said Grant MacIntyre, director of regulatory affairs and senior attorney at the Auto Care Association. CISA estimated that more than 300,000 entities will be subject to its requirements.
Some industries advocated for their removal entirely, such as two different groups representing elements of the insurance sector. Some sought to reduce the number affected within their sector, such as the Nuclear Energy Institute wanting the list cut down to those already subject to Nuclear Regulatory Commission cybersecurity reporting requirements.
While CISA wrote the regulation with the intention to avoid overburdening small businesses, some feared it wouldn’t work that way in practice.
“The current approach where an entity qualifies either by size or by sector effectively negates the intended limitation on small businesses,” said Douglas Leigh, vice president of legislative affairs for the Alliance for Chemical Distribution. “In chemical distribution, even small entities could be swept in under multiple cyber categories.”
Where the rule specifies what kind of data organizations should report in a major incident, CISA should “seek to collect the least amount of information possible in the easiest to report fashion to facilitate information accuracy and reporting speed,” said Samantha Burch, vice president of technology public policy at government affairs at AHIP, a health insurance industry trade association.
Many, for instance, argued the report should not include information on the affected entities’ security measures.
Others worried about what kind of incidents would trigger reporting requirements.
“My big concern is that you’re going to be asking us to report incidents on every time some foreign entity tickles our firewall, whether they do anything or not, if they just do a ping or a search,” said Tim Pospisil, chief security officer for Nebraska Public Power District. “And that could be extremely burdensome.”
Industry Expectations
One industry representative told CyberScoop that CISA’s willingness to hold town halls, combined with the Trump administration strategy emphasizing “common sense regulation,” was a good sign about where the rule might be heading.
‘They are not picking up on the Biden administration’s approach and tweaking it. They’re thinking, ‘What are the specific pieces of information we need during a cyber incident to help critical infrastructure companies respond?’” said Henry Young, senior director of policy for the Business Software Alliance. “In general, industry is optimistic that what we’ll end up with are a few of the most important pieces of information, so that in the emergency, companies can act quickly and actually respond to an incident rather than completing lots of paperwork.”
But multiple industry sources said they haven’t gotten many indications about CISA’s intentions. Nor are they optimistic CISA can meet the September target date in the Unified Agenda of Regulatory and Deregulatory Actions.
“It could slip,” one said. “But I think they’re going to try.”
That industry source said they’d like to see a proposal from CISA before it cements anything forever.
Another industry source said it’s hard to trust the September date given past CISA delays, some of which aren’t CISA’s fault, such as dealing with multiple government shutdowns. Some of the delays trace to the Trump administration, given the massive cuts to CISA’s personnel.
Congress is also getting impatient.
The House Appropriations Committee “is concerned about delays in publishing the final CIRCIA rule and urges CISA to finalize it promptly following stakeholder review and feedback,” the panel wrote in the committee report for its fiscal 2027 Department of Homeland Security spending bill.
It’s a much different world than when CISA began writing the rule, something the agency also has to take into account now.
“AI has fundamentally changed the playing field,” the source said. “When this was set up, we didn’t even have the first generation of ChatGPT. We’re now in a mythos class environment.” That’s changed “how quickly we can identify threats, mitigate them, the level of human intervention, potential machine engagement.”
While CISA might have good intentions, past interactions give cause for skepticism about how capable it is of working collaboratively with industry, the source said.
Another industry source said conversations with CISA suggest the agency will look to simplify the regulation to keep it smaller and narrower, then potentially build upon it later.
From CISA’s mouth
Nick Andersen, the acting director of CISA, talked about his overarching intentions with CIRCIA at the town halls.
“CISA does not view CIRCIA as simply a check-the-box compliance exercise,” Andersen said at one. “CIRCIA will enhance visibility into the cyberthreat landscape to enable a robust national early warning capability for critical infrastructure. By quickly reporting covered cyber incidents and ransom payments to CISA, we will be able to provide timely and actionable defensive and eviction measures to your network defenders.”
Asked by CyberScoop about next steps for CIRCIA, and how it might incorporate the industry feedback, a spokesperson provided a statement.
“CISA recognizes the importance of CIRCIA, however, multiple funding lapses impacted CISA’s ability to conduct rulemaking activity for CIRCIA. CISA continues to work on the final rule,” the spokesperson said, adding that 1,200 critical infrastructure stakeholders attended the town halls. “CISA will continue to communicate updates on the CIRCIA rulemaking process and timeline through CISA.gov/CIRCIA and the Office of Information and Regulatory Affairs’ Unified Agenda of Regulatory and Deregulatory Actions.”