CISA plans sector town halls on CIRCIA cyber reporting rule

THE BRIEF
CyberScoop reports that the Cybersecurity and Infrastructure Security Agency (CISA) plans to hold sector-by-sector town halls in the coming weeks on a proposed cyber incident reporting regulation. The sessions are intended to gather industry feedback on a stalled rule being advanced under the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), enacted by Congress in 2022. CISA says the meetings will give external stakeholders a limited additional opportunity to comment on the proposal’s scope and burden. The law requires covered critical infrastructure owners and operators to notify CISA within 72 hours after a significant cyberattack and within 24 hours after making a ransomware payment. The report says disagreement remains over which entities the regulation would cover and how its requirements would apply. Meeting dates are expected to be published in the Federal Register, according to the report. CyberScoop’s account describes a continuing feedback process; it does not establish a final rule or implementation date.
WHY IT MATTERS
CIRCIA could shape how covered critical infrastructure organizations identify, document, and report significant cyberattacks and ransomware payments to CISA. The planned town halls indicate that the scope and reporting burden remain under discussion. Organizations may need to follow the feedback process closely because coverage, definitions, and operational expectations are not yet settled in the reported account. Until CISA finalizes the rule, teams should distinguish existing obligations from proposed requirements and avoid treating the town halls as evidence that implementation details have been decided.
WHO SHOULD CARE
Critical infrastructure owners and operators, security leaders, incident-response teams, legal and compliance staff, and organizations tracking federal cyber regulations should monitor the town halls and forthcoming Federal Register notices.
WHAT TO DO NOW
- Monitor the Federal Register for the announced town-hall dates and relevant CISA materials.
- Review how your organization currently identifies significant cyberattacks and records ransomware payments.
- Map internal legal, security, and incident-response stakeholders who may need to assess the proposal’s scope and reporting burden.
- Prepare focused questions or comments on which entities and activities the proposed rule would cover.