Saturday, October 3, 2026

CISA Sends CIRCIA Reporting Final Rule to OMB

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a final rule from CISA on “Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements”. The notice of proposed rulemaking for this action was published on April 4th, 2024. The Congressional deadline {6 USC 681b(b)(2)} for publishing the final rule was October 4th, 2025. 

According to the 2026 Unified Agenda entry for this rulemaking:  

“The Cybersecurity and Infrastructure Security Agency (CISA) will finalize regulations to implement certain aspects of the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA).  Specifically, CIRCIA directs CISA to develop and implement regulations requiring covered entities to submit reports to CISA regarding covered cyber incidents and ransom payments.  CISA published the NPRM on April 4, 2024. CISA received significant public comments on the proposed rule, many of which emphasized the need to reduce the scope and burden of the proposed reporting requirements, improve harmonization of CIRCIA with other federal cyber incident reporting requirements, and clarify terms. CISA is considering the public comments and examining options for the rulemaking. Additional information about this rulemaking is available at www.cisa.gov/circia.” 

NOTE: The link reported above does not work, it should read “https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/cyber-incident-reporting-critical-infrastructure-act-2022-circia” 

An interesting problem that CISA had to address during the crafting of this regulation is defining who would be required to submit the cyber incident reports. The statute uses the term ‘covered entity’ in setting out the reporting requirement and then give the following broad and vague definition for that term {6 USC 681(4)}: 

“The term ‘covered entity’ means an entity in a critical infrastructure sector, as defined in Presidential Policy Directive 21, that satisfies the definition established by the Director in the final rule issued pursuant to section 681b(b) of this title.” 

I discussed the approach that CISA took to refine this definition in the NPRM. It will be interesting to see what changes CISA may have made in the final rule. 

No comments:

 
/* Use this with templates/template-twocol.html */