Skip to content

White House cyber leader says CIRCIA will harmonize incident reporting

Federalnewsnetwork • September 29, 2026

National Cyber Director Sean Cairncross said "a lot of attention" has gone into ensuring the final incident reporting rules fit into existing requirements.

A top White House official says his office has worked with agencies to ensure a highly anticipated final rule for the Cyber Incident Reporting for Critical Infrastructure Act is aimed at “harmonizing the reporting structure” across government.

National Cyber Director Sean Cairncross discussed the impending CIRCIA final rule during a speech recorded Tuesday morning for an event hosted by the USTelecom Association. The final rule is expected to be issued by the Cybersecurity and Infrastructure Security Agency this fall.

“We have a tremendous partnership with [the Department of Homeland Security] and CISA on this,” Cairncross said. “There is a lot of attention going into moving this forward and providing clarity to industry and harmonizing the reporting structure, which I think will go a long way.”

CISA previewed plans to potentially issue the final CIRICA rule as soon as this month as part of the latest Unified Agenda. The cyber agency held a series of townhalls over the summer to get feedback on the final regulations for the law, which Congress passed in 2022.

The reporting rules will span 16 critical infrastructure sectors, ranging from electric utilities and water systems to hospitals and chemical facilities. Under the regulations, covered entities will have to report cyber incidents to CISA within 72 hours and ransomware payments within 24 hours.

But draft CIRCIA rules released by CISA in 2024 have been criticized by industry groups, members of Congress and other stakeholders for being overly broad and ambiguous, as well as unnecessarily overlapping with existing incident reporting rules.

A Government Accountability Office report released in July found 80 of 117 incident reporting regulations, or roughly 70%, had the same kind of requirements, including incident reporting, as another regulation.

GAO found 37 federal agencies have issued cybersecurity regulations that cut across nine critical infrastructure sectors. They range from sector-specific regulations, to cross-cutting rules, like the Securities and Exchange Commission’s 2023 cybersecurity disclosure rules for public companies.

Cairncross’s are the latest sign that the Office of the National Cyber Director has been involved in ensuring the final CIRCIA rules fit into a patchwork of existing cyber incident reporting rules. The law creating ONCD put it in charge of streamlining cyber regulations.

In addition to CIRCIA, Cairncross also mentioned the 2023 SEC rules.

“There’s the SEC rule, for example, looking for ways to build in safe harbors to engage law enforcement,” he said.

Overall, Cairncross said ONCD wants to hear from industry on “where friction points exist, and then we will go knocking them down.”

“Form has to follow a function, and the function is the protection of systems and our citizens,” he said. “One of the things that we frequently run into is there is an incident, and whomever it is has a hesitation with engaging law enforcement for a variety of regulatory or liability reasons, and so looking for ways to clear that brush, so we can get engaged on the law enforcement side to track, figure out where this is coming from, what happened, and then we can get onto the business of getting after that actor, without standing in the way of remediation.”

Follow @jdoubledayWFED

Extracted Entities