CISA Finalizes Cyber Incident Reporting Rules for Critical Infrastructure

CISA Finalizes Cyber Incident Reporting Rules for Critical Infrastructure

First seen 16 Jun 2026, 16:27 UTC PerkinscoieNews.BloomberglawClarkhillNextgovFeeds.Feedburner+4 88% similarity 27.9

Article Content

Browse articles
ThreatCluster

The Cybersecurity and Infrastructure Security Agency (CISA) is finalizing rules under the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA), requiring covered entities to report cyber incidents within 72 hours and ransom payments within 24 hours. The rules will apply to entities in critical infrastructure sectors, including healthcare and energy, even if they do not own critical assets. During town hall meetings, industry representatives expressed concerns about overlapping reporting requirements and the burden of detailed reporting. CISA is accepting feedback on the proposed rules, which are expected to significantly impact incident response planning for affected companies. The rules aim to enhance national cybersecurity by ensuring timely reporting of significant cyber incidents.

Key Points: • CISA's new rules require reporting of cyber incidents within 72 hours. • Entities in critical infrastructure sectors must comply, regardless of asset ownership. • Industry representatives are advocating for limits on the reporting requirements.

ThreatCluster AI How this analysis works

Timeline

2026-06-15
CISA conducts town hall meetings
CISA held meetings to discuss finalizing rules for reporting cyber incidents under CIRCIA, gathering feedback from industry stakeholders.
Perkinscoie
2026-06-16
Industry calls for limits on reporting rules
At a town hall, representatives from health and auto sectors urged CISA to ease the proposed cyber incident reporting requirements.
News.Bloomberglaw

Community

Browse all →