SECURITYCYBERSCOOP
Industry’s message on CIRCIA: Please ask us fewer questions about cyberattacks
Industry groups have consistently urged CISA to reduce the scope of the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), advocating for fewer companies to be covered, fewer incidents reported, and less detailed information shared. CISA has delayed finalizing the rule multiple times, with industry sources doubting a September 2025 completion timeline. The law mandates reporting major cyberattacks within 72 hours and ransomware payments within 24 hours to enhance federal information sharing.
Mentioned
Cybersecurity and Infrastructure Security AgencyorganizationCyber Incident Reporting for Critical Infrastructure ActtopicAuto Care AssociationorganizationNuclear Energy InstituteorganizationAlliance for Chemical DistributionorganizationAHIPorganizationinsurance sectortopicNuclear Regulatory Commissionorganization
Related Signal
Adjacent reporting
- CISA to require federal agencies to patch some cyber vulnerabilities within 3 days
- CISA Tells US Agencies to Fix Security Bugs in as Little as 3 Days Thanks to AI Threats
- CISA wants critical infrastructure to operate ‘weeks to months’ in isolation during conflict
- US cyber agency CISA had to build its incident playbook during the incident, agency reveals
- New CISA initiative aims for critical infrastructure to operate offline during cyberattacks
- CISA to transform how it assesses cyber vulnerabilities and risks, Andersen says