Dossier
Cyber Incident Reporting for Critical Infrastructure Act
Coverage of Cyber Incident Reporting for Critical Infrastructure Act in the Nexus archive.
- Industry’s message on CIRCIA: Please ask us fewer questions about cyberattacks
Industry groups have consistently urged CISA to reduce the scope of the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), advocating for fewer companies to be covered, fewer incidents reported, and less detailed information shared. CISA has delayed finalizing the rule multiple times, with industry sources doubting a September 2025 completion timeline. The law mandates reporting major cyberattacks within 72 hours and ransomware payments within 24 hours to enhance federal information sharing.