Skip to main content
Compliance

CISA Faces Industry Pushback on Cyber Incident Reporting Rule

Formal meeting setting with attendees seated around a podium or conference table, surrounded by natural daylight from large…

"The rule includes too many companies," said Grant MacIntyre, director of regulatory affairs and senior attorney at the Auto Care Association.

What industry told CISA at four June town halls

CISA published transcripts last week from four June town halls where the agency sought feedback on the delayed rule implementing the 2022 Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA). Several consistent themes emerged: trade groups urged a smaller scope for the rule, fewer incidents required to be reported, and narrower data collection when reporting does occur. CISA estimated that more than 300,000 entities will be subject to its requirements; the town halls drew roughly 1,200 critical infrastructure stakeholders, CISA’s spokesperson said.

Who wants carve-outs or narrower categories

Some industries pushed for wholesale removal from the rule or for narrower inclusion lists. Two different groups representing elements of the insurance sector argued for removal entirely, the transcripts show. The Nuclear Energy Institute asked CISA to limit coverage to those already subject to Nuclear Regulatory Commission cybersecurity reporting requirements. Douglas Leigh, vice president of legislative affairs for the Alliance for Chemical Distribution, warned that "the current approach where an entity qualifies either by size or by sector effectively negates the intended limitation on small businesses," adding that "in chemical distribution, even small entities could be swept in under multiple cyber categories."

Debate over what incidents and what data must be reported

Industry participants repeatedly pushed CISA to minimize what information the agency will seek and to avoid reporting requirements triggered by routine or exploratory activity. Samantha Burch, vice president of technology public policy at government affairs at AHIP, urged CISA to "seek to collect the least amount of information possible in the easiest to report fashion to facilitate information accuracy and reporting speed." Several commenters said incident reports should not require disclosures about affected entities' security measures. Tim Pospisil, chief security officer for Nebraska Public Power District, expressed concern that the rule could demand reports "every time some foreign entity tickles our firewall, whether they do anything or not, if they just do a ping or a search," a burden he said could be "extremely burdensome."

CISA’s stated purpose, schedule, and industry skepticism

Nick Andersen, the acting director of CISA, framed CIRCIA as an operational tool rather than a compliance checkbox: "CISA does not view CIRCIA as simply a check-the-box compliance exercise," he said, adding that timely reports of "covered cyber incidents and ransom payments" will allow the agency to "provide timely and actionable defensive and eviction measures to your network defenders." CISA published a proposed rule in 2024 to define terms such as "covered cyber incident," but it missed an October 2025 deadline for finalization and then missed a May reset target date. The administration now lists completion in September in the Unified Agenda of Regulatory and Deregulatory Actions; multiple industry sources said they are skeptical that CISA can meet that target. One industry source said, "It could slip," while also predicting "they’re going to try."

CISA’s spokesperson acknowledged setbacks: "CISA recognizes the importance of CIRCIA, however, multiple funding lapses impacted CISA’s ability to conduct rulemaking activity for CIRCIA. CISA continues to work on the final rule," the statement said, reiterating that CISA will communicate updates via CISA.gov/CIRCIA and the Office of Information and Regulatory Affairs’ Unified Agenda. The House Appropriations Committee has signaled impatience: in the committee report for its fiscal 2027 Department of Homeland Security spending bill the panel wrote it "is concerned about delays in publishing the final CIRCIA rule and urges CISA to finalize it promptly following stakeholder review and feedback."

How technologists, regulators, and affected enterprises are positioned

  • Technologists and security teams: Will watch for whether the final rule enables the "timely and actionable defensive and eviction measures" Andersen described, while also preparing for potential new reporting workflows if CISA narrows the information requested.
  • Policymakers and regulators: The House Appropriations Committee’s report and the Unified Agenda listing put near-term pressure on CISA to finish the rule; CISA has said it will continue updates on CISA.gov/CIRCIA and the OIRA Unified Agenda.
  • Affected enterprises and procurement leaders: Small businesses and companies in sectors such as chemical distribution and nuclear energy remain concerned about being "swept in" by sector or size tests, and several groups pressed CISA to limit what is required to report—particularly requests for details about security measures.

Industry participants expressed guarded optimism in parts: Henry Young, senior director of policy for the Business Software Alliance, said town halls combined with a regulatory posture emphasizing "common sense regulation" suggested CISA might narrow the list of data elements to "a few of the most important pieces of information" so companies could "act quickly and actually respond to an incident rather than completing lots of paperwork." Yet many speakers said they have received little indication from CISA about which town-hall suggestions the agency will adopt, and some traced delays to earlier policy choices, noting "some of the delays trace to the Trump administration, given the massive cuts to CISA’s personnel."

With CISA promising continued outreach and a September target on the Unified Agenda, the central question remains factual and immediate: will the final rule substantially narrow who is covered and what must be reported, or will it keep the broader scope that prompted sustained industry pushback? CISA’s next public steps on CISA.gov/CIRCIA and the OIRA Unified Agenda will be the clearest indicators.

The original CyberScoop story