logo

CISA’s incident reporting requirements go too far, trade groups and lawmakers say

ID: 70b20778-989a-5e9a-bec9-0c273797afb1

STIX ID: report--70b20778-989a-5e9a-bec9-0c273797afb1

Feed Name: CyberScoop

Date Published: 2024-05-01

Date Updated: 2026-04-21

Author: Christian Vasquez

...
...

Industry and lawmakers at a House cybersecurity subcommittee hearing criticized CISA’s 447-page draft rule requiring critical infrastructure to report significant cyber incidents within 72 hours and ransomware payments within 24 hours, warning its broad scope could overwhelm CISA and burden smaller entities. Witnesses urged clearer definitions, harmonization with existing mandates, and questioned CISA’s subject-matter capacity and data-protection track record, while lawmakers signaled intent to narrow the rule to focus on truly significant incidents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.