CISA Unveils Critical Infrastructure Reporting Rule
ID: 8762cb38-39f2-53b5-9f7c-71d02cbc892b
STIX ID: report--8762cb38-39f2-53b5-9f7c-71d02cbc892b
Feed Name: Security Boulevard
CISA issued a Notice of Proposed Rulemaking for CIRCIA, proposing that covered critical infrastructure entities report significant cyber incidents within 72 hours and ransom payments within 24 hours to enhance national cybersecurity visibility and response; the NPRM (published April 4, 2024, with comments due by June 3, 2024) is estimated to cost $2.6B and affect over 316,000 entities, with a final rule expected ~18 months later. Stakeholders highlight challenges such as defining “significant” incidents, potential underreporting due to liability concerns, sector-specific maturity gaps, and growing OT/IT convergence risks, recommending phased implementation, support for smaller entities, clear guidance, sector-tailored frameworks, and proactive risk and incident playbooks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
