logo

CISA Unveils Critical Infrastructure Reporting Rule

ID: 8762cb38-39f2-53b5-9f7c-71d02cbc892b

STIX ID: report--8762cb38-39f2-53b5-9f7c-71d02cbc892b

Feed Name: Security Boulevard

Date Published: 2024-04-05

Date Updated: 2026-04-22

Author: Nathan Eddy

...
...

CISA issued a Notice of Proposed Rulemaking for CIRCIA, proposing that covered critical infrastructure entities report significant cyber incidents within 72 hours and ransom payments within 24 hours to enhance national cybersecurity visibility and response; the NPRM (published April 4, 2024, with comments due by June 3, 2024) is estimated to cost $2.6B and affect over 316,000 entities, with a final rule expected ~18 months later. Stakeholders highlight challenges such as defining “significant” incidents, potential underreporting due to liability concerns, sector-specific maturity gaps, and growing OT/IT convergence risks, recommending phased implementation, support for smaller entities, clear guidance, sector-tailored frameworks, and proactive risk and incident playbooks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.