Advertisement
Advertisement
Advertisement
25 July 2026·5 min read·By Konrad Weber

Industry Pushes Back on CIRCIA Reporting Rules

Industry groups are urging CISA to narrow the scope and reduce reporting requirements for the pending CIRCIA rule.

Industry Pushes Back on CIRCIA Reporting Rules

CIRCIA reporting rules face mounting industry pushback

CIRCIA is the rift's focal point. The Cybersecurity and Infrastructure Security Agency is working to finalize a mandate that would require critical infrastructure owners to report major cyberattacks within 72 hours and ransom payments within 24 hours. But industry groups are signaling that the current regulatory trajectory is too broad and demanding.

Too many companies in the net

The net is cast too wide. But recent town hall meetings hosted by the agency revealed deep-seated concerns regarding the scale of the proposed requirements, and with an estimated 300,000 entities subject to these rules, many organizations feel it's far too broad and unfairly inclusive. Some industry representatives argued that the criteria for inclusion effectively capture small businesses that were intended to be exempted from the administrative burden.

Market Context: According to StrongDM and CrowdStrike, nearly 47% of businesses with fewer than 50 employees had no cybersecurity budget in 2025.

four people all on laptops, two men and two women, listen to person talking in a board meeting

The following industries have expressed specific concerns about the scope of the rule:

  • The insurance sector, where multiple groups have advocated for a total removal from the requirements.
  • The nuclear energy industry, which proposed limiting the scope to entities already reporting to the Nuclear Regulatory Commission.
  • Chemical distribution firms, which fear that even small operators could be pulled into compliance across multiple cyber categories.

The reporting burden

But the fight isn't just about who reports. There's serious friction over what information must be shared, driven by a fear that the mandate will force companies to submit data on inconsequential events like basic network pings or routine searches from foreign entities. It could overwhelm everyone. This avalanche of low-level reporting threatens to bury both the companies and the agency.

My big concern is that you are going to be asking us to report incidents on every time some foreign entity tickles our firewall, whether they do anything or not, if they just do a ping or a search. And that could be extremely burdensome.

, Tim Pospisil, chief security officer for Nebraska Public Power District.

Targets delayed and goals unclear

The timeline for finalizing these rules has slipped repeatedly. It's a frustrating pattern. After missing an initial deadline in October 2025 and a subsequent target in May, the current administrative goal is set for September, but industry analysts remain skeptical that this date is achievable given the history of delays and the complexity of the task. So some observers point to past government shutdowns and personnel reductions as contributing factors to the current logjam.

A changing technological environment

The rise of artificial intelligence has complicated rulemaking. It's a big problem. Because the technology environment has evolved significantly since the law was first drafted, the challenge of defining how quickly threats are identified and mitigated has grown, and many are still unsure how to handle it. Officials maintain the regulation is not a box-ticking exercise, but many industry participants feel they've received little clarity on whether their feedback will actually shape the final outcome.

Seeking a common sense approach

Some stakeholders see a glimmer of optimism. They believe the agency is genuinely trying to identify the most critical information required during an emergency, and policy experts say the goal is to ensure companies can prioritize incident response over paperwork. But the lack of transparency about which feedback will be integrated leaves many organizations in a state of uncertainty.

The agency maintains it must work through these challenges. But it's doing so to provide actionable defensive measures to network defenders, who desperately need them, and an open question remains as the September deadline approaches. We can't know yet. Whether the final rule will satisfy both the push for national security and the industry plea for simplicity.

Frequently Asked Questions

What is the CIRCIA reporting rule and what are its key requirements?

CIRCIA is a mandate requiring critical infrastructure owners to report major cyberattacks within 72 hours and ransom payments within 24 hours. The Cybersecurity and Infrastructure Security Agency is working to finalize this rule, but industry groups are pushing back, arguing it is too broad and demanding.

Why are industry groups pushing back against the CIRCIA reporting rules?

Industry groups are concerned that the rule is too broad, capturing up to 300,000 entities, including small businesses intended to be exempted. They also fear the mandate will force reporting of inconsequential events like basic network pings, leading to an overwhelming burden on both companies and the agency.

How have specific industries expressed their concerns about the scope of CIRCIA?

The insurance sector has advocated for total removal from the requirements, while the nuclear energy industry proposed limiting scope to entities already reporting to the Nuclear Regulatory Commission. Chemical distribution firms fear even small operators could be pulled into compliance across multiple cyber categories.

When is the current deadline for finalizing the CIRCIA rules, and why is it uncertain?

The current administrative goal for finalizing the rules is September, but industry analysts are skeptical given repeated delays from an initial deadline in October 2025 and a subsequent target in May. Past government shutdowns and personnel reductions have also contributed to the logjam.

Who is Tim Pospisil and what concern did he raise about the CIRCIA reporting requirements?

Tim Pospisil is the chief security officer for Nebraska Public Power District. He expressed concern that the mandate would require reporting on every instance of a foreign entity tickling their firewall, such as a ping or search, which could be extremely burdensome.

Konrad Weber
Written by
Infosec and Threats Writer

Konrad Weber writes about the security landscape, from emerging threats to the tools that guard against them. He is focused on helping readers understand risk in a connected world.

💬 Comments (0)

Sign in to leave a comment.

No comments yet. Be the first!

Advertisement