Funding
REGULATION WATCH:

CIRCIA Rule Faces September Deadline As Industry Seeks Narrower Filings

Newsroom brief

CISA is working toward a September target for the delayed CIRCIA rule as industry groups seek fewer covered entities, narrower incident triggers and leaner reporting requirements. The law sets 72-hour incident and 24-hour ransomware-payment reporting deadlines, while the proposed rule could cover more than 300,000 entities.

Verified against source materialEdited by SendTech Times Capital & Policy DeskSource: cyberscoop.com
CIRCIA Rule Faces September Deadline As Industry Seeks Narrower Filings

The US Cybersecurity and Infrastructure Security Agency is working toward a September target for its delayed cyber incident reporting rule as industry groups press for fewer covered organisations, narrower incident triggers and less information in each filing.

The rule implements the 2022 Cyber Incident Reporting for Critical Infrastructure Act, known as CIRCIA.

The law requires covered critical infrastructure operators to notify the federal government of major cyber incidents within 72 hours and report ransomware payments within 24 hours.

Reporting Scope Remains Contested

CISA's 2024 proposal estimated that more than 300,000 entities could fall within the rule.

Industry representatives told four agency town halls in June that the proposed scope could include too many organisations and incidents.

Grant MacIntyre of the Auto Care Association argued that the rule reaches too many companies.

Insurance representatives sought exclusions for parts of their sector, while the Nuclear Energy Institute wanted coverage limited to operators already subject to Nuclear Regulatory Commission cyber-reporting requirements.

Small-business treatment is another point of dispute.

According to Douglas Leigh of the Alliance for Chemical Distribution, the proposed size-or-sector test could still pull small chemical distributors into several covered categories.

Samantha Burch of the health insurance association AHIP urged CISA to collect only the information needed for accurate and rapid reporting.

Industry Seeks Narrower Incident Triggers

Participants also questioned which events should trigger a filing.

Tim Pospisil of Nebraska Public Power District warned that broad language could require reports for routine probes of a firewall even when no compromise occurs.

Several groups opposed requirements to disclose details about an affected organisation's security controls.

Their comments frame the central implementation choice: how much information CISA needs for national warning and defensive action without diverting incident-response teams into excessive paperwork.

September Target Follows Earlier Delays

CISA missed the original October 2025 deadline and a later May target.

The administration's regulatory agenda now lists September for completion, although several industry sources told CyberScoop they doubted that schedule would hold.

Congress has also pressed the agency to finish.

In its fiscal 2027 Department of Homeland Security report, the House Appropriations Committee expressed concern about the delays and urged publication after stakeholder review.

The timetable follows a process that began with the 2022 law and moved to a proposed rule in 2024.

That proposal was intended to define covered entities, covered incidents and the information required in a report before the obligations take effect.

CISA Says Rulemaking Continues

Acting CISA director Nick Andersen told a town hall that the agency does not view CIRCIA as a compliance checklist.

He said faster reporting is intended to improve visibility into cyber threats and support warnings and defensive measures for critical infrastructure.

A CISA spokesperson attributed the rulemaking delays partly to funding lapses and confirmed that work on the final rule continues.

The agency also said 1,200 critical infrastructure stakeholders attended its town halls and directed future updates to CISA.gov/CIRCIA and the federal regulatory agenda.

CISA does not identify which industry requests it will accept and has not confirmed that the September target will hold.

The unresolved items are the final coverage threshold, the incidents that trigger a filing and the information affected organisations must provide.

Share this article
inXf

Related articles

More
Open-Weight AI Safety Gap Widens As GLM-5.2 Nears Frontier Models
Capital & Policy

Open-Weight AI Safety Gap Widens As GLM-5.2 Nears Frontier Models

SaferAI found Z.ai GLM-5.2 close to frontier cyber and biology capabilities while lacking published safety commitments, making release controls part of the AI risk debate.

OpenAI Backs State AI Safety Baseline As Federal Cyber Tests Near
Capital & Policy

OpenAI Backs State AI Safety Baseline As Federal Cyber Tests Near

OpenAI said California, New York and Illinois have advanced frontier AI safety legislation with shared disclosure, incident-reporting and audit elements, while a federal cyber-testing framework is still targeted for early August.

Malaysia AI Agency Launch Leaves Sovereign Cloud Question Unassigned
Capital & Policy

Malaysia AI Agency Launch Leaves Sovereign Cloud Question Unassigned

Tech Wire Asia reported that Prime Minister Anwar Ibrahim launched AI Malaysia while raising unresolved sovereign cloud, US CLOUD Act and cybersecurity questions around the country’s AI governance plan.

US Visa Restrictions Extend Cyber Scam Crackdown To Family Members
Capital & Policy

US Visa Restrictions Extend Cyber Scam Crackdown To Family Members

The State Department is using visa restrictions against people linked to cyber-enabled scams and sextortion, with CyberScoop reporting that immediate family members can also face limits under the new policy.

DOJ Trade-Fraud Unit Raises Payment Compliance Exposure
Fintech & Digital Payments

DOJ Trade-Fraud Unit Raises Payment Compliance Exposure

PYMNTS reported that a new U.S. Justice Department trade-fraud section and more than $1 billion in recent task-force recoveries are pushing banks to compare payment flows with customs and supply-chain records.

ADIB Tests Visa Threat Intelligence Before Payment Fraud
Fintech & Digital Payments

ADIB Tests Visa Threat Intelligence Before Payment Fraud

A joint ADIB-Visa announcement covered by Economy Middle East identified Abu Dhabi Islamic Bank as the first bank globally to deploy Visa’s threat-intelligence platform, moving cyber-risk data closer to payment-fraud prevention while external performance evidence remains limited.

Agentic AI Is Moving Fraud Decisions Into the Payment Itself
Fintech & Digital Payments

Agentic AI Is Moving Fraud Decisions Into the Payment Itself

PYMNTS published i2c CEO Amir Wain's argument that agentic AI in payments depends on unified data, audit trails and human oversight before autonomous systems make transaction-level decisions.

Keep Reading

More Stories

Latest
Indosat AI Data Centre Plan Targets 1GW With Ooredoo, Nokia And NvidiaCloud & Data CentersAug 8, 2026Indosat AI Data Centre Plan Targets 1GW With Ooredoo, Nokia And NvidiaData Center Dynamics reported that Indosat, Ooredoo Group, Nokia and Nvidia launched Zankore by Indosat with a plan for up to 1GW of AI data centre capacity in Indonesia.Hugging Face Hack Pushes AI Agents Into Cybersecurity SpotlightAIAug 8, 2026Hugging Face Hack Pushes AI Agents Into Cybersecurity SpotlightCNBC reported that Black Hat cybersecurity leaders treated the Hugging Face AI-agent breach as a turning point for governing autonomous cyber models rather than a one-off failure.Alibaba Tests Revenue Sharing For Commercial Qwen AI UseAIAug 8, 2026Alibaba Tests Revenue Sharing For Commercial Qwen AI UseAI News reported that Alibaba plans revenue-sharing terms for some commercial users of its next Qwen open-weight AI model, following a licensing pattern already used by Moonshot for Kimi K3.Meta Ordered To Fund $567M New Mexico Youth Mental Health PlanCapital & PolicyAug 8, 2026Meta Ordered To Fund $567M New Mexico Youth Mental Health PlanArs Technica reported that a New Mexico judge ordered Meta to provide $567 million for treatment, screening, awareness and prevention after finding that its platforms contributed to a public nuisance.Harvey Funding Talks Could Lift Legal AI Startup To $15.5B ValuationAIAug 8, 2026Harvey Funding Talks Could Lift Legal AI Startup To $15.5B ValuationSiliconANGLE reported that Harvey AI is seeking at least $500 million in new funding that could value the legal AI startup at $15.5 billion after annualized revenue passed $350 million.Vietnam Shows Shopee-TikTok Shop Race Tightening In Southeast AsiaScience & TechAug 7, 2026Vietnam Shows Shopee-TikTok Shop Race Tightening In Southeast AsiaTech Collective SEA wrote that Shopee’s Vietnam share fell from 61% to 53% between May 2025 and April 2026 as TikTok Shop rose from 33% to 44%, showing how social commerce is reshaping regional ecommerce infrastructure.China Opens Security Review Of Palo Alto Networks ProductsCybersecurityAug 7, 2026China Opens Security Review Of Palo Alto Networks ProductsChina's cyberspace regulator opened a security review of Palo Alto Networks products, with no named product line, technical flaw or decision timetable disclosed.AI Pioneers Split Over Risk As Compute Buildout AcceleratesAIAug 7, 2026AI Pioneers Split Over Risk As Compute Buildout AcceleratesData Center Knowledge reported that Geoffrey Hinton, Fei-Fei Li and Andrew Ng disagreed at Ai4 over AI risk, jobs, openness and regulation, leaving infrastructure investors to plan capacity amid unsettled deployment rules.SpaceX Asks FCC To Wind Down $4.5bn Rural Broadband SupportTelco & ConnectivityAug 7, 2026SpaceX Asks FCC To Wind Down $4.5bn Rural Broadband SupportLight Reading reported that SpaceX urged the FCC to sunset High-Cost rural broadband subsidies, while rural telecom and electric-cooperative groups said LEO satellite coverage cannot replace terrestrial network support.OpenAI Expands Free ChatGPT Access In GPT-5.6 RolloutAIAug 7, 2026OpenAI Expands Free ChatGPT Access In GPT-5.6 RolloutBleepingComputer reported that OpenAI is rolling out GPT-5.6 Sol for paid ChatGPT users and GPT-5.6 Luna for Free and Go users, pairing unlimited free text chats with a new reasoning control and additional safeguards for users believed to be under 18.JLL Data Centre Report Shows Middle East Pipeline Pause As FLAPD GrowsCapital & PolicyAug 7, 2026JLL Data Centre Report Shows Middle East Pipeline Pause As FLAPD GrowsData Center Dynamics reported that JLL's EMEA Mid-Year Data Centre Report 2026 put FLAPD live capacity at 3.8GW, while the Middle East had 2.6GW in development paused and 13.8GW in planning.AWS Adds Persistent Runtime Instances For Production AI AgentsCloud & Data CentersAug 7, 2026AWS Adds Persistent Runtime Instances For Production AI AgentsAWS announced runtime instances for Amazon Bedrock AgentCore Runtime, adding managed infrastructure for multi-agent workflows, shared sessions lasting up to 14 days and GPU-supported production agent deployments.