SendTech Times
News
MARKET SIGNAL:

CIRCIA Rule Faces September Deadline As Industry Seeks Narrower Filings

Newsroom brief

CISA is working toward a September target for the delayed CIRCIA rule as industry groups seek fewer covered entities, narrower incident triggers and leaner reporting requirements. The law sets 72-hour incident and 24-hour ransomware-payment reporting deadlines, while the proposed rule could cover more than 300,000 entities.

Verified against source materialEdited by SendTech Times Capital & Policy DeskSource: cyberscoop.com
CIRCIA Rule Faces September Deadline As Industry Seeks Narrower Filings

The US Cybersecurity and Infrastructure Security Agency is working toward a September target for its delayed cyber incident reporting rule as industry groups press for fewer covered organisations, narrower incident triggers and less information in each filing.

The rule implements the 2022 Cyber Incident Reporting for Critical Infrastructure Act, known as CIRCIA.

The law requires covered critical infrastructure operators to notify the federal government of major cyber incidents within 72 hours and report ransomware payments within 24 hours.

Reporting Scope Remains Contested

CISA's 2024 proposal estimated that more than 300,000 entities could fall within the rule.

Industry representatives told four agency town halls in June that the proposed scope could include too many organisations and incidents.

Grant MacIntyre of the Auto Care Association argued that the rule reaches too many companies.

Insurance representatives sought exclusions for parts of their sector, while the Nuclear Energy Institute wanted coverage limited to operators already subject to Nuclear Regulatory Commission cyber-reporting requirements.

Small-business treatment is another point of dispute.

According to Douglas Leigh of the Alliance for Chemical Distribution, the proposed size-or-sector test could still pull small chemical distributors into several covered categories.

Samantha Burch of the health insurance association AHIP urged CISA to collect only the information needed for accurate and rapid reporting.

Industry Seeks Narrower Incident Triggers

Participants also questioned which events should trigger a filing.

Tim Pospisil of Nebraska Public Power District warned that broad language could require reports for routine probes of a firewall even when no compromise occurs.

Several groups opposed requirements to disclose details about an affected organisation's security controls.

Their comments frame the central implementation choice: how much information CISA needs for national warning and defensive action without diverting incident-response teams into excessive paperwork.

September Target Follows Earlier Delays

CISA missed the original October 2025 deadline and a later May target.

The administration's regulatory agenda now lists September for completion, although several industry sources told CyberScoop they doubted that schedule would hold.

Congress has also pressed the agency to finish.

In its fiscal 2027 Department of Homeland Security report, the House Appropriations Committee expressed concern about the delays and urged publication after stakeholder review.

The timetable follows a process that began with the 2022 law and moved to a proposed rule in 2024.

That proposal was intended to define covered entities, covered incidents and the information required in a report before the obligations take effect.

CISA Says Rulemaking Continues

Acting CISA director Nick Andersen told a town hall that the agency does not view CIRCIA as a compliance checklist.

He said faster reporting is intended to improve visibility into cyber threats and support warnings and defensive measures for critical infrastructure.

A CISA spokesperson attributed the rulemaking delays partly to funding lapses and confirmed that work on the final rule continues.

The agency also said 1,200 critical infrastructure stakeholders attended its town halls and directed future updates to CISA.gov/CIRCIA and the federal regulatory agenda.

CISA does not identify which industry requests it will accept and has not confirmed that the September target will hold.

The unresolved items are the final coverage threshold, the incidents that trigger a filing and the information affected organisations must provide.

Share this article
inXf

Related articles

More
Open-Weight AI Safety Gap Widens As GLM-5.2 Nears Frontier Models
Capital & Policy

Open-Weight AI Safety Gap Widens As GLM-5.2 Nears Frontier Models

SaferAI found Z.ai GLM-5.2 close to frontier cyber and biology capabilities while lacking published safety commitments, making release controls part of the AI risk debate.

Singapore Gives Platforms January Deadline For Anti-Scam Controls
Capital & Policy

Singapore Gives Platforms January Deadline For Anti-Scam Controls

Singapore is requiring messaging services to restrict unknown contacts and social platforms to verify advertisers under anti-scam rules that carry a January 31, 2027 compliance deadline.

Grindr Agrees £26m Settlement Over UK HIV-Data Privacy Claims
Capital & Policy

Grindr Agrees £26m Settlement Over UK HIV-Data Privacy Claims

Grindr will pay £26m to settle claims over historical sharing of users’ sensitive data, including HIV status, while denying liability and pointing to privacy changes since 2020.

Khalifa Fund Cybersecurity Program Starts Without Funding Or Cohort Details
Capital & Policy

Khalifa Fund Cybersecurity Program Starts Without Funding Or Cohort Details

Khalifa Fund and the UAE Cyber Security Council have launched a national program for cybersecurity startups with CyberE71 support. The announcement names mentorship, investor access and partnership support, but gives no funding amount, cohort size or application timetable.

Singapore Online Safety Office Gets 500 Reports in First Test
Capital & Policy

Singapore Online Safety Office Gets 500 Reports in First Test

Singapore’s new Online Safety Commission received more than 500 reports in its first two months, with doxxing and harassment dominating eligible online-harm complaints.

India Rights Watchdog Seeks Reports Over Instagram Child-Safety Ads
Capital & Policy

India Rights Watchdog Seeks Reports Over Instagram Child-Safety Ads

India’s NHRC asked MeitY, the Ministry of Information and Broadcasting and Delhi Police for action-taken reports after allegations that paid Instagram ads facilitated access to child sexual abuse material.

Yokogawa Opens Singapore Hub For Industrial Cyber Resilience
Capital & Policy

Yokogawa Opens Singapore Hub For Industrial Cyber Resilience

Yokogawa Engineering Asia has launched a Singapore center focused on OT cyber resilience, training, response planning and recovery coordination for Southeast Asia, Oceania and Taiwan.

NPCI Sees AI In UPI Growth While App-Concentration Deadline Still Looms
Fintech & Digital Payments

NPCI Sees AI In UPI Growth While App-Concentration Deadline Still Looms

NPCI chief Dilip Asbe said AI could help UPI reach new users, detect fraud and support credit, while India’s payment ecosystem still faces a December 31, 2026 app-concentration deadline.

Keep Reading

More Stories

Latest
Kepler Targets 2027 Production for HBM Replacement MemoryCloud & Data CentersOct 6, 2026Kepler Targets 2027 Production for HBM Replacement MemoryEE Times reports that Kepler Computing is preparing 3D ferroelectric memory for 2027 production, promising higher capacity and bandwidth per watt while limiting reliance on advanced-node lithography.ClickFix Attack Uses Browser Cache To Hide Malware PayloadCybersecurityOct 6, 2026ClickFix Attack Uses Browser Cache To Hide Malware PayloadMicrosoft Threat Intelligence traced a ClickFix cache-smuggling method that preloads malware into browser caches, then uses file size checks and a pasted Run command to launch later credential-theft stages.VOA Tests Six-Month Startup Buildout Before Funding DecisionsFintech & Digital PaymentsOct 6, 2026VOA Tests Six-Month Startup Buildout Before Funding DecisionsTechCabal’s interview with VOA Venture Partners founder Victoria Olayide Adesanya describes a six-month build programme that lets the firm work inside African financial-infrastructure startups before deciding whether to invest.Bitcoin Holds $86,000 As Dollar Index Hits 18-Month HighCrypto/Web3Oct 6, 2026Bitcoin Holds $86,000 As Dollar Index Hits 18-Month HighCoinDesk reported that bitcoin stayed near $86,000 while the U.S. Dollar Index reached about 102.5, with U.S. rate expectations and European political risks strengthening the dollar backdrop.Google Freezes OSS Bug Bounty Reports After AI Submission FloodCybersecurityOct 6, 2026Google Freezes OSS Bug Bounty Reports After AI Submission FloodGoogle has stopped accepting new product vulnerability reports in its OSS VRP after invalid automated submissions swamped reviewers, while older reports and some Cloud VRP routes remain open.Fleuret AI Raises €4M For Continuous AI Pentesting PlatformCybersecurityOct 6, 2026Fleuret AI Raises €4M For Continuous AI Pentesting PlatformTech.eu reported that French startup Fleuret AI raised €4 million in pre-seed funding to develop an agentic-AI platform that turns penetration testing into a continuous security process.GFT Analysis Says AI Documentation Can Cut Maintenance Work 30%Fintech & Digital PaymentsOct 6, 2026GFT Analysis Says AI Documentation Can Cut Maintenance Work 30%A GFT Technologies analysis says AI-linked software documentation can cut maintenance effort and speed developer onboarding when knowledge assets stay synchronized with code changes.Schneider Electric Lines Up $22.6 Billion PTC DealAIOct 5, 2026Schneider Electric Lines Up $22.6 Billion PTC DealSchneider Electric plans to buy PTC in a cash transaction valuing the US engineering software provider’s equity at about $22.6 billion, adding product-lifecycle software to its industrial AI push.Aggarwal Pledges Ola Electric Stake To Fund ₹1,000 Cr Rights IssueCapital & PolicyOct 5, 2026Aggarwal Pledges Ola Electric Stake To Fund ₹1,000 Cr Rights IssueOla Electric founder Bhavish Aggarwal pledged 20 Cr shares to finance his participation in a rights issue that forms part of a larger ₹1,500 Cr fundraising plan.Natrona Schools AI Review Puts Student Privacy Ahead Of Classroom Tool UseAIOct 5, 2026Natrona Schools AI Review Puts Student Privacy Ahead Of Classroom Tool UseNatrona County trustees questioned whether teacher AI tools expose student data, even as existing district rules already ban unauthorized generative AI use by students.AMD Prices 256-Core EPYC 9996 At $14,904 For Server BuyersChips & SemiconductorsOct 5, 2026AMD Prices 256-Core EPYC 9996 At $14,904 For Server BuyersTechRadar reports that AMD’s 6th Gen EPYC 9006 “Venice” lineup includes a 256-core EPYC 9996 with 512 threads, 1GB of L3 cache, a 600W default power rating and a $14,904 list price for 1,000-unit orders.New Relic Reports US$18 Million GreenOps Savings After AI CertificationCloud & Data CentersOct 5, 2026New Relic Reports US$18 Million GreenOps Savings After AI CertificationA New Relic company news item carried by iTWire says the observability vendor has earned ISO/IEC 42001 certification, joined the EU AI Pact and reported US$18 million in GreenOps savings from more than 80 engineering initiatives.