CISA Delays Critical Cyber Incident Reporting Rule to May 2026
DWT Privacy & Security Law Blog
|
Contributed by: Drex DeFord
Summary
The Cybersecurity & Infrastructure Security Agency (CISA) has delayed the implementation of its cyber incident reporting rule for critical infrastructure operators until May 2026, shifting the timeline from the previously expected October 2025 release. This regulation, mandated by the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) of 2022, requires timely reporting of cyber incidents to CISA, which is essential for strengthening national cybersecurity. The postponement comes amidst substantial criticism from industry stakeholders and lawmakers who argue that the proposed definitions, particularly regarding "covered entities," may be too broad and potentially exceed the statute's intent. This situation highlights ongoing tensions between regulatory frameworks and industry practices in managing cybersecurity risks effectively within healthcare technology and other critical sectors.