A growing number of industry groups have expressed frustration with a pending cyber incident notification regulation, urging the Cybersecurity and Infrastructure Security Agency (CISA) to revise its proposed rule to apply to fewer entities and reduce reporting requirements.
The controversy surrounds the 2022 Cyber Incident Reporting for Critical Infrastructure Act, which requires critical infrastructure owners to report major cyberattacks to the federal government within 72 hours. Industry groups have been vocal in their opposition to the regulation, arguing that it is overly broad and would burden small businesses with excessive reporting requirements.
According to transcripts of town halls hosted by CISA, industry representatives claimed that the proposed rule includes too many companies, with over 300,000 entities estimated to be subject to its requirements. Some groups advocated for removal from the list entirely, while others sought to reduce the number affected within their sector. For example, the Nuclear Energy Institute requested that only those already subject to Nuclear Regulatory Commission cybersecurity reporting requirements be included.
Industry experts worry that the current approach would sweep in small businesses under multiple cyber categories, negating the intended limitation on small businesses. They also expressed concerns about what kind of data organizations should report in a major incident, arguing that CISA should collect the least amount of information possible to facilitate accurate and timely reporting.
Furthermore, representatives from various industries questioned the type of incidents that would trigger reporting requirements, with some worrying that companies might be asked to report on minor incidents or even just a “ping” from a foreign entity. This could lead to an excessive burden on critical infrastructure owners, particularly small businesses.
Despite the industry’s concerns, CISA has yet to provide clear indications about how much of the town hall feedback it intends to incorporate into its final rule. The agency missed multiple deadlines for finalizing the regulation, and some industry sources now doubt that a September completion date is realistic.
Industry optimism remains, however, with some representatives believing that the proposed rule will be streamlined to focus on the most critical pieces of information necessary for a quick response during an emergency. As CISA continues to work on the regulation, one takeaway for critical infrastructure owners and small businesses alike is the importance of staying vigilant and engaged in the regulatory process.
To prepare for potential changes to the regulation, it’s essential that companies understand their obligations under current law and stay informed about any updates or revisions. This includes familiarizing themselves with the proposed rule and participating in public comment periods when they are available. By doing so, critical infrastructure owners can ensure they are prepared to meet any new reporting requirements while minimizing potential burdens on their operations.
Source: CyberScoop — 2026-07-24