Business Roundtable
CISARulemakingCISA-2022-0010

Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements

RIN
Last modified
May 27, 2026
Comment window
closed 755d ago
Business Roundtable filings
3

Activity

Business Roundtable filed 3 comments on this docket between Nov 15, 2022 and Jul 14, 2026. 155 other organizations filed here. The comment window closed 755d ago.

What Business Roundtable filed (3)

Jul 14, 2026· Comment submitted by Business Roundtable· CISA-2022-0010-0502

Filed on regulations.gov — full text not in the inline record.

Jul 3, 2024· Comment Submitted by Business Roundtable· CISA-2022-0010-0417

Filed on regulations.gov — full text not in the inline record.

Nov 15, 2022· Comment Submitted by Business Roundtable· CISA-2022-0010-0115

Filed on regulations.gov — full text not in the inline record.

Abstract

The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA), as amended, requires the Cybersecurity and Infrastructure Security Agency (CISA) to promulgate regulations implementing the statute’s covered cyber incident and ransom payment reporting requirements for covered entities. CISA seeks comment on the proposed rule to implement CIRCIA’s requirements and on several practical and policy issues related to the implementation of these new reporting requirements.

View on regulations.gov →