National Federation of Independent Business
CISARulemakingCISA-2022-0010

Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements

RIN
Last modified
May 27, 2026
Comment window
closed 755d ago
National Federation of Independent Business filings
1

Activity

National Federation of Independent Business filed 1 comment on this docket between May 3, 2024 and May 3, 2024. 155 other organizations filed here. The comment window closed 755d ago.

What National Federation of Independent Business filed (1)

May 3, 2024· Comment Submitted by National Federation of Independent Business, Inc. (NFIB)· CISA-2022-0010-0190

NFIB (National Federation of Independent Business) comment letter of May 2, 2024, in response to Department of Homeland Security Cybersecurity and Infrastructure Security Agency notice of proposed rulemaking titled "Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements," Docket No. CISA-2022-0010, 89 Fed. Reg. 23644 (April 4, 2024), is attached.

Abstract

The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA), as amended, requires the Cybersecurity and Infrastructure Security Agency (CISA) to promulgate regulations implementing the statute’s covered cyber incident and ransom payment reporting requirements for covered entities. CISA seeks comment on the proposed rule to implement CIRCIA’s requirements and on several practical and policy issues related to the implementation of these new reporting requirements.

View on regulations.gov →