CISA is expected to finalize its long-delayed Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) rule by September, establishing a mandatory federal reporting regime for critical infrastructure operators. Under the rule, covered entities would have to report substantial cyber incidents to CISA within 72 hours and disclose ransomware payments within 24 hours, marking a major shift from the agency’s largely voluntary incident-sharing model.
The reporting mandate was authorized in 2022 but missed its statutory October 2025 deadline amid rulemaking delays and Department of Homeland Security scheduling disruptions. CISA has continued procedural work and stakeholder outreach, including notices and town halls, as officials refine the final directive shaped by lessons from the SolarWinds compromise, the Colonial Pipeline attack, and broader concerns that geopolitical crises could trigger cyberattacks against U.S. infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
A regulation document published last week indicated that CISA expects to finalize the critical infrastructure cyber incident reporting rule in September.
After the scheduling delays, CISA conducted additional stakeholder town halls as part of continued engagement to refine the final reporting rule.
A Department of Homeland Security shutdown delayed scheduling for the rulemaking process, contributing to broader delays in finalizing the reporting rule.
In April 2024, CISA issued its first procedural notice for the Cyber Incident Reporting for Critical Infrastructure Act rulemaking process.
The Cyber Incident Reporting for Critical Infrastructure Act was enacted in 2022, establishing the basis for mandatory reporting of substantial cyber incidents and ransomware payments by critical infrastructure entities.
CISA did not meet the statutory October 2025 deadline for finalizing the Cyber Incident Reporting for Critical Infrastructure Act rule.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.