CISA Sets September Deadline for Cyber Incident Reporting Rules
CISA Sets September Deadline for Cyber Incident Reporting Rules
US · Published Jul 8, 2026
The Cybersecurity and Infrastructure Security Agency (CISA) has announced a new deadline of September 2026 to publish long-delayed rules for the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA).
These rules were initially due by October 4, 2025, but delays were caused by a government shutdown and other administrative challenges.

Impact & Risks

The delay in implementing these rules leaves critical infrastructure sectors vulnerable to cyber threats without a standardized reporting framework. This could hinder timely responses to cyber incidents and complicate coordination between private entities and federal agencies. The delay also raises concerns about the government's ability to enforce cybersecurity measures effectively.

Related News