circiatrade-pressNewsThe Broadside2 min read

CIRCIA transcripts show industry united against 300,000-entity scope

After two missed deadlines and four town halls of industry pushback, CISA still hasn't signaled what it will change in the CIRCIA rule or whether September is realistic.


TL;DR

CISA published transcripts from four June town halls on its CIRCIA incident reporting rule, and industry's message was near-universal: the proposed scope, covering an estimated 300,000 entities, is too broad and the reporting triggers too sensitive. The data collection demands drew separate objections. The rule has missed two deadlines. The administration now targets September, but multiple industry sources consider that unlikely, and CISA hasn't signaled what feedback it'll act on.

What industry asked for

CISA published transcripts last week from four June town halls on the CIRCIA incident reporting rule, and the record now shows what industry has been saying privately for two years: the proposed rule covers too many entities and would trigger reports on incidents most organizations don't consider significant. It also demands more data than CISA can usefully process. The agency estimated more than 300,000 entities would fall under the rule. Insurance trade groups asked to be carved out entirely. Nuclear operators want the covered list narrowed to facilities already reporting to the NRC. Chemical distributors warned the sector-based criteria sweep in small businesses the rule was supposed to exclude. The feedback was consistent and the asks were specific, but CISA has given no indication which, if any, it intends to grant.

The timeline nobody believes

That silence matters because the clock has run out twice already. The rule missed an October 2025 statutory deadline, then a May reset. The administration now points to September, but multiple industry sources told CyberScoop they don't expect CISA to hit it. One noted the agency has been through multiple funding lapses and Trump-era personnel cuts. The House Appropriations Committee, in its fiscal 2027 DHS spending report, said it is concerned about delays in publishing the final CIRCIA rule and urges CISA to finalize it promptly.

The gap between ambition and capacity

CIRCIA was signed in 2022, before ChatGPT and the current AI threat landscape. It was also before CISA absorbed the staff reductions that have slowed rulemaking across DHS components. Acting Director Nick Andersen told town hall attendees the agency doesn't view CIRCIA as a check-the-box compliance exercise, but without narrowing the covered entity definition, the volume of reports could overwhelm the early-warning capability the statute was meant to create. Industry isn't arguing against reporting. It's arguing that 300,000 entities filing on every firewall ping won't produce actionable threat intelligence.

What primes and MSPs do now

For primes, contractors, MSPs, and C3PAOs that sit in covered sectors, the immediate problem is uncertainty. The proposed rule is still the only public draft, and organizations that build compliance programs around it risk over-investing in requirements that may be narrowed or eliminated in the final rule. Those that wait risk standing up reporting capabilities on short notice if CISA does meet September. The transcripts make clear what industry wants. What CISA will actually do remains, for now, anyone's guess.


Published ·Deep Fathom

CIRCIA transcripts show industry united against 300,000-entity scope — The Broadside