CISA rulemaking lead draws line between duplication and overlap
Clagett's definitions matter: overlap is legitimate agencies needing the same incident data for different missions; duplication is what harmonization targets.
TL;DR
CISA's CIRCIA rulemaking lead Nichole Clagett laid out a framework for distinguishing duplication from overlap in cyber incident reporting regulations, telling a Billington Cybersecurity Summit panel that legacy all-hazards rules where cyber reporting "wasn't the original purpose" are potential harmonization targets. The final rule has not entered OMB interagency review. Acting Director Nick Andersen said the day before that timing remains "a work in progress" with more information "very soon."
Nichole Clagett, CISA's deputy director for CIRCIA, used a Sept. 10 panel at the Billington Cybersecurity Summit to define terms the agency has not previously parsed in public: duplication versus overlap in incident reporting.
Overlap, Clagett said, is when multiple federal agencies have different missions (national security, economic security, public health and safety) and each needs information about the same incident for its own legitimate reasons. Duplication is something else. It's what happens when reporting requirements ask for the same information for the same purpose, and it's where harmonization can actually reduce burden.
The distinction isn't academic. It gives CISA a public rationale for which regulations get harmonized and which don't, and it signals where the agency sees room to adjust the April 2024 notice of proposed rulemaking before finalization.
Legacy rules in the crosshairs
Clagett pointed specifically to "legacy regulations where cyber incident reporting maybe wasn't the original purpose", all-hazards frameworks that later absorbed cyber. Those rules may now have trigger thresholds and content requirements that differ from what CIRCIA would impose. She said harmonization "could include those things or none of those things," but named trigger definitions and reporting content as "touch points" of the regulation where changes are possible.
That matters for critical infrastructure operators who face multiple reporting regimes. The American Petroleum Institute, during CISA's June town hall series, flagged that oil and natural gas operators already report incidents under TSA and Coast Guard requirements. The U.S. Chamber of Commerce and Auburn's McCrary Institute have separately called for establishing CISA as a single intake point that satisfies multiple notification requirements.
Not yet at OMB
The final rule was listed for September 2026 in the most recent unified agenda, but it has not been submitted to OMB's Office of Information and Regulatory Affairs for interagency review, the gate that precedes publication. Asked about timing on Sept. 9, Acting Director Nick Andersen said the rule "continues to be a work in progress" and that CISA expects to share more "very soon." He did not commit to a month.
Clagett's panel included EPA cybersecurity branch chief Nushat Thomas, who noted that the EPA is aligning drinking-water and wastewater rules with the same cyber performance goals used across federal agencies, and GAO's Dave Hinchman, who previewed a fifth GAO report on regulatory harmonization expected within weeks. The previous GAO report, published July 22, catalogued duplicative federal cybersecurity regulations by sector.
Published ·Deep Fathom