CTIA presses CISA to narrow CIRCIA incident threshold
CIRCIA’s scope fight is where a reporting program becomes an incident-response tax for carriers and contractors.
TL;DR
CTIA filed June 23 comments urging CISA to define “substantial cyber incident” through a harm-based threshold tied to national security, the U.S. economy, or public health and safety, plus a function-specific covered-entity test. Telecom carriers and their primes, MSPs, and contractors are trying to keep noncritical service disruptions out of CIRCIA reporting. The filing exposes the rulemaking’s live fight: overreporting is not free when responders are still inside the incident.
CTIA is not objecting to incident reporting in the abstract. It is trying to shrink the trigger that decides when the Cybersecurity and Infrastructure Security Agency gets a mandatory Cyber Incident Reporting for Critical Infrastructure Act report. According to Inside Cybersecurity, CTIA’s June 23 filing asks CISA to replace the April 2024 notice of proposed rulemaking’s definition of “substantial cyber incident” with a harm-based test tied to effects on national security, the U.S. economy, or public health and safety. The group also wants the definition limited to systems or networks needed to provide critical infrastructure services.
That distinction matters because CIRCIA reporting is a clock, not a newsletter signup. CISA’s NPRM would require a covered entity to report a covered cyber incident within 72 hours after it reasonably believes the incident occurred, and to report a ransom payment within 24 hours after payment is disbursed, according to CISA’s informational overview (https://www.cisa.gov/sites/default/files/2024-05/CIRCIA%20NPRM%20Overview%20May_508cL.pdf). If “substantial” includes disruptions to noncritical services, carriers and the contractors around them spend incident hours classifying, drafting and preserving a report that may teach CISA little about national risk.
CTIA’s proposed fix has two parts. First, apply a harm threshold across the definition, borrowing from Presidential Policy Directive 41 and CIRCIA, so reportable incidents are those with consequences for national security, economic security, or public health and safety. Second, use a function-specific approach to covered entities, keyed to National Critical Functions, rather than treating every affected service as equally tied to critical infrastructure. CTIA also asked CISA to streamline report contents, limit data retention, set clearer enforcement triggers and create room for ex parte meetings.
The uncomfortable point for CISA is that industry is not merely asking for a lighter form. It is contesting the unit of measurement. A broad definition maximizes government visibility, which is a real objective after years of fragmented incident reporting. But it also pushes liability-sensitive reporting work into the same window where defenders are containing damage. The final rule will show whether CISA treats that burden as the price of visibility or as noise that makes visibility worse.
Published ·Deep Fathom