CISA is moving closer to finalizing its long-awaited CIRCIA rule — and now it wants direct feedback from critical infrastructure operators.
The draft proposal requires covered entities to report significant cyber incidents within 72 hours. Business groups have raised concerns about scope, reporting burden, and which sectors are included.
Seven public meetings are scheduled to gather industry input before the rule is finalized.
🔐 Cybersecurity regulation is evolving — and industry voices are being invited into the process.
CISA проводить зустрічі з секторами критичної інфраструктури щодо правила звітності про кіберінциденти CIRCIA.




















