Blog

Cyber Incident Reporting Update: CIRCIA and GAO Report

Written by Bola Ogbara | Aug 7, 2026, 7:10:03 PM

As CIRCIA's final rule approaches, concerns about the scope of the historical cyber reporting act grow alongside others on conflicting reporting policies.

Four years ago, Congress passed the Consolidated Appropriations Act, a law that included a rule that could dramatically change the cybersecurity policies for any and all organizations in a critical infrastructure sector. The Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) appeared in division Y of the law and captured attention for the new requirements it demanded. CIRCIA mandated that these organizations report “significant” cyber incidents to the Cybersecurity and Infrastructure Security Agency (CISA) within 72 hours of the incident being discovered. The act also required that if made, ransom payments should also be reported in 24 hours. CIRCIA was developed in response to older self-disclosure practices that didn’t always provide adequate information.

 

CIRCIA signified a critical change to the federal government’s attitude on cyber incident reporting. Previous ransomware incidents like the Colonial Pipeline attack rendered parts of the nation’s key infrastructure unusable, impacting the lives of millions of Americans - demonstrating a need for closer overview in these sectors. The previous Director of CISA, Jen Easterly, commended the potential impact of CIRCIA: “CIRCIA is a game changer for the whole cybersecurity community, including everyone invested in protecting our nation’s critical infrastructure. It will allow us to better understand the threats we face, spot adversary campaigns earlier, and take more coordinated action with our public and private sector partners in response to cyber threats. We look forward to additional feedback from the critical infrastructure community as we move towards developing the Final Rule.”

 

Before a Final Rule could be reached, CIRCIA still inspired other legislation. Not long after the passing of the 2022 Consolidated Appropriations Act, the US Securities and Exchange Commission (SEC) developed a rule also requiring public companies to disclose data breaches and set up cybersecurity risk policies. The SEC’s rules for reporting were a little more flexible than CISA’s, setting the timeline to four business days. Still, the announcement was met with some controversy, as some argued that the period was not long enough for companies. Though finalized in 2023, the law is still receiving some criticism, especially as artificial intelligence (AI) has powered more attacks against companies.

 

Even with its impact, CIRCIA has still not been finalized. The act received a Notice of Proposed Rule Making (NPRM) in 2024, which added more specificity to the original rule by clarifying how a substantial cyber incident was defined and set out critical estimates for the cost of the rule ($2.6 billion). Progress on the act has been flying under the radar, partially due to CISA’s biggest stories in the last two years centering critical cuts to budget and staff under the new administration - but not for long. Despite the “multiple funding lapses [that] impacted CISA’s ability to conduct rulemaking activity for CIRCIA”, CISA is expected to release the final ruling on act this September. The rule making will be informed by the feedback gathered from their latest town hall series for critical infrastructure stakeholders, held in June 2026.

 

The comments from the town hall pushed back on the parameters of the act, arguing that too many companies fell under the “covered entities”, possibly targeting smaller entities with the same strictness intended for bigger groups. Other criticisms pointed out how companies may be burdened with reporting too frequently depending on how many incidents they face and the severity of the attacks. Even the depth of information requested in the reports was picked at. For example, the Public Water Agencies Group - a coalition of water service providers in Los Angeles County, CA - wrote about their fears of the disproportionate reporting burden, being uncertain of how a serious or substantial incident was defined, and the gap between how much warning water facilities know ahead of time about possible risks and how much would be expected of them to report. The Group explained that “most small water suppliers and wastewater providers lack internal IT or OT staff needed for compliance with such detailed reporting requirements in such a short time frame,” a comment that seems especially relevant with the recent attacks on cyberattacks on American water facilities.

 

Another point of concern with CIRCIA is less about the law itself, but rather the timing of its release. The Department of Homeland Security’s Committee on Appropriations shared that it “is concerned about delays in publishing the final CIRCIA rule and urges CISA to finalize it promptly following stakeholder review and feedback.” What’s more, an industry source told Cyberscoop that the act may already be out of date since the extensive delays: “AI has fundamentally changed the playing field. When this was set up, we didn’t even have the first generation of Char GPT. We’re now in a mythos class environment.”

 

Adding to the timing contention, CIRCIA is set to be finalized along two other critical cyber regulations. “Standardizing Cybersecurity Requirements for Unclassified Information Systems” and “Cyber Threat and Incident Reporting and Information Sharing” are both due for their Final Rules to be completed in September. More rules around cyber incident reporting and cybersecurity practices may seem like a protective move, but more regulatory legislation does not necessarily mean that the legislation becomes easier to follow.

 

On July 22nd, 2026, the US Government Accountability Office (GAO) published a report that reviewed reporting requirements for critical infrastructure and found that several sectors are facing redundant or overlapping requirements. Their investigation discovered “117 cybersecurity regulations established by 37 federal agencies for private entities, spanning nine critical infrastructure sectors”, with the majority of the regulations “either contain the same kind of reporting requirement applicable to a sector or the same reporting requirement as at least one other regulation, which may lead to duplication.” One example the report shares is the SEC requirement for public companies to disclose cyber incidents and cybersecurity plans, as this “may duplicate or conflict with regulations focused on a specific sector.”

 

Harmonization has been a work in progress for a while, but the GAO’s report urges faster implementation across sectors, now that CIRCIA is on its way to being finalized. Although industry stakeholders and federal workers have shared their doubts about its progress, CISA acting director Nick Andersen maintains that the act is a step in the right direction: “CISA does not view CIRCIA as simply a check-the-box compliance exercise. CIRCIA will enhance visibility into the cyberthreat landscape to enable a robust national early warning capability for critical infrastructure.” Hopefully, the next month will deliver on CISA’s goals with the cyber incident reporting act.