Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Navigating Cyber Disclosures in 2026: A Limited Renewal of CISA 2015, and “Take Two” on Finalizing CIRCIA’s Reporting Regulations

Дата публикации: 26-02-2026 16:14:35

Key point: 2026 may be a pivotal year for organizations to monitor cyber incident reporting requirements—the voluntary sharing allowed under CISA 2015 remains available, but only through September, and regulations delineating who and how mandatory reporting requirements are managed under CIRCIA are coming. Owner-operators in critical infrastructure sectors should monitor two federal initiatives regarding cybersecurity...

Основное содержимое страницы с новостью.

Key point: 2026 may be a pivotal year for organizations to monitor cyber incident reporting requirements—the voluntary sharing allowed under CISA 2015 remains available, but only through September, and regulations delineating who and how mandatory reporting requirements are managed under CIRCIA are coming.

Owner-operators in critical infrastructure sectors should monitor two federal initiatives regarding cybersecurity sharing and reporting. First, voluntary information sharing under CISA 2015 has been extended again, from January 30 to September 30, 2026. Second, CISA (the agency, not the law) is soliciting industry feedback as it resumes the rulemaking process for cyber incident reporting under CIRCIA.

CISA 2015: Voluntary Disclosures Extended

When Congress originally passed the law, the goal was to allow companies to voluntarily share information about cyber threats with the federal government to help improve the national cybersecurity posture. In return, these companies would receive certain legal protections, such as limits on how the information can be used by regulators and immunity from lawsuits. Originally, the law was scheduled to sunset on September 30, 2025, but as part of the compromise to reopen the government last fall, Congress renewed the law through January 30, 2026.

For now, at least, Congress has decided “something is better than nothing” and has renewed the law a second time in this month’s Consolidated Appropriations Act, but only until September 30, 2026. Arguably, the most helpful step Congress could take would be to rename the statute to eliminate the duplicative use of the ‘CISA acronym,’ which refers to a cybersecurity law as well as a federal cybersecurity agency.

These temporary extensions keep the current voluntary sharing system in place without changing any of the law’s requirements and protections. Organizations should be aware that the future of voluntary cyber information sharing remains uncertain beyond the end of this fiscal year.

CIRCIA: Mandatory Disclosures on the Horizon

CIRCIA’s statutory text directs CISA to promulgate regulations by October 2025, but last September, CISA announced the final regulations would be delayed until May 2026. As part of its effort to refine the scope and burden of CIRCIA-mandated regulations, CISA announced seven virtual town halls between March 9 and April 2, 2026 to get stakeholder input. The first five events will be industry-specific, and the final two sessions general in nature.

Registration for these sessions is open at www.cisa.gov/circia.

Industry SectorDate
Chemical Sector; Water and Wastewater Sector; Dams Sector; Energy Sector; and Nuclear Reactors, Materials, and Waste SectorMarch 9, 2026
Commercial Facilities Sector; Critical Manufacturing Sector; and Food and Agriculture SectorMarch 12, 2026
Emergency Services Sector, Government Facilities Sector, Healthcare and Public Health SectorMarch 17, 2026
Communications Sector; Transportation Systems Sector; and Financial Services SectorMarch 18, 2026
Defense Industrial Base Sector and Information Technology SectorMarch 19, 2026
CISA also plans to hold two general town hall meetings:
General Session 1March 31, 2026
General Session 2April 2, 2026

To avoid any confusion in the discussion, the 72-hour and 24-hour deadlines for covered entities to notify CISA of an incident or a ransom payment are statutory requirements and cannot be altered by regulation. Hence, the topics for these town halls include: (1) the scope of covered entities (2) the inclusion of cloud or managed service providers in the regulations (3) definitions of ‘covered cyber incidents’ and ‘ransom payments’ (4) harmonization with other federal and state requirements, and (5) the reporting of ‘substantially similar’ events.

Conclusion

With CISA 2015 extended only briefly and CIRCIA rules still taking shape, organizations must prioritize agility and awareness in their compliance efforts. Now is the time for organizations to get engaged and update their internal policies to be ready for these changes.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1CISA Announces Rescheduled Virtual Town Hall Meetings for CIRCIA Rulemaking06.7401-06-2026
2CISA 2015: Congress Faces Fast-Approaching Deadline to Reauthorize a Critical Cybersecurity Law012.9714-08-2025
3The Defense Department’s Cybersecurity Requirements Go Live08.811-09-2025
4OIRA Completes its Review of the DFARS CMMC Proposed Rule: Is Your Company CMMC Certified, or Will It be Excluded from Future Awards?08.1502-09-2025
5Website Compliance Must-Dos for 2026: What Legal and Business Teams Should Revisit Now013.9117-02-2026
6Department of War Suspends CMMC Phase II: What Defense Contractors Need to Know010.9814-07-2026
7GSA Joins the CUI Compliance Movement: What Non-Defense Contractors Need to Know08.909-02-2026
8U.S. State Privacy Law Landscape Expands to 24 States: What the Latest Legislative Wave Means for Businesses01029-06-2026
92025 Update: Website Tracking Litigation and Enforcement09.4520-11-2025
10California’s Deletion Request and Opt-Out Platform (DROP) is Live010.4411-02-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 11.74. Источник: www.lexblog.com.