Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements; Extension of Comment Period
Primary source
Metadata and text below are from the Federal Register, a public-domain U.S. government work. Always verify the official published version before relying on it for any legal matter.
Issuing agencies
Abstract
On April 4, 2024, the Cybersecurity and Infrastructure Security Agency (CISA) published a proposed rule in the Federal Register, the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA), which proposes regulations implementing the statute's covered cyber incident and ransom payment reporting requirements for covered entities. CISA is extending the public comment period for the proposed rulemaking for an additional 30 days through July 3, 2024, in response to comments received from the public requesting additional time.
This is legal information, not legal advice. Laws vary by jurisdiction and change frequently. Always verify current law with official sources and consult a licensed attorney in your jurisdiction for advice on your specific situation.