2026-02948Proposed Rule

CISA Hosts Cyber Snitch Sessions for Infra Bigwigs

Published Date: 2/13/2026

Proposed Rule

Summary

The Cybersecurity and Infrastructure Security Agency (CISA) is hosting virtual town hall meetings in March and April 2026 to get feedback on new rules requiring critical infrastructure sectors to report cyber incidents and ransom payments. These rules affect industries like energy, healthcare, finance, and more, aiming to boost cybersecurity and reduce risks. If you’re in these sectors, now’s the time to weigh in before the rules are finalized!

Analyzed Economic Effects

4 provisions identified: 1 benefits, 3 costs, 0 mixed.

Mandatory Cyber Incident Reporting

CISA is proposing rules under the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) that would require 'covered entities' in critical infrastructure sectors to report 'covered cyber incidents' and 'ransom payments' to CISA. The NPRM was published April 4, 2024, and CIRCIA was enacted in March 2022; the town halls in March–April 2026 are part of the stakeholder input process.

Size-Based Coverage Criterion Under Consideration

The NPRM proposes, and CISA is seeking feedback on, including a size-based criterion that could make entities 'covered' solely because of their size. CISA seeks input on which entities would be covered only by size and on whether to keep or change this size-based threshold.

Potential Inclusion of MSPs and Cloud Providers

CISA is asking whether the final rule should include specific criteria to cover Managed Service Providers (MSPs) or Cloud Service Providers (CSPs), including reporting related to open-source software or code repositories. Stakeholders are invited to provide examples and suggested criteria during the March–April 2026 town halls.

Effort to Harmonize and Reduce Duplicate Reporting

CISA explicitly seeks input on approaches to harmonize CIRCIA reporting requirements with other federal, state, local, tribal, or territorial laws and on ways to reduce duplication or conflict. Stakeholders may suggest methods to avoid duplicate reporting during the town halls and by submitting written materials within seven calendar days after a meeting.

Your PRIA Score

Score Hidden

Personalized for You

How does this regulation affect your finances?

Sign up for a PRIA Policy Scan to see your personalized alignment score for this federal register document and every other regulation we track. We analyze your financial profile against policy provisions to show you exactly what matters to your wallet.

Free to start

Key Dates

Published Date
2/13/2026

Department and Agencies

Department
Independent Agency
Agency
Homeland Security Department
Source: View HTML

Related Federal Register Documents

Previous / Next Documents

Back to Federal Register

Take It Personal

Get Your Personalized Policy View

Start a Free Government Policy Watch to see how policy affects your household, then upgrade to PRIA Full Coverage for year-round monitoring.

Already have an account? Sign in