CISA's Cyber Incident Reporting Rule Sits at OIRA as the Agency Shrinks to 2,200 Staff Without a Confirmed Director
The final rule under the Cyber Incident Reporting for Critical Infrastructure Act, known as CIRCIA, went to the White House Office of Information and Regulatory Affairs for review on 1 October 2026. It hasn’t been published. When it is, it will require critical infrastructure companies to report significant cyber incidents to the Cybersecurity and Infrastructure Security Agency within 72 hours, and ransom payments within 24 hours.
Congress passed CIRCIA in March 2022. The law gave CISA until 2025 to write the final rule. It’s more than a year late.
What the rule would do
The 2024 proposed rule would cover an estimated 316,244 entities across 16 critical infrastructure sectors, from hospitals to water utilities and pipelines. CISA estimated the total cost at about $2.6 billion over eleven years, mostly for companies to set up reporting processes.
Industry groups said the proposal was too broad and duplicated reporting rules from other regulators, including the SEC, the Federal Communications Commission and sector agencies. CISA said in 2025 it would narrow the scope. The final text won’t be known until OIRA clears it.
An agency getting smaller
CISA is writing the rule with far fewer people. Its workforce fell from about 3,300 at the start of 2025 to about 2,200, through buyouts, deferred resignations and layoffs. The administration’s fiscal 2027 budget asks for another cut to CISA’s funding, arguing the agency should focus on federal networks and drop work it considers outside its mission, including election security and misinformation.
The agency also lacks a confirmed director. The President’s nominee, Sean Plankey, was held up in the Senate for over a year and withdrew on 22 April 2026. Nick Andersen has been acting director. No new nominee has been confirmed.
The legal gap
A related law has lapsed and returned in pieces. The Cybersecurity Information Sharing Act of 2015, which protects companies that share threat data with the government from liability, expired at the end of September 2025 during the shutdown. Congress has extended it in stopgap funding bills since, most recently in the continuing resolution that runs to 11 December. Companies say short extensions make legal teams cautious about sharing.
Why the delay matters
Without CIRCIA, federal visibility of attacks on critical infrastructure depends on voluntary reporting and a patchwork of sector rules. The 2021 Colonial Pipeline attack, which shut fuel supplies along the East Coast, was the event that pushed Congress to act. The law’s sponsors wanted a single reporting point so CISA could spot campaigns across sectors.
Congress has options. It can press OIRA through oversight, fund CISA at higher levels than requested, or legislate a long-term extension of the 2015 information-sharing law. All three depend on December’s spending deal.