<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<REGINFO_RIN_DATA xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" RUN_DATE="2026-04-07-04:00" xsi:noNamespaceSchemaLocation="https://www.reginfo.gov/public/xml/REGINFO_XML_Ver10262011.xsd">
    <RIN_INFO>
        <RIN>1670-AA04</RIN>
        <PUBLICATION>
            <PUBLICATION_ID>202410</PUBLICATION_ID>
            <PUBLICATION_TITLE>The Regulatory Plan and the Unified Agenda of Federal Regulatory and Deregulatory Actions</PUBLICATION_TITLE>
        </PUBLICATION>
        <AGENCY>
            <CODE>1670</CODE>
            <NAME>Cybersecurity and Infrastructure Security Agency</NAME>
            <ACRONYM>CISA</ACRONYM>
        </AGENCY>
        <PARENT_AGENCY>
            <CODE>1600</CODE>
            <NAME>Department of Homeland Security</NAME>
            <ACRONYM>DHS</ACRONYM>
        </PARENT_AGENCY>
        <RULE_TITLE>Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements</RULE_TITLE>
        <ABSTRACT><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>The Cybersecurity and Infrastructure Security Agency (CISA) will&nbsp;finalize regulations to implement certain aspects of the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA).&nbsp; Specifically, CIRCIA directs CISA to develop and implement regulations requiring covered entities to submit reports to CISA regarding covered cyber incidents and ransom payments.&nbsp; CIRCIA requires CISA to publish a Notice of Proposed Rulemaking (NPRM) within 24 months of the date of enactment of CIRCIA as part of the process for developing these regulations.&nbsp; CISA previously issued a Request for Information on September 12, 2022, and held a series of listening sessions seeking public input on potential aspects of the proposed regulation prior to publication of the NPRM. On April 4, 2024, CISA published the NPRM with a 60-day open comment period to solicit public feedback on the proposed regulations.&nbsp;On May 6, 2024, CISA extended the public comment period for an additional 30 days ending the comment period on July 3, 2024.</p>
</body>
</html>]]></ABSTRACT>
        <PRIORITY_CATEGORY>Section 3(f)(1) Significant</PRIORITY_CATEGORY>
        <RIN_STATUS>Previously Published in The Unified Agenda</RIN_STATUS>
        <RULE_STAGE>Final Rule Stage</RULE_STAGE>
        <MAJOR>Yes</MAJOR>
        <UNFUNDED_MANDATE_LIST>
            <UNFUNDED_MANDATE>No</UNFUNDED_MANDATE>
        </UNFUNDED_MANDATE_LIST>
        <CFR_LIST>
            <CFR>6 CFR 226</CFR>
        </CFR_LIST>
        <LEGAL_AUTHORITY_LIST>
            <LEGAL_AUTHORITY>6 U.S.C. 681 et seq.</LEGAL_AUTHORITY>
        </LEGAL_AUTHORITY_LIST>
        <LEGAL_DLINE_LIST>
            <LEGAL_DLINE_INFO>
                <DLINE_TYPE>Statutory</DLINE_TYPE>
                <DLINE_ACTION_STAGE>Final</DLINE_ACTION_STAGE>
                <DLINE_DATE>10/04/2025</DLINE_DATE>
                <DLINE_DESC>Final Rule</DLINE_DESC>
            </LEGAL_DLINE_INFO>
            <LEGAL_DLINE_INFO>
                <DLINE_TYPE>Statutory</DLINE_TYPE>
                <DLINE_ACTION_STAGE>NPRM</DLINE_ACTION_STAGE>
                <DLINE_DATE>03/15/2024</DLINE_DATE>
                <DLINE_DESC>Notice of Proposed Rulemaking</DLINE_DESC>
            </LEGAL_DLINE_INFO>
        </LEGAL_DLINE_LIST>
        <RPLAN_ENTRY>Yes</RPLAN_ENTRY>
        <RPLAN_INFO>
            <STMT_OF_NEED><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>The Cybersecurity Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) directs CISA to develop and implement regulations requiring covered entities to submit reports to CISA regarding covered cyber incidents and ransom payments.&nbsp; CIRCIA requires CISA to publish a Notice of Proposed Rulemaking (NPRM)&nbsp;within 24 months of the date of enactment of CIRCIA and to publish a final rule 18 months after publication of the NPRM.&nbsp;&nbsp;CISA previously issued a Request for Information on September 12, 2022, and held a series of listening sessions seeking public input on potential aspects of the proposed regulation prior to publication of the NPRM. &nbsp;&nbsp;</p>
</body>
</html>]]></STMT_OF_NEED>
            <LEGAL_BASIS><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>This regulation is statutorily mandated by 6 U.S.C.&nbsp;681 et seq.</p>
</body>
</html>]]></LEGAL_BASIS>
            <COSTS_AND_BENEFITS><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>As CISA has already begun making investments to operationalize the CIRCIA program in anticipation of the publication of the Final Rule in 2025, the Preliminary RIA for the NPRM presents an 11-year period of analysis with government costs for the two years prior to publication of the CIRCIA Final Rule included in the total cost of the proposed rule. Based on the primary estimates for industry&rsquo;s cost of $1,444.5 million, and an estimated Government cost of $1.175.3 million, CISA estimates an 11-year undiscounted combined cost to industry and government of $2.6 billion. Discounted at 2%, the estimated 11-year cost of this proposed rule is $2.4 billion, with an annualized cost of $244.6 million.</p>
<p>&nbsp;</p>
<p>Qualitative benefits include (a) improved incident reporting and response and (b) improved cybersecurity posture through improved ability to prevent or mitigate events through information sharing, early warning, threat analysis, and incident response. The preservation of data and records in the aftermath of a Covered Cyber Incident serves a number of critical purposes, such as supporting the ability of (a) analysts and investigators to understand how a cyber incident was perpetrated and by whom and (b) law enforcement to capture and prosecute perpetrators of cyber incidents and recover ill-gotten proceeds from the criminal activity.</p>
</body>
</html>]]></COSTS_AND_BENEFITS>
        </RPLAN_INFO>
        <TIMETABLE_LIST>
            <TIMETABLE>
                <TTBL_ACTION>NPRM</TTBL_ACTION>
                <TTBL_DATE>04/04/2024</TTBL_DATE>
                <FR_CITATION>89 FR 23644</FR_CITATION>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>NPRM Comment Period Extended</TTBL_ACTION>
                <TTBL_DATE>05/06/2024</TTBL_DATE>
                <FR_CITATION>89 FR 37141</FR_CITATION>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>NPRM Correction</TTBL_ACTION>
                <TTBL_DATE>06/03/2024</TTBL_DATE>
                <FR_CITATION>89 FR 47471</FR_CITATION>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>NPRM Comment Period End</TTBL_ACTION>
                <TTBL_DATE>06/03/2024</TTBL_DATE>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>NPRM Comment Period Extended End</TTBL_ACTION>
                <TTBL_DATE>07/03/2024</TTBL_DATE>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>Final Rule</TTBL_ACTION>
                <TTBL_DATE>10/00/2025</TTBL_DATE>
            </TIMETABLE>
        </TIMETABLE_LIST>
        <RFA_REQUIRED>Undetermined</RFA_REQUIRED>
        <GOVT_LEVEL_LIST>
            <GOVT_LEVEL>Undetermined</GOVT_LEVEL>
        </GOVT_LEVEL_LIST>
        <FEDERALISM>No</FEDERALISM>
        <FURTHER_INFO_URL>https://www.regulations.gov</FURTHER_INFO_URL>
        <PUBLIC_COMMENT_URL>https://www.regulations.gov</PUBLIC_COMMENT_URL>
        <PRINT_PAPER>No</PRINT_PAPER>
        <INTERNATIONAL_INTEREST>No</INTERNATIONAL_INTEREST>
        <AGENCY_CONTACT_LIST>
            <CONTACT>
                <FIRST_NAME>Todd</FIRST_NAME>
                <LAST_NAME>Klessman</LAST_NAME>
                <TITLE>CIRCIA Rulemaking Team Lead</TITLE>
                <AGENCY>
                    <CODE>1670</CODE>
                    <NAME>Cybersecurity and Infrastructure Security Agency</NAME>
                    <ACRONYM>CISA</ACRONYM>
                </AGENCY>
                <PHONE>202 964-6869</PHONE>
                <EMAIL>circia@cisa.dhs.gov</EMAIL>
                <MAILING_ADDRESS>
                    <STREET_ADDRESS>CISA - CHR Mailstop 0609, 1310 N Courthouse Road,</STREET_ADDRESS>
                    <CITY>Arlington</CITY>
                    <STATE>VA</STATE>
                    <ZIP>20598-0609</ZIP>
                </MAILING_ADDRESS>
            </CONTACT>
        </AGENCY_CONTACT_LIST>
    </RIN_INFO>
</REGINFO_RIN_DATA>
