CYBERSECURITYTRACKER
TRACKING
Permanent story citation

A Threat-Sharing Law Slides Into December. A CIRCIA Reporting Mandate Does Not

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8781

As cited

Copy frozen at (site build).

regulatory

A Threat-Sharing Law Slides Into December. A CIRCIA Reporting Mandate Does Not

The Cybersecurity Information Sharing Act (CISA) 2015 threat-sharing protections are receiving another short-term extension into December, while the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) 72-hour incident reporting requirement becomes permanent this month. The divergent treatment reflects ongoing congressional debate over balancing information sharing incentives with mandatory disclosure requirements.

Why it matters: Critical infrastructure operators and their security teams must immediately align incident response procedures with CIRCIA's permanent 72-hour reporting deadline to avoid penalties, while monitoring whether CISA 2015 protections remain available to encourage future threat intelligence sharing.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary