October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Financial Groups Ask CISA to Withdraw and Rewrite Proposed CIRCIA Rule

ABA, BPI, IIB, and SIFMA asked DHS and OMB to rescind and reissue CISA’s proposed CIRCIA rule, citing broad thresholds and operational burdens. The statute’s deadlines remain distinct from proposed implementation details, and the cited 2026 notices do not verify a final rule in force.
From TheFinanceBase Team6 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Four financial-sector associations asked the Department of Homeland Security and the Office of Management and Budget on February 28, 2025, to rescind and reissue CISA’s proposed rules for implementing the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA). Their objection is to the proposal’s scope and reporting burden—not necessarily to CIRCIA’s goal of giving the government timely information about cyber threats.

Status as of August 18, 2026: CISA was still gathering sector input on the proposal, including at a Financial Services Sector town hall scheduled for March 18, 2026. The available notices do not establish that a final implementation rule had entered into force. Treat the April 2024 proposal as a proposal, not as the final operational reporting regime. Federal Register notice

What the financial groups asked CISA to do

The American Bankers Association (ABA), Bank Policy Institute (BPI), Institute of International Bankers (IIB), and Securities Industry and Financial Markets Association (SIFMA) asked DHS Secretary Kristi Noem and OMB Director Russell Vought to rescind and reissue CISA’s April 2024 notice of proposed rulemaking. That is a request for a new proposal and another opportunity for public comment, rather than a request for only minor edits. The coalition’s letter

The associations said they support a more consistent way to share cyber-incident information across critical-infrastructure sectors. They argue, however, that the proposal’s broad thresholds and detailed information demands could pull incident responders away from containment, recovery, and remediation. Those are the associations’ concerns, not a finding that every report under the proposal would impede response.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What CIRCIA requires—and what the proposal adds

Congress enacted CIRCIA in March 2022. The statute requires covered entities to report covered cyber incidents to CISA within 72 hours and ransom payments within 24 hours. The April 4, 2024, proposed rule seeks to define and operationalize those obligations. The statutory deadlines should not be confused with every proposed definition, threshold, or data field. CISA’s proposed rule

For an organization trying to plan, the dispute is about more than the clock. The proposal addresses who is a covered entity, what counts as a covered or substantial cyber incident, what information an initial report and later supplements would include, when a third party may submit a report, how records should be preserved, and how substantially similar reports to other federal agencies may be treated. These are proposed-rule details; their final treatment is not established by the cited 2026 notices. Full proposed-rule document

Why thresholds and report contents matter

The financial associations contend that broad thresholds could capture incidents involving de minimis outages or non-critical services, while the proposed data requirements could exceed those in some existing cyber-reporting regimes. Their concern is that an organization might have to assemble detailed information while technical teams are still establishing what happened. CISA’s stated objective, by contrast, is timely, actionable information about threats affecting critical infrastructure.

The coalition’s original comments set out its concerns about the proposal’s thresholds, information demands, and operational burden. ABA-hosted coalition comments

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why financial institutions face an overlap problem

CIRCIA would sit alongside other duties rather than simply replace them. Depending on the entity and incident, a bank, broker-dealer, asset manager, payment company, insurer, or market-infrastructure operator may also have SEC disclosure obligations, federal banking-agency notification rules, state breach-notification duties, contractual commitments, payment-network requirements, or insurance-notification terms.

Those regimes may use different triggers and ask different questions. An incident can matter to national-security situational awareness without being material to investors; it can also be financially material without meeting CIRCIA’s proposed test. A report to one regulator should not be assumed to satisfy another obligation unless the applicable rule expressly allows it and the report meets its conditions. CISA’s proposal discusses substantially similar reporting, but the final treatment remains unsettled in the sources cited here.

The competing operational concerns

The associations’ case

  • Broad thresholds may generate reports about low-impact events or non-critical services.
  • Detailed reporting during an active incident may consume scarce response capacity.
  • Multiple regimes can require separate assessments, timelines, and narratives, increasing the risk of duplication or inconsistency.
  • Early facts may be incomplete, so a demand for extensive detail could put pressure on teams before scope and impact are known.

CISA’s stated objective

CISA is seeking timely, standardized information that can help identify campaigns across sectors, provide early warnings, and support national defense. Early notification need not mean a completed forensic investigation: an initial account of known facts can be followed by supplements as the picture develops. The policy question is how to make that first report useful without making it an obstacle to emergency response.

How the reporting questions can arise in practice

A cloud-provider outage

A cloud or managed-service provider might suffer an outage affecting a financial firm’s internal, non-critical service while customer transactions remain available. The associations say broad proposed thresholds could sweep in low-impact events of this kind. Whether a particular incident meets a CIRCIA threshold depends on the governing definition and facts; an outage alone does not establish that it is reportable.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A ransomware event and a payment decision

The statutory ransom-payment reporting deadline is separate from the incident-reporting deadline. A payment may be considered before investigators know the incident’s full scope, so organizations need a way to record the payment decision and its timing alongside the incident timeline. Payment decisions may also involve legal review, insurance approval, law-enforcement coordination, and sanctions screening. Sanctions exposure depends on the parties and facts; a ransom payment is not automatically a sanctions violation.

An incident at a shared processor

If a core processor, custodian, exchange, or payment provider is affected, several financial institutions may need to assess the same event. The proposal addresses third-party submissions, but firms would still need to establish who is reporting, whether the provider can act on their behalf, how customers and regulators will be informed, and how conflicting or changing accounts will be reconciled.

An early-stage investigation

An organization may have credible evidence of a compromise but not yet know the root cause, affected data, or attacker identity. A sound reporting workflow should distinguish confirmed facts from working hypotheses and unknowns, then support a later supplement. Waiting for perfect attribution can delay action under reporting regimes whose triggers are based on the incident and its impact.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What changed after the 2025 letter

The associations’ request was published February 28, 2025; SecurityWeek reported it on March 6, 2025. The public-comment period on the 2024 proposal had closed July 3, 2024. Subsequent Federal Register notices show continuing review rather than a verified resolution: a 2025 notice said comments were still being reviewed and the final rule was being developed, and a 2026 notice announced additional sector-specific town halls, including the Financial Services Sector session scheduled for March 18, 2026. 2025 information-collection notice · 2026 town-hall notice

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value

The October 2025 date sometimes associated with CIRCIA was a deadline for issuing a final rule, not proof that the final reporting system automatically became operational then. The cited later notices do not verify a final rule, a withdrawal, or an effective date. Organizations should check current CISA and Federal Register materials before relying on any later development.

How financial organizations can prepare without treating the proposal as final

The following are prudent incident-response practices, not a definitive checklist of final CIRCIA requirements.

  1. Map reporting duties. Maintain an obligations matrix for CIRCIA concepts alongside SEC, banking-agency, state, contractual, payment-network, and insurance requirements.
  2. Track distinct clocks. Record discovery, reasonable-belief, material-impact, ransom-payment, and report-submission times separately. A 72-hour period, an SEC disclosure obligation, and a banking notification duty may use different triggers.
  3. Assign decision owners. Separate technical investigation, legal analysis, executive approval, regulator contact, and customer communications, while keeping them on a shared chronology.
  4. Prepare a concise initial-report package. Organize known facts about affected systems, operational impact, attack vector, and containment status. Mark what is confirmed, provisional, or unknown rather than holding a report until every field can be completed.
  5. Plan for supplements. Build a process to add facts as investigation proceeds and to reconcile updates across regulators and other recipients.
  6. Coordinate third-party incidents. Set expectations with critical providers about notification, information sharing, reporting authority, and correction of inconsistent accounts.
  7. Preserve evidence and decisions. Keep a defensible chronology showing when the organization learned facts and why it concluded that an incident did or did not meet a reporting threshold.
  8. Test the workflow. Run scenarios involving ransomware, a shared-service outage, and an incident with uncertain scope to expose conflicting clocks, unclear ownership, and approval bottlenecks.

These steps help organizations prepare for a possible reporting regime while preserving the distinction between the statute, CISA’s proposed details, and any final rule that may later be issued.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.