Town Hall Meetings To Provide Input on Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Rulemaking
Details
The document's own metadata, straight from the source system.
- Title
- Town Hall Meetings To Provide Input on Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Rulemaking
- Posted
- May 26, 2026
- FR Doc
- 2026-10417
- CFR
- 6 CFR Part 226
- Topics
Overview
What the public is saying — stance, who's commenting, and the issues they raise.
Stance breakdown
Who commented
Breakdown by commenter type.
Comments over time
Weekly arrivals, stacked by stance.
Support × commenter type
How each type splits across stance.
Issues raised
The docket's canonical issues. Select one to browse its comments.
Position map
Who stands where on each issue?
Every non-silent position is backed by an excerpt from the comment.
Issues shown
Uncheck an issue to choose another.
| Organization | Reporting burden on small businesses | Chemical sector applicability criteria | Conflicting reporting requirements | Isac integration and reporting | Ot cyber incident identification |
|---|---|---|---|---|---|
Alliance for Chemical Distribution Trade associationSupport The Alliance for Chemical Distribution (ACD) supports the CIRCIA rulemaking but urges CISA to narrow the scope of applic | · | · | · | · | |
American Short Line and Regional Railroad Association Trade associationOppose The American Short Line and Regional Railroad Association (ASLRRA) opposes the broad definition of "covered entities" in | · | · | · | · | |
Applied Control Solutions, LLC BusinessOther Joe Weiss, Managing Partner at Applied Control Solutions, LLC, provides feedback on the CIRCIA rulemaking regarding cont | · | · | · | · | |
Farm Credit Mid-America, ACA BusinessOppose Farm Credit Mid-America, ACA, submits supplemental comments on behalf of the Farm Credit System, expressing concerns reg | · | · | · | · | |
Health-ISAC, Inc. AdvocacySupport Errol Weiss, Chief Security Officer of Health-ISAC, supports the CIRCIA rulemaking but urges CISA to integrate Informati | · | · | · | · | |
Paragon D&E BusinessSupport Thomas Symons, IT Director at Paragon D&E, a small business in the Defense Industrial Base, supports the goal of the CIR | · | · | · | · | |
Pinnacle Systems Group LLC BusinessSupport Pinnacle Systems Group LLC, representing the AgGateway WG35 working group, supports the CIRCIA rulemaking but argues tha | · | · | · | · | · |
SIFMA Trade associationOppose SIFMA, representing the financial services industry, opposes the proposed CIRCIA rule because it imposes overly burdenso | · | · | · | · | · |
Explorer
Every mirrored comment — filter by stance, campaign, or issue.
- Jul 14, 2026Comment submitted by American Public Transportation AssociationSupportTrade association📎 Attachment
The American Public Transportation Association (APTA) supports the CIRCIA rulemaking but urges CISA to streamline reporting processes, clarify reporting obligations for supply chain incidents, and coordinate with the TSA to harmonize regulations. They also emphasize the need for robust information protection, clear definitions of "substantial cyber incidents," and increased grant funding for transit agencies to meet cybersecurity standards.
Read comment → - Jul 14, 2026Comment submitted by Todd KlessmanOpposeTrade association📎 Attachment
SIFMA, representing the financial services industry, opposes the proposed CIRCIA rule because it imposes overly burdensome and expansive reporting requirements that exceed statutory authorities. They argue the rule lacks a sufficiently high threshold for "substantial" incidents and request that reporting be limited to information directly related to an actionable purpose.
Read comment → - Jul 14, 2026Comment submitted by Pinnacle Systems Group LLCSupportBusiness📎 Attachment
Pinnacle Systems Group LLC, representing the AgGateway WG35 working group, supports the CIRCIA rulemaking but argues that the current proposal lacks sector-specific criteria and vocabulary for the Food and Agriculture Sector. They advocate for the adoption of an "agricultural data custodian" criterion to capture supply chain intermediaries and the use of the AgDataBOM Stewardship Metadata Profile to provide a standardized vocabulary for incident reporting.
Read comment → - Jul 14, 2026Comment submitted by Elizabeth GuillotSupportBusiness📎 Attachment
CrowdStrike, a global cybersecurity provider, supports the proposed CIRCIA rule but recommends refining the definitions of "covered incident" and "supply chain compromise" to focus on outcomes rather than specific attack vectors. They also advocate for potential exemptions or tailored assistance for small entities to ensure reporting requirements do not hinder incident remediation.
Read comment → - Jul 14, 2026Comment submitted by Alliance for Chemical DistributionSupportTrade association📎 Attachment
The Alliance for Chemical Distribution (ACD) supports the CIRCIA rulemaking but urges CISA to narrow the scope of applicability to high-risk facilities using hazardous-release chemicals from Appendix A rather than the broader EPA Risk Management Program. They argue that a broader scope creates an overwhelming reporting burden that could hinder CISA's ability to respond effectively to cyber-attacks.
Read comment → - Jul 14, 2026Comment submitted by USTelecomSupportTrade association📎 Attachment
USTelecom, representing the broadband industry, supports the CIRCIA rulemaking but urges CISA to refine definitions for "covered cyber incidents" and "substantial cyber incidents" to focus on genuine national security risks. They also advocate for the creation of a centralized federal cyber incident reporting clearinghouse to harmonize reporting requirements across different government agencies.
Read comment → - Jul 14, 2026Comment submitted by Business RoundtableSupportTrade association📎 Attachment
The Business Roundtable, representing over 200 CEOs of leading U.S. companies, submitted comments to refine the CIRCIA rulemaking. They advocate for a risk-based approach that focuses on systemic impact rather than size-based criteria, while seeking to reduce compliance burdens, harmonize reporting requirements, and ensure robust data confidentiality.
Read comment → - Jul 14, 2026Comment submitted by Competitive Carriers AssociationSupportTrade association📎 Attachment
The Competitive Carriers Association (CCA) supports CISA's renewed approach to the CIRCIA rulemaking but urges the agency to significantly streamline and narrow the draft regulations. They argue that the current proposed rules are overly broad, create excessive compliance burdens (especially for small and rural carriers), and risk overreporting while failing to sufficiently coordinate with other federal agencies.
Read comment → - Jul 14, 2026Comment submitted by Jeffrey Davis JusinoSupportIndividual📎 Attachment
Jeffrey Davis Jusino, a cybersecurity governance and risk professional, supports the CIRCIA rulemaking but suggests improvements to reduce organizational burden. He advocates for automated interagency reporting, clearer definitions of "substantial" incidents in operational technology environments, and safe-harbor protections for good-faith reporting.
Read comment → - Jul 14, 2026Comment submitted by HackerOne IncSupportBusiness📎 Attachment
HackerOne, a cybersecurity firm, supports the CIRCIA rulemaking but urges CISA to refine the definition of "substantial cyber incident" to focus on actual impacts on national critical functions. They also advocate for clarifying exclusions for independent good-faith security research and adopting a reciprocity principle to harmonize reporting requirements across different federal agencies.
Read comment →
