{"description":"Documents matching '\"Cyber Incident Reporting for Critical Infrastructure\"'","count":36,"total_pages":2,"next_page_url":"https://www.federalregister.gov/api/v1/documents?conditions%5Bterm%5D=%22Cyber+Incident+Reporting+for+Critical+Infrastructure%22&format=json&page=2","results":[{"title":"Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Rulemaking; Town Hall Meetings","type":"Proposed Rule","abstract":"This notice announces town hall meetings to allow external stakeholders a limited additional opportunity to provide input on refining the scope and burden of the CIRCIA Notice of Proposed Rulemaking (NPRM) issued in the Federal Register on April 4, 2024. The proposed CIRCIA rulemaking seeks to implement the Cyber Incident Reporting for Critical Infrastructure Act of 2022, as amended, by implementing covered cyber incident and ransom payment reporting requirements for covered entities.","document_number":"2026-02948","html_url":"https://www.federalregister.gov/documents/2026/02/13/2026-02948/cyber-incident-reporting-for-critical-infrastructure-act-circia-rulemaking-town-hall-meetings","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2026-02-13/pdf/2026-02948.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2026-02948.pdf?1770903920","publication_date":"2026-02-13","agencies":[{"raw_name":"DEPARTMENT OF HOMELAND SECURITY","name":"Homeland Security Department","id":227,"url":"https://www.federalregister.gov/agencies/homeland-security-department","json_url":"https://www.federalregister.gov/api/v1/agencies/227","parent_id":null,"slug":"homeland-security-department"}],"excerpts":"stakeholders a limited additional opportunity to provide input on refining the scope and burden of the CIRCIA Notice of Proposed Rulemaking (NPRM) issued in the \n Federal Register \n on April 4, 2024. The proposed CIRCIA rulemaking seeks to implement the <span class=\"match\">Cyber Incident Reporting for Critical Infrastructure</span> Act of 2022, as amended, by implementing covered cyber incident and ransom payment reporting requirements for covered entities.\n \n \n \n DATES: \n Town hall meetings are scheduled to be held on the following dates: \n \n \n • \n Chemical Sector; Water and"},{"title":"Town Hall Meetings To Provide Input on Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Rulemaking","type":"Proposed Rule","abstract":"This notice announces a revised town hall meeting schedule to allow external stakeholders a limited additional opportunity to provide input on refining the scope and burden of the CIRCIA Notice of Proposed Rulemaking (NPRM) issued in the Federal Register on April 4, 2024. The proposed CIRCIA rulemaking seeks to implement the Cyber Incident Reporting for Critical Infrastructure Act of 2022, as amended, by implementing covered cyber incident and ransom payment reporting requirements for covered entities.","document_number":"2026-10417","html_url":"https://www.federalregister.gov/documents/2026/05/26/2026-10417/town-hall-meetings-to-provide-input-on-cyber-incident-reporting-for-critical-infrastructure-act","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2026-05-26/pdf/2026-10417.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2026-10417.pdf?1779453919","publication_date":"2026-05-26","agencies":[{"raw_name":"DEPARTMENT OF HOMELAND SECURITY","name":"Homeland Security Department","id":227,"url":"https://www.federalregister.gov/agencies/homeland-security-department","json_url":"https://www.federalregister.gov/api/v1/agencies/227","parent_id":null,"slug":"homeland-security-department"}],"excerpts":"stakeholders a limited additional opportunity to provide input on refining the scope and burden of the CIRCIA Notice of Proposed Rulemaking (NPRM) issued in the \n Federal Register \n on April 4, 2024. The proposed CIRCIA rulemaking seeks to implement the <span class=\"match\">Cyber Incident Reporting for Critical Infrastructure</span> Act of 2022, as amended, by implementing covered cyber incident and ransom payment reporting requirements for covered entities.\n \n \n \n DATES: \n Town hall meetings are scheduled to be held virtually on the following dates: \n \n • General Session 1—Monday"},{"title":"Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements; Correction","type":"Proposed Rule","abstract":"On April 4, 2024, the Cybersecurity and Infrastructure Security Agency (CISA) published, in the Federal Register, the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements notice of proposed rulemaking (NPRM). The NPRM proposes regulations to implement CIRCIA's covered cyber incident and ransom payment reporting requirements for covered entities. In the section describing covered entities, the NPRM included information and references in the applicability criteria for transportation system entities that were based on a proposed rule that has not yet been published by the Transportation Security Administration (TSA). This document clarifies and corrects the proposed applicability criteria for pipeline facilities and systems in the sector-based criteria discussion for transportation systems sector entities.","document_number":"2024-12084","html_url":"https://www.federalregister.gov/documents/2024/06/03/2024-12084/cyber-incident-reporting-for-critical-infrastructure-act-circia-reporting-requirements-correction","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2024-06-03/pdf/2024-12084.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2024-12084.pdf?1717073138","publication_date":"2024-06-03","agencies":[{"raw_name":"DEPARTMENT OF HOMELAND SECURITY","name":"Homeland Security Department","id":227,"url":"https://www.federalregister.gov/agencies/homeland-security-department","json_url":"https://www.federalregister.gov/api/v1/agencies/227","parent_id":null,"slug":"homeland-security-department"}],"excerpts":"Cybersecurity and Infrastructure Security Agency, \n circia@cisa.dhs.gov, \n 202-964-6869.\n \n \n \n \n SUPPLEMENTARY INFORMATION: \n Background and Discussion \n \n On April 4, 2024, CISA published a NPRM, “<span class=\"match\">Cyber Incident Reporting for Critical Infrastructure</span> Act Reporting Requirements,” 89 FR 23644, that was required by the <span class=\"match\">Cyber Incident Reporting for Critical Infrastructure</span> Act of 2022 (CIRCIA).\n 1 \n \n CIRCIA requires covered entities to report to CISA within certain prescribed timeframes any covered cyber incidents, ransom payments made in response to a ransomware"},{"title":"Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements","type":"Proposed Rule","abstract":"The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA), as amended, requires the Cybersecurity and Infrastructure Security Agency (CISA) to promulgate regulations implementing the statute's covered cyber incident and ransom payment reporting requirements for covered entities. CISA seeks comment on the proposed rule to implement CIRCIA's requirements and on several practical and policy issues related to the implementation of these new reporting requirements.","document_number":"2024-06526","html_url":"https://www.federalregister.gov/documents/2024/04/04/2024-06526/cyber-incident-reporting-for-critical-infrastructure-act-circia-reporting-requirements","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2024-04-04/pdf/2024-06526.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2024-06526.pdf?1711543528","publication_date":"2024-04-04","agencies":[{"raw_name":"DEPARTMENT OF HOMELAND SECURITY","name":"Homeland Security Department","id":227,"url":"https://www.federalregister.gov/agencies/homeland-security-department","json_url":"https://www.federalregister.gov/api/v1/agencies/227","parent_id":null,"slug":"homeland-security-department"}],"excerpts":"ACTION: \n Proposed rule. \n \n \n SUMMARY: \n The <span class=\"match\">Cyber Incident Reporting for Critical Infrastructure</span> Act of 2022 (CIRCIA), as amended, requires the Cybersecurity and Infrastructure Security Agency (CISA) to promulgate regulations implementing the statute's covered cyber incident and ransom payment reporting requirements for covered entities. CISA seeks comment on the proposed rule to implement CIRCIA's requirements and on several practical and policy issues related to the implementation of these new reporting requirements. \n \n \n DATES: \n Comments"},{"title":"Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements; Extension of Comment Period","type":"Proposed Rule","abstract":"On April 4, 2024, the Cybersecurity and Infrastructure Security Agency (CISA) published a proposed rule in the Federal Register, the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA), which proposes regulations implementing the statute's covered cyber incident and ransom payment reporting requirements for covered entities. CISA is extending the public comment period for the proposed rulemaking for an additional 30 days through July 3, 2024, in response to comments received from the public requesting additional time.","document_number":"2024-09505","html_url":"https://www.federalregister.gov/documents/2024/05/06/2024-09505/cyber-incident-reporting-for-critical-infrastructure-act-circia-reporting-requirements-extension-of","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2024-05-06/pdf/2024-09505.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2024-09505.pdf?1714740317","publication_date":"2024-05-06","agencies":[{"raw_name":"DEPARTMENT OF HOMELAND SECURITY","name":"Homeland Security Department","id":227,"url":"https://www.federalregister.gov/agencies/homeland-security-department","json_url":"https://www.federalregister.gov/api/v1/agencies/227","parent_id":null,"slug":"homeland-security-department"}],"excerpts":"Agency, \n circia@cisa.dhs.gov, \n 202-964-6869.\n \n \n \n \n SUPPLEMENTARY INFORMATION: \n Background and Discussion \n On April 4, 2024, CISA published a notice of proposed rulemaking, “<span class=\"match\">Cyber Incident Reporting for Critical Infrastructure</span> Act Reporting Requirements” (89 FR 23644), which proposes a rulemaking required by the <span class=\"match\">Cyber Incident Reporting for Critical Infrastructure</span> Act of 2022 (CIRCIA). See 6 U.S.C. 681-681g; Public Law 117-103, as amended by Public Law 117-263 (Dec. 23, 2022). The proposed rule provided for a 60-day comment period which was"},{"title":"Unified Agenda of Federal Regulatory and Deregulatory Actions","type":"Notice","abstract":"This regulatory agenda is a summary of projected regulations, existing regulations, and completed actions of the Department of Homeland Security (DHS) and its components. This agenda provides the public with information about DHS's regulatory and deregulatory activity. DHS expects that this information will enable the public to be more aware of, and effectively participate in, the Department's regulatory and deregulatory activity. DHS invites the public to submit comments on any aspect of this agenda.","document_number":"2026-16605","html_url":"https://www.federalregister.gov/documents/2026/08/14/2026-16605/unified-agenda-of-federal-regulatory-and-deregulatory-actions","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2026-08-14/pdf/2026-16605.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2026-16605.pdf?1786625114","publication_date":"2026-08-14","agencies":[{"raw_name":"DEPARTMENT OF HOMELAND SECURITY","name":"Homeland Security Department","id":227,"url":"https://www.federalregister.gov/agencies/homeland-security-department","json_url":"https://www.federalregister.gov/api/v1/agencies/227","parent_id":null,"slug":"homeland-security-department"},{"raw_name":"Office of the Secretary"}],"excerpts":"Identification Display Area (SIDA) \n 1652-AA70 \n \n \n 265 \n Enhancing Surface Cyber Risk Management \n 1652-AA74 \n \n \n \n Cybersecurity and Infrastructure Security Agency—Final Rule Stage \n \n Sequence No. \n Title \n \n Regulation\n Identifier No. \n \n \n \n 266 \n \n <span class=\"match\">Cyber Incident Reporting for Critical Infrastructure</span> Act (CIRCIA) Reporting Requirements \n (Reg Plan Seq No. 85) \n \n 1670-AA04 \n \n \n References in boldface appear in The Regulatory Plan in part II of this issue of the \n Federal Register \n .\n \n \n \n Cybersecurity and Infrastructure Security Agency—Long-Term"},{"title":"Agency Information Collection Activities: Incident Reporting Form","type":"Notice","abstract":"The Cybersecurity Division (CSD) within the Cybersecurity and Infrastructure Security Agency (CISA) submits the following Information Collection Request (ICR) to the Office of Management and Budget (OMB) for review and clearance in accordance with the Paperwork Reduction Act of 1995. This is a replacement to an existing collection and is a new collection request. This ICR collects cybersecurity incident reports related to Federal agency information systems, mandatory reports on behalf of certain Federal regulatory agencies, mandatory reports due to contractual requirements, and voluntary reports from members of the public. This ICR, which is authorized by the Federal Information Security Modernization Act of 2014 (FISMA) and the Homeland Security Act, is distinct from incident reporting under the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA). CISA will use a different information collection instrument for CIRCIA incident reports after the effective date of CIRCIA implementing regulations. The questions included in this package for public review represent the universe of all possible questions CISA may use for incident report information collection purposes across multiple use cases; no respondent will be presented all the questions.","document_number":"2024-23070","html_url":"https://www.federalregister.gov/documents/2024/10/07/2024-23070/agency-information-collection-activities-incident-reporting-form","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2024-10-07/pdf/2024-23070.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2024-23070.pdf?1728045920","publication_date":"2024-10-07","agencies":[{"raw_name":"DEPARTMENT OF HOMELAND SECURITY","name":"Homeland Security Department","id":227,"url":"https://www.federalregister.gov/agencies/homeland-security-department","json_url":"https://www.federalregister.gov/api/v1/agencies/227","parent_id":null,"slug":"homeland-security-department"}],"excerpts":"contractual requirements, and voluntary reports from members of the public. This ICR, which is authorized by the Federal Information Security Modernization Act of 2014 (FISMA) and the Homeland Security Act, is distinct from incident reporting under the <span class=\"match\">Cyber Incident Reporting for Critical Infrastructure</span> Act (CIRCIA). CISA will use a different information collection instrument for CIRCIA incident reports after the effective date of CIRCIA implementing regulations. The questions included in this package for public review represent the universe of all"},{"title":"Agency Information Collection Activities: Incident Reporting Form","type":"Notice","abstract":"The Cybersecurity Division (CSD) within the Cybersecurity and Infrastructure Security Agency (CISA) will submit the following information collection request (ICR) to the Office of Management and Budget (OMB) for review and clearance. CISA previously published this information collection request (ICR) in the Federal Register on October 7, 2024, for a 60-day public comment period. Three (3) comments were received by CISA. One unrelated public comment was submitted. The purpose of this notice is to allow additional 30-days for public comments.","document_number":"2025-01165","html_url":"https://www.federalregister.gov/documents/2025/01/17/2025-01165/agency-information-collection-activities-incident-reporting-form","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2025-01-17/pdf/2025-01165.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2025-01165.pdf?1737035132","publication_date":"2025-01-17","agencies":[{"raw_name":"DEPARTMENT OF HOMELAND SECURITY","name":"Homeland Security Department","id":227,"url":"https://www.federalregister.gov/agencies/homeland-security-department","json_url":"https://www.federalregister.gov/api/v1/agencies/227","parent_id":null,"slug":"homeland-security-department"}],"excerpts":"question is driven by the individual respondent's responses. No respondent will be prompted to answer all the questions included in this package for review and approval. \n This collection of information is distinct from CISA's efforts to implement the <span class=\"match\">Cyber Incident Reporting for Critical Infrastructure</span> Act of 2022 (CIRCIA) covered cyber incident and ransom payment reporting requirements. On April 4, 2024, CISA published the CIRCIA notice of proposed rulemaking (NPRM). 89 FR 23644 (Apr. 4, 2024). Among other aspects of the proposed rulemaking, the"},{"title":"Protecting the Nation's Communications Systems From Cybersecurity Threats","type":"Notice","abstract":"In this document, the Federal Communications Commission (\"Commission\" or \"FCC\") announces that it has reconsidered and rescinded a prior Declaratory Ruling and Notice of Proposed Rulemaking, neither of which had been published in the Federal Register. The Declaratory Ruling misconstrued the Communications Assistance for Law Enforcement Act (CALEA), and the Notice of Proposed Rulemaking was based in part on the Declaratory Ruling's flawed legal analysis and proposed ineffective cybersecurity requirements. This Order follows the FCC's engagement with providers to help strengthen their cybersecurity posture.","document_number":"2025-22830","html_url":"https://www.federalregister.gov/documents/2025/12/15/2025-22830/protecting-the-nations-communications-systems-from-cybersecurity-threats","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2025-12-15/pdf/2025-22830.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2025-22830.pdf?1765547125","publication_date":"2025-12-15","agencies":[{"raw_name":"FEDERAL COMMUNICATIONS COMMISSION","name":"Federal Communications Commission","id":161,"url":"https://www.federalregister.gov/agencies/federal-communications-commission","json_url":"https://www.federalregister.gov/api/v1/agencies/161","parent_id":null,"slug":"federal-communications-commission"}],"excerpts":"timing of the incident, as well as the impact of the incident, in Form 8-K filings. Additionally, many carriers are subject to state laws that require them to implement reasonable cybersecurity risk management practices to protect customer data. The <span class=\"match\">Cyber Incident Reporting for Critical Infrastructure</span> Act of 2022 (CIRCIA), as amended, also requires the Cybersecurity and Infrastructure Security Agency (CISA) to promulgate regulations implementing CIRCIA's covered cyber incident and ransom payment reporting requirements for covered entities, including"},{"title":"Cyber Incident Reporting for Critical Infrastructure Act of 2022: Washington, DC Listening Session","type":"Notice","abstract":"The Cybersecurity and Infrastructure Security Agency (CISA) is announcing one additional public listening session located in Washington, DC to receive input on the forthcoming proposed regulations required by the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA). This session will allow interested parties to provide input to CISA on the same key areas of interest published in the Federal Register on September 12, 2022.","document_number":"2022-21635","html_url":"https://www.federalregister.gov/documents/2022/10/05/2022-21635/cyber-incident-reporting-for-critical-infrastructure-act-of-2022-washington-dc-listening-session","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2022-10-05/pdf/2022-21635.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2022-21635.pdf?1664887533","publication_date":"2022-10-05","agencies":[{"raw_name":"DEPARTMENT OF HOMELAND SECURITY","name":"Homeland Security Department","id":227,"url":"https://www.federalregister.gov/agencies/homeland-security-department","json_url":"https://www.federalregister.gov/api/v1/agencies/227","parent_id":null,"slug":"homeland-security-department"}],"excerpts":"listening session. \n \n \n SUMMARY: \n \n The Cybersecurity and Infrastructure Security Agency (CISA) is announcing one additional public listening session located in Washington, DC to receive input on the forthcoming proposed regulations required by the <span class=\"match\">Cyber Incident Reporting for Critical Infrastructure</span> Act of 2022 (CIRCIA). This session will allow interested parties to provide input to CISA on the same key areas of interest published in the \n Federal Register \n on September 12, 2022.\n \n \n \n DATES: \n An additional public listening session is scheduled"},{"title":"Cyber Incident Reporting for Critical Infrastructure Act of 2022 Listening Sessions","type":"Notice","abstract":"The Cybersecurity and Infrastructure Security Agency (CISA) is announcing a series of public listening sessions to receive input as CISA develops proposed regulations required by the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA). CISA is interested in receiving public input on potential aspects of the proposed regulations prior to their publication in a Notice of Proposed Rulemaking (NPRM), and issued a request for information in the Federal Register on September 12, 2022 (the \"RFI\") as a means to receive that input. These public listening sessions are intended to serve as an additional means for interested parties to provide input to CISA on the topics identified in the RFI prior to the publication of the NPRM.","document_number":"2022-19550","html_url":"https://www.federalregister.gov/documents/2022/09/12/2022-19550/cyber-incident-reporting-for-critical-infrastructure-act-of-2022-listening-sessions","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2022-09-12/pdf/2022-19550.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2022-19550.pdf?1662727515","publication_date":"2022-09-12","agencies":[{"raw_name":"DEPARTMENT OF HOMELAND SECURITY","name":"Homeland Security Department","id":227,"url":"https://www.federalregister.gov/agencies/homeland-security-department","json_url":"https://www.federalregister.gov/api/v1/agencies/227","parent_id":null,"slug":"homeland-security-department"}],"excerpts":"ACTION: \n Notice of public listening sessions. \n \n \n SUMMARY: \n \n The Cybersecurity and Infrastructure Security Agency (CISA) is announcing a series of public listening sessions to receive input as CISA develops proposed regulations required by the <span class=\"match\">Cyber Incident Reporting for Critical Infrastructure</span> Act of 2022 (CIRCIA). CISA is interested in receiving public input on potential aspects of the proposed regulations prior to their publication in a Notice of Proposed Rulemaking (NPRM), and issued a request for information in the \n \n Federal \n \n Register"},{"title":"Request for Information on the Cyber Incident Reporting for Critical Infrastructure Act of 2022","type":"Notice","abstract":"The Cybersecurity and Infrastructure Security Agency (CISA) is issuing this Request for Information (RFI) to receive input from the public as CISA develops proposed regulations required by the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA). Among other things, CIRCIA directs CISA to develop and oversee implementation of regulations requiring covered entities to submit to CISA reports detailing covered cyber incidents and ransom payments. CIRCIA requires CISA to publish a Notice of Proposed Rulemaking (NPRM) within 24 months of the date of enactment of CIRCIA as part of the process for developing these regulations. CISA is interested in receiving public input on potential aspects of the proposed regulation prior to publication of the NPRM and is issuing this RFI as a means to receive that input. While CISA welcomes input on other aspects of CIRCIA's regulatory requirements, CISA is particularly interested in input on definitions for and interpretations of the terminology to be used in the proposed regulations; the form, manner, content, and procedures for submission of reports required under CIRCIA; information regarding other incident reporting requirements including the requirement to report a description of the vulnerabilities exploited; and other policies and procedures, such as enforcement procedures and information protection policies, that will be required for implementation of the regulations.","document_number":"2022-19551","html_url":"https://www.federalregister.gov/documents/2022/09/12/2022-19551/request-for-information-on-the-cyber-incident-reporting-for-critical-infrastructure-act-of-2022","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2022-09-12/pdf/2022-19551.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2022-19551.pdf?1662727515","publication_date":"2022-09-12","agencies":[{"raw_name":"DEPARTMENT OF HOMELAND SECURITY","name":"Homeland Security Department","id":227,"url":"https://www.federalregister.gov/agencies/homeland-security-department","json_url":"https://www.federalregister.gov/api/v1/agencies/227","parent_id":null,"slug":"homeland-security-department"}],"excerpts":"ACTION: \n Request for information. \n \n \n SUMMARY: \n The Cybersecurity and Infrastructure Security Agency (CISA) is issuing this Request for Information (RFI) to receive input from the public as CISA develops proposed regulations required by the <span class=\"match\">Cyber Incident Reporting for Critical Infrastructure</span> Act of 2022 (CIRCIA). Among other things, CIRCIA directs CISA to develop and oversee implementation of regulations requiring covered entities to submit to CISA reports detailing covered cyber incidents and ransom payments. CIRCIA requires CISA to publish"},{"title":"Modernization of the Nation's Alerting Systems; Protecting the Nation's Communications Systems From Cybersecurity Threats","type":"Rule","abstract":"In the Report and Order, the Federal Communications Commission (the FCC or the Commission) seeks to preserve the public's trust in the Emergency Alert System (EAS) by requiring targeted cybersecurity improvements that will help protect against hijacking by cybercriminals and our nation's adversaries.","document_number":"2026-15601","html_url":"https://www.federalregister.gov/documents/2026/07/31/2026-15601/modernization-of-the-nations-alerting-systems-protecting-the-nations-communications-systems-from","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2026-07-31/pdf/2026-15601.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2026-15601.pdf?1785415525","publication_date":"2026-07-31","agencies":[{"raw_name":"FEDERAL COMMUNICATIONS COMMISSION","name":"Federal Communications Commission","id":161,"url":"https://www.federalregister.gov/agencies/federal-communications-commission","json_url":"https://www.federalregister.gov/api/v1/agencies/161","parent_id":null,"slug":"federal-communications-commission"}],"excerpts":"unauthorized access of their systems to the Commission. We agree with commenters that adopting additional cybersecurity incident reporting requirements for alerting participants would be premature in light of CISA's pending rulemaking implementing the <span class=\"match\">Cyber Incident Reporting for Critical Infrastructure</span> Act (CIRCIA). Rather than adopting potentially duplicative incident requirements, we will continue to monitor CISA's work. \n We decline to remove language from Sections 10.330 and 10.500 of the Commission's rules that provide that WEA functionality"},{"title":"Request for Information on Cyber Regulatory Harmonization; Request for Information: Opportunities for and Obstacles To Harmonizing Cybersecurity Regulations","type":"Notice","abstract":"The Office of the National Cyber Director (ONCD) invites public comments on opportunities for and obstacles to harmonizing cybersecurity regulations, per Strategic Objective 1.1 of the National Cybersecurity Strategy. ONCD seeks input from stakeholders to understand existing challenges with regulatory overlap, and explore a framework for reciprocity (the recognition or acceptance by one regulatory agency of another agency's assessment, determination, finding, or conclusion with respect to the extent of a regulated entity's compliance with certain cybersecurity requirements) in regulator acceptance of other regulators' recognition of compliance with baseline requirements.","document_number":"2023-17424","html_url":"https://www.federalregister.gov/documents/2023/08/16/2023-17424/request-for-information-on-cyber-regulatory-harmonization-request-for-information-opportunities-for","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2023-08-16/pdf/2023-17424.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2023-17424.pdf?1692103517","publication_date":"2023-08-16","agencies":[{"raw_name":"Office of the National Cyber Director","name":"Office of the National Cyber Director","id":613,"url":"https://www.federalregister.gov/agencies/office-of-the-national-cyber-director","json_url":"https://www.federalregister.gov/api/v1/agencies/613","parent_id":538,"slug":"office-of-the-national-cyber-director"}],"excerpts":"this RFI regarding harmonization of cyber incident reporting requirements. Such requirements are being analyzed through a separate effort led by the Cyber Incident Reporting Council established by the Secretary of Homeland Security as required by the <span class=\"match\">Cyber Incident Reporting for Critical Infrastructure</span> Act of 2022. \n \n • All submissions are public records and may be published on \n www.regulations.gov. \n Do NOT submit sensitive, confidential, or personally identifiable information.\n \n \n Questions for respondents: \n \n 1. Conflicting, mutually exclusive"},{"title":"Defense Federal Acquisition Regulation Supplement: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041)","type":"Rule","abstract":"DoD is issuing a final rule amending the Defense Federal Acquisition Regulation Supplement (DFARS) to incorporate contractual requirements related to the final Cybersecurity Maturity Model Certification program rule, titled Cybersecurity Maturity Model Certification Program. This final DFARS rule also partially implements a section of the National Defense Authorization Act for Fiscal Year 2020 that directed the Secretary of Defense to develop a consistent, comprehensive framework to enhance cybersecurity for the U.S. defense industrial base.","document_number":"2025-17359","html_url":"https://www.federalregister.gov/documents/2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2025-09-10/pdf/2025-17359.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2025-17359.pdf?1757421911","publication_date":"2025-09-10","agencies":[{"raw_name":"DEPARTMENT OF DEFENSE","name":"Defense Department","id":103,"url":"https://www.federalregister.gov/agencies/defense-department","json_url":"https://www.federalregister.gov/api/v1/agencies/103","parent_id":null,"slug":"defense-department"},{"raw_name":"Defense Acquisition Regulations System","name":"Defense Acquisition Regulations System","id":97,"url":"https://www.federalregister.gov/agencies/defense-acquisition-regulations-system","json_url":"https://www.federalregister.gov/api/v1/agencies/97","parent_id":103,"slug":"defense-acquisition-regulations-system"}],"excerpts":"changes should be included. Several \n \n respondents requested a clarification on what “security changes” mean in the context of the proposed rule clause. A respondent stated the notification requirements under the rule should be aligned with a forthcoming <span class=\"match\">Cyber Incident Reporting for Critical Infrastructure</span> Act of 2022 (CIRCIA) rule. Another respondent recommended focusing the incident reporting requirements under DFARS 252.204-7021 paragraph (b)(4) solely on reporting changes in the status of the CMMC certificate levels or CMMC self-assessment levels"},{"title":"Federal Acquisition Regulation: Prohibition on Certain Semiconductor Products and Services","type":"Proposed Rule","abstract":"OFPP, DoD, GSA, and NASA (collectively referred to as the Federal Acquisition Regulatory Council, or FAR Council) are proposing to amend the Federal Acquisition Regulation (FAR) to partially implement a section of the James M. Inhofe National Defense Authorization Act for Fiscal Year 2023 which prohibits executive agencies from procuring or obtaining certain products and services that include covered semiconductor products or services effective December 23, 2027.","document_number":"2026-03065","html_url":"https://www.federalregister.gov/documents/2026/02/17/2026-03065/federal-acquisition-regulation-prohibition-on-certain-semiconductor-products-and-services","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2026-02-17/pdf/2026-03065.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2026-03065.pdf?1770990325","publication_date":"2026-02-17","agencies":[{"raw_name":"OFFICE OF MANAGEMENT AND BUDGET","name":"Management and Budget Office","id":280,"url":"https://www.federalregister.gov/agencies/management-and-budget-office","json_url":"https://www.federalregister.gov/api/v1/agencies/280","parent_id":null,"slug":"management-and-budget-office"},{"raw_name":"Office of Federal Procurement Policy","name":"Federal Procurement Policy Office","id":184,"url":"https://www.federalregister.gov/agencies/federal-procurement-policy-office","json_url":"https://www.federalregister.gov/api/v1/agencies/184","parent_id":280,"slug":"federal-procurement-policy-office"},{"raw_name":"DEPARTMENT OF DEFENSE","name":"Defense Department","id":103,"url":"https://www.federalregister.gov/agencies/defense-department","json_url":"https://www.federalregister.gov/api/v1/agencies/103","parent_id":null,"slug":"defense-department"},{"raw_name":"GENERAL SERVICES ADMINISTRATION","name":"General Services Administration","id":210,"url":"https://www.federalregister.gov/agencies/general-services-administration","json_url":"https://www.federalregister.gov/api/v1/agencies/210","parent_id":null,"slug":"general-services-administration"},{"raw_name":"NATIONAL AERONAUTICS AND SPACE ADMINISTRATION","name":"National Aeronautics and Space Administration","id":301,"url":"https://www.federalregister.gov/agencies/national-aeronautics-and-space-administration","json_url":"https://www.federalregister.gov/api/v1/agencies/301","parent_id":null,"slug":"national-aeronautics-and-space-administration"}],"excerpts":"Hardware, Software, and Services Developed or Provided by Kaspersky Lab Covered Entities(3 business days), the clause at FAR 52.204-25, Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment (1 business day), <span class=\"match\">Cyber Incident Reporting for Critical Infrastructure</span> Act of 2022, Division Y of Public Law 117-103 (72 hours), and Defense FAR Supplement (DFARS) 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting (72 hours). The FAR Council has proposed a 72-hour reporting deadline, similar"},{"title":"Federal Acquisition Regulation: Revolutionary Federal Acquisition Regulation Overhaul Parts 1, 2, 4, 33, 39, 40, and 53","type":"Proposed Rule","abstract":"OFPP, DoD, GSA, and NASA (collectively referred to as the Federal Acquisition Regulatory Council or FAR Council) are proposing to amend the Federal Acquisition Regulation (FAR) to implement Executive Order (E.O.) 14275, Restoring Common Sense to Federal Procurement. The E.O. directs the elimination of excessive acquisition regulations to stop the inefficient use of American taxpayer dollars. The FAR Council is issuing twelve proposed rules that collectively will streamline the FAR in its entirety. This rule proposes revisions to FAR parts 1, 2, 4, 33, 39, 40, 52, and 53.","document_number":"2026-12559","html_url":"https://www.federalregister.gov/documents/2026/06/23/2026-12559/federal-acquisition-regulation-revolutionary-federal-acquisition-regulation-overhaul-parts-1-2-4-33","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2026-06-23/pdf/2026-12559.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2026-12559.pdf?1782132314","publication_date":"2026-06-23","agencies":[{"raw_name":"OFFICE OF MANAGEMENT AND BUDGET","name":"Management and Budget Office","id":280,"url":"https://www.federalregister.gov/agencies/management-and-budget-office","json_url":"https://www.federalregister.gov/api/v1/agencies/280","parent_id":null,"slug":"management-and-budget-office"},{"raw_name":"Office of Federal Procurement Policy","name":"Federal Procurement Policy Office","id":184,"url":"https://www.federalregister.gov/agencies/federal-procurement-policy-office","json_url":"https://www.federalregister.gov/api/v1/agencies/184","parent_id":280,"slug":"federal-procurement-policy-office"},{"raw_name":"DEPARTMENT OF DEFENSE","name":"Defense Department","id":103,"url":"https://www.federalregister.gov/agencies/defense-department","json_url":"https://www.federalregister.gov/api/v1/agencies/103","parent_id":null,"slug":"defense-department"},{"raw_name":"GENERAL SERVICES ADMINISTRATION","name":"General Services Administration","id":210,"url":"https://www.federalregister.gov/agencies/general-services-administration","json_url":"https://www.federalregister.gov/api/v1/agencies/210","parent_id":null,"slug":"general-services-administration"},{"raw_name":"NATIONAL AERONAUTICS AND SPACE ADMINISTRATION","name":"National Aeronautics and Space Administration","id":301,"url":"https://www.federalregister.gov/agencies/national-aeronautics-and-space-administration","json_url":"https://www.federalregister.gov/api/v1/agencies/301","parent_id":null,"slug":"national-aeronautics-and-space-administration"}],"excerpts":"reporting requirements. This rule proposes to standardize the report and disclosure timeframe to 72 hours from discovery with just one required report. This change aligns with the 72 hours for incident reporting which is the reporting standard in the <span class=\"match\">Cyber Incident Reporting for Critical Infrastructure</span> Act of 2022 and the DoD CUI incident reporting requirements in DFARS 252.204-7012. Providing one standard timeframe for prohibitions and incident reporting simplifies reporting for offerors and contractors. \n This proposed rule also harmonizes the disclosure"},{"title":"Financial Market Utilities","type":"Rule","abstract":"The Board of Governors of the Federal Reserve System (Board) is publishing a final rule amending the requirements relating to operational risk management in the Board's Regulation HH, which applies to certain financial market utilities (FMUs) that have been designated as systemically important (designated FMUs) by the Financial Stability Oversight Council (FSOC) under Title VIII of the Dodd-Frank Wall Street Reform and Consumer Protection Act (the Dodd-Frank Act or Act). The amendments update, refine, and add specificity to the operational risk management requirements in Regulation HH to reflect changes in the operational risk, technology, and regulatory landscape in which designated FMUs operate. The final rule also adopts specific incident- notification requirements.","document_number":"2024-05322","html_url":"https://www.federalregister.gov/documents/2024/03/15/2024-05322/financial-market-utilities","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2024-03-15/pdf/2024-05322.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2024-05322.pdf?1710420317","publication_date":"2024-03-15","agencies":[{"raw_name":"FEDERAL RESERVE SYSTEM","name":"Federal Reserve System","id":188,"url":"https://www.federalregister.gov/agencies/federal-reserve-system","json_url":"https://www.federalregister.gov/api/v1/agencies/188","parent_id":null,"slug":"federal-reserve-system"}],"excerpts":" 86 FR 38182 (July 19, 2021). The Board, OCC, and FDIC issued final third-party risk management guidance for banking organizations in June 2023. 88 FR 37920 (June 9, 2023).\n \n \n \n \n 19 \n  86 FR 66424 (Nov. 23, 2021). Congress also recently enacted the <span class=\"match\">Cyber Incident Reporting for Critical Infrastructure</span> Act of 2022, which requires covered entities to report significant cyber incidents to the Cybersecurity and Infrastructure Agency (“CISA”). \n See \n Public Law 117-103, Div. Y (codified at 6 U.S.C. 681-681g).\n \n \n D. Overview of the Proposal \n \n The"},{"title":"Cyber Incident Notification Requirements for Federally Insured Credit Unions","type":"Rule","abstract":"The National Credit Union Administration (NCUA or agency) is amending Part 748 of its regulations to require a federally insured credit union (FICU) that experiences a reportable cyber incident to report the incident to the NCUA as soon as possible and no later than 72 hours after the FICU reasonably believes that it has experienced a reportable cyber incident. This notification requirement provides an early alert to the NCUA and does not require a FICU to provide a detailed incident assessment to the NCUA within the 72-hour time frame.","document_number":"2023-03682","html_url":"https://www.federalregister.gov/documents/2023/03/01/2023-03682/cyber-incident-notification-requirements-for-federally-insured-credit-unions","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2023-03-01/pdf/2023-03682.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2023-03682.pdf?1677591918","publication_date":"2023-03-01","agencies":[{"raw_name":"NATIONAL CREDIT UNION ADMINISTRATION","name":"National Credit Union Administration","id":335,"url":"https://www.federalregister.gov/agencies/national-credit-union-administration","json_url":"https://www.federalregister.gov/api/v1/agencies/335","parent_id":null,"slug":"national-credit-union-administration"}],"excerpts":"The Board is adopting this final rule largely as proposed to give the NCUA early notice of substantial cyber incidents that have consequences for FICUs as stated in the rule. \n \n Shortly before the Board issued its proposed rule, Congress enacted the <span class=\"match\">Cyber Incident Reporting for Critical Infrastructure</span> Act of 2022 (Cyber Incident Reporting Act) requiring covered entities to report covered cyber incidents to the Cybersecurity and Infrastructure Security Agency (CISA) not later than 72 hours after the entity reasonably believes that a covered cyber"},{"title":"Introduction to the Unified Agenda of Federal Regulatory and Deregulatory Actions-2026","type":"Notice","abstract":"Publication of the 2026 Unified Agenda of Federal Regulatory and Deregulatory Actions represents a key component of the regulatory planning mechanism prescribed in Executive Order (\"E.O.\") 12866, \"Regulatory Planning and Review,\" (58 FR 51735, as amended) and reaffirmed in E.O. 13563, \"Improving Regulation and Regulatory Review,\" (76 FR 3821) and E.O. 14192, \"Unleashing Prosperity Through Deregulation.\" The Regulatory Flexibility Act requires that agencies publish semiannual regulatory agendas in the Federal Register describing regulatory actions they are developing that may have a significant economic impact on a substantial number of small entities (5 U.S.C. 602). The Unified Agenda of Federal Regulatory and Deregulatory Actions (Unified Agenda) helps agencies fulfill all of these requirements. All Federal regulatory agencies have chosen to publish their regulatory agendas as part of this publication. The complete publication of the 2026 Unified Agenda contains 78 Federal agency regulatory agendas available to the public at www.reginfo.gov. The 2026 Unified Agenda publication appearing in the Federal Register includes the agency Regulatory Flexibility Agendas, in accordance with the publication requirements of the Regulatory Flexibility Act. Agency Regulatory Flexibility Agendas contain only those Agenda entries for rules that are likely to have a significant economic impact on a substantial number of small entities and entries that have been selected for periodic review under section 610 of the Regulatory Flexibility Act.","document_number":"2026-16603","html_url":"https://www.federalregister.gov/documents/2026/08/14/2026-16603/introduction-to-the-unified-agenda-of-federal-regulatory-and-deregulatory-actions-2026","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2026-08-14/pdf/2026-16603.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2026-16603.pdf?1786625114","publication_date":"2026-08-14","agencies":[{"raw_name":"REGULATORY INFORMATION SERVICE CENTER","name":"Regulatory Information Service Center","id":449,"url":"https://www.federalregister.gov/agencies/regulatory-information-service-center","json_url":"https://www.federalregister.gov/api/v1/agencies/449","parent_id":null,"slug":"regulatory-information-service-center"}],"excerpts":"Academic Students, Exchange Visitors, and Representatives of Foreign Information Media \n 1653-AA95 \n Final Rule Stage. \n \n \n 84 \n Removal of Updates to Floodplain Management and Protection of Wetlands Regulations \n 1660-AB18 \n Final Rule Stage. \n \n \n 85 \n <span class=\"match\">Cyber Incident Reporting for Critical Infrastructure</span> Act (CIRCIA) Reporting Requirements \n 1670-AA04 \n Final Rule Stage. \n \n \n 86 \n Electronic Bond Transmission \n 1685-AA24 \n Final Rule Stage. \n \n \n \n Department of Housing and Urban Development \n \n Sequence No. \n Title \n \n Regulation\n Identifier No. "}]}