CISA has now blown two deadlines on the rule that would force more than 300,000 companies to report major cyberattacks within 72 hours and ransom payments within 24. The agency’s 2024 proposed rule implementing the 2022 Cyber Incident Reporting for Critical Infrastructure Act missed its October 2025 statutory deadline, missed a May reset, and now carries a September target industry sources doubt CISA will hit.

Industry showed up to argue the number down. At four June town halls with 1,200 stakeholders, trade groups from auto parts to chemical distribution to nuclear power asked CISA to shrink the covered-entity list, strip security-posture details from reports, and stop counting every firewall ping as a reportable incident. CISA has published the transcripts but given no signal on which asks it’s keeping.

Congress isn’t waiting patiently either. The House Appropriations Committee’s report on the fiscal 2027 DHS spending bill says it’s “concerned about delays” and wants the rule finalized “promptly.”

Here’s the pattern: every disclosure regime, from the SEC’s 2023 cyber rule to CIRCIA now, follows the same arc. Agencies propose broad scope, industry lobbies it down during the comment period, and the final rule lands narrower than drafted. CISA’s acting director frames the law as a national early-warning system for critical infrastructure. A workforce gutted by shutdowns and staff cuts is negotiating that vision on the back foot.

Mark September on the calendar. Industry isn’t betting on it.

Marcus Webb