CISA proposes landmark rule for sweeping cyber incident reporting

CISA has published long-awaited draft rules on how critical-infrastructure companies must report cyberattacks to the government.

In one of the most significant cybersecurity policy reforms in recent memory, the Cybersecurity and Infrastructure Security Agency (CISA, part of the US Department of Homeland Security or DHS) has released its much-anticipated notice of proposed rulemaking (NPOR) to require critical infrastructure organizations to report cybersecurity incidents.

The move is

Free Trial

Register for free to keep reading.

To continue reading this article and unlock full access to GRIP, register now. You’ll enjoy free access to all content until our subscription service launches in early 2026.

  • Unlimited access to industry insights
  • Stay on top of key rules and regulatory changes with our Rules Navigator
  • Ad-free experience with no distractions
  • Regular podcasts from trusted external experts
  • Fresh compliance and regulatory content every day
Register for free Already a member? Sign in