Federal authorities are nearing the finish line to implement mandatory cyber incident reporting requirements for critical infrastructure, including the nation’s seaports, more than four years after the US Congress enacted landmark cybersecurity legislation. But maritime industry representatives are calling on regulators to cut down on administrative burdens and improve information sharing before the new rules are officially published.
On October 1, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) submitted its final rule implementing the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) to the White House Office of Information and Regulatory Affairs for final executive branch review.
President Joe Biden signed CIRCIA into law in March 2022 to give federal agencies more visibility into emerging cyber dangers. The legislation requires covered entities to notify CISA of significant cyber incidents within 72 hours and ransomware payments within 24 hours. The information is designed to assist the government in coordinating assistance to those organizations affected and to alert other potential targets more quickly.
As the regulation nears publication, feedback from ports, carriers and maritime employers reflects continued concern about how the requirements will work in practice. Industry representatives are especially concerned about the need to avoid duplicative reporting requirements and to ensure that federal agencies provide timely and actionable intelligence.
A single reporting process to avoid duplication
The possibility of redundant federal reporting requirements has emerged as a central concern for the US maritime sector.
CISA’s proposed rule covers facilities regulated under the Maritime Transportation Security Act, which falls under the oversight of the US Coast Guard (USCG). Both agencies operate within the Department of Homeland Security (DHS), raising questions about whether affected organisations could be required to submit similar incident reports to multiple federal authorities.
Maritime industry groups argue that the first hours of a cyberattack are critical to containing damage and restoring operations. Diverting personnel and other limited resources towards duplicate administrative procedures could undermine those efforts.
The Port of Oakland highlighted the potential consequences in its comments on the proposed requirements.
“While we appreciate this support from our federal partners, having to divert limited resources towards excessive and duplicative compliance efforts such as this harms not only our cybersecurity posture, but also our mutual national security interest,” the port cautioned.
The Association of American Port Authorities, the National Association of Waterfront Employers and Matson Navigation, a US-flagged containership operator, are among the organisations advocating for a formal agreement between CISA and the USCG.
Such a CIRCIA Agreement would establish a coordinated reporting arrangement, potentially allowing companies to submit a single cybersecurity incident report to the Coast Guard while satisfying their obligations under CIRCIA.
CISA is working to finalise agreements with the USCG and other federal agencies. Maritime stakeholders want the mechanism to be clearly established in the final regulatory framework to reduce unnecessary duplication and preserve resources for incident response.
Ports call for faster threat intelligence and stronger communication
Beyond reporting procedures, maritime representatives are pressing federal authorities to improve the speed and effectiveness of information sharing.
The Port of Virginia, which also supports an agreement between CISA and the Coast Guard, urged the agency to strengthen the way it communicates cyber incident information to industry stakeholders.
In comments submitted to CISA, the port said it had encountered several situations in which it learned about cyber incidents affecting the maritime sector through media reports rather than direct communication from federal partners. Earlier notifications, it argued, could have helped the port take preventive measures and mitigate threats before they escalated.
The port also criticised delays in the distribution of intelligence that could support operational security decisions.
“Federal agencies are slow to share information and actionable intelligence with ports directly or through industry sharing and analysis groups in a timely manner,” the Port of Virginia stated.
It called for more active engagement from federal partners and a two-way exchange of information that would enable ports to prepare for attacks, respond more effectively to emerging threats and prevent their systems from being compromised.
As CIRCIA advances through its final review, the maritime sector’s message is clear: mandatory reporting must be accompanied by practical coordination between federal agencies and industry operators. A streamlined reporting system and faster intelligence sharing, stakeholders argue, would help strengthen cybersecurity without diverting critical resources from the protection of port infrastructure and national security.





















