{"id":952,"date":"2026-10-09T11:33:27","date_gmt":"2026-10-09T11:33:27","guid":{"rendered":"https:\/\/regulasshipping.com\/blog\/us-ports-press-for-a-single-circia-report-as-cisa-rule-hits-oira\/"},"modified":"2026-10-09T11:34:27","modified_gmt":"2026-10-09T11:34:27","slug":"us-ports-press-for-a-single-circia-report-as-cisa-rule-hits-oira","status":"publish","type":"post","link":"https:\/\/regulasshipping.com\/blog\/us-ports-press-for-a-single-circia-report-as-cisa-rule-hits-oira\/","title":{"rendered":"US ports press for a single CIRCIA report as CISA rule hits OIRA"},"content":{"rendered":"<p>The White House Office of Information and Regulatory Affairs received the Cybersecurity and Infrastructure Security Agency\u2019s final rule implementing the Cyber Incident Reporting for Critical Infrastructure Act of 2022 on Thursday, 1 October. The pending Executive Order 12866 review is logged under RIN 1670-AA04, title \u201cCyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements,\u201d agency DHS \/ CISA, stage Final Rule, legal deadline Statutory. Covington\u2019s 8 October note and John Gallagher\u2019s 9 October Seatrade Maritime write-through are the industry reads of that docket. The final text is not in the Federal Register. It is not in force. It does not change the Coast Guard\u2019s already-effective Marine Transportation System cybersecurity rule, and it is not a US port-entry instrument.<\/p>\n<p>CIRCIA, enacted in March 2022 as Division Y of the Consolidated Appropriations Act, directs CISA to collect reports of covered cyber incidents within 72 hours and ransom payments within 24 hours. CISA published its notice of proposed rulemaking on 4 April 2024. The NPRM estimated coverage of about 316,000 entities across all 16 critical-infrastructure sectors. After hundreds of comments, CISA held town halls in June 2026. Thursday\u2019s OIRA receipt is the last executive-review step before publication. OIRA review can run up to 90 days, or longer if extended, which would push Federal Register publication into early 2027. Implementing regulations are unlikely to take effect for at least 60 days after publication. The precise effective date will be in the final rule text, not in the 1 October receipt stamp.<\/p>\n<h2>What ports and carriers are actually asking for<\/h2>\n<p>Seatrade\u2019s 9 October piece is the maritime sector\u2019s read, not a substitute for the unpublished final rule. The Association of American Port Authorities, the National Association of Waterfront Employers and US-flag containership operator Matson Navigation are pressing for a formal CIRCIA Agreement between CISA and the Coast Guard so that a single cyber incident report to the Coast Guard can satisfy CIRCIA. The Port of Oakland told CISA that diverting limited resources to duplicative compliance \u201charms not only our cybersecurity posture, but also our mutual national security interest.\u201d The Port of Virginia, which also wants a CISA\u2013Coast Guard reporting agreement, said it has learned of several maritime cyber incidents from news reports rather than from federal partners, and that early notification would have allowed earlier threat mitigation. Virginia asked for two-way communication so ports can prepare, respond and prevent compromise.<\/p>\n<p>That overlap is not a hypothetical. CISA\u2019s 2024 NPRM itself said the proposed approach for the maritime sector \u201cwill result in two separate cyber incident reporting requirements for entities that are subject to both [the Maritime Transportation Security Act] and CIRCIA.\u201d CISA and the Coast Guard said they were committed to exploring the \u201csubstantially similar reporting\u201d exception, or other mechanisms, so that an MTSA entity could comply with both regimes through one report. AAPA\u2019s earlier comments argued that, once the Coast Guard\u2019s Marine Transportation System cybersecurity rule is fully implemented, ports should qualify for that exception. No published CIRCIA Agreement is on the 1 October OIRA record. Do not brief a single-portal deal as already signed.<\/p>\n<h2>The Coast Guard rule that is already running<\/h2>\n<p>The Coast Guard\u2019s Cybersecurity in the Marine Transportation System final rule was published on 17 January 2025, became effective on 16 July 2025, and is codified at 33 CFR Parts 101 and 160. It applies to US-flagged vessels, Outer Continental Shelf facilities, and facilities regulated under the Maritime Transportation Security Act of 2002. From 16 July 2025, regulated entities must report \u201creportable cyber incidents\u201d to the National Response Center without delay. By 12 January 2026, personnel with access to information-technology or operational-technology systems were required to complete initial cybersecurity training. By 16 July 2027, owners and operators must designate a Cybersecurity Officer, conduct a Cybersecurity Assessment, and submit a Cybersecurity Plan to the Coast Guard for approval. CRS, writing in June 2026 as R49009, recorded that the Coast Guard had separately asked whether a two-to-five-year additional delay should be granted for US-flagged vessels; as of that report, no final decision on that delay had been published.<\/p>\n<p>The definitions and clocks do not match CIRCIA\u2019s statute. The Coast Guard product is an immediate NRC report of a reportable cyber incident, plus a phased plan, officer and training regime. CIRCIA\u2019s statute is a 72-hour covered-cyber-incident report and a 24-hour ransom-payment report to CISA. TSA\u2019s still-proposed surface cyber rule is a third overlay for high-risk pipeline, freight-rail, passenger-rail and bus operators, with a proposed 24-hour report to CISA. A marine terminal that also handles a pipeline or rail interface can sit under more than one of those clocks. CRS put the CIRCIA NPRM\u2019s estimated population at about 316,000 entities and TSA\u2019s at about 293 high-risk operators. Those figures are NPRM estimates, not the unpublished CIRCIA final rule\u2019s scope.<\/p>\n<h2>Operational implications<\/h2>\n<p>An OIRA receipt is a process fact. It is not a reporting instruction, not a covered-entity list, and not a reason to retire the NRC number. Until the final rule is published and effective, MTSA facilities and US-flag vessels keep reporting reportable cyber incidents to the NRC without delay under 33 CFR, keep the January 2026 training box, and keep the July 2027 CySO \/ assessment \/ plan clock. A DPA who treats Thursday as \u201cCIRCIA is live\u201d will file to the wrong desk on the wrong timeline. A DPA who treats Thursday as \u201cnothing to do until 2027\u201d will walk into a dual-report week with no playbook for which facts go to the NRC, which facts would later go to CISA, and which ransom-payment facts have a 24-hour statutory fuse.<\/p>\n<p>The useful work in this window is the matrix, not a new SMS annex written against an unseen final text. Identify which hulls, terminals, OCS units and MTSA facilities you operate that already sit under the Coast Guard rule. Identify which of those would also be a CIRCIA covered entity if the final rule stays close to the NPRM\u2019s 16-sector scope. Write a single incident-response timeline that can spawn an immediate NRC report and, if the final rule so requires, a 72-hour CISA report and a 24-hour ransom-payment report, without making the watchstander fill two forms in the first hour. Watch OIRA and the Federal Register for whether a CIRCIA Agreement, or a substantially similar reporting exception, actually appears in the final text. AAPA, NAWE and Matson have asked for that exception. They have not been given it in a published instrument.<\/p>\n<p>Do not recast 1 October as a completed CISA regulation, a worldwide port cyber code, a substitute for the Coast Guard MTS rule, or a US port-entry denial. Do not fold it into a Hormuz kinetic file or into an unpublished Holland &amp; Knight \/ MTS CYBER Act recap. The confirmed facts are RIN 1670-AA04 at OIRA as a Final Rule received 1 October, the statutory 72-hour \/ 24-hour CIRCIA clocks, the Coast Guard\u2019s already-running NRC-without-delay duty, and a maritime-sector request for one report that has not yet been granted in the public docket.<\/p>\n<h2>What Operators Should Note<\/h2>\n<ul>\n<li><strong>Keep the NRC report. Thursday is not a CIRCIA effective date.<\/strong> RIN 1670-AA04, received by OIRA on 1 October, stage Final Rule, review pending. Publication may take up to 90 days or longer. Effectiveness is likely at least 60 days after Federal Register publication and will be stated in the final text. Do not file a CIRCIA report against an unpublished rule, and do not stop reporting reportable cyber incidents to the National Response Center without delay under 33 CFR Parts 101 and 160.<\/li>\n<li><strong>Separate the three clocks before you write a playbook.<\/strong> Coast Guard MTS rule: immediate NRC notice, training from 12 January 2026, CySO \/ assessment \/ Cybersecurity Plan by 16 July 2027, for US-flag vessels, OCS facilities and MTSA facilities. CIRCIA statute: 72 hours for a covered cyber incident and 24 hours for a ransom payment, to CISA, once the final rule is effective. TSA\u2019s surface NPRM is a third, still-proposed 24-hour CISA report for designated high-risk pipeline and rail operators. A terminal with a pipeline or rail interface can sit on more than one line.<\/li>\n<li><strong>Do not brief a single-portal deal as signed.<\/strong> AAPA, NAWE and Matson want a CIRCIA Agreement so one Coast Guard report satisfies CIRCIA. CISA\u2019s NPRM acknowledged two separate MTSA\/CIRCIA reporting requirements and said it would explore a substantially similar reporting exception. Oakland warned that duplicate paperwork harms incident response. Virginia said it has learned of maritime cyber incidents from the press, not from federal partners. None of that is a published exception. Watch the final rule text, not the comment letters, for whether one filing will count.<\/li>\n<li><strong>Size coverage against the NPRM, then wait for the final list.<\/strong> The April 2024 NPRM estimated about 316,000 covered entities across 16 sectors. That is the proposal CISA took to June 2026 town halls, not the unpublished final scope. A foreign-flag operator calling a US MTSA terminal is not, on the Coast Guard rule, in the vessel-side CySO box unless the hull is US-flag; the terminal still is. Do not assume a CIRCIA covered-entity definition until RIN 1670-AA04 is printed.<\/li>\n<li><strong>Build one incident file that can feed two desks.<\/strong> In the first hour, the watchstander should be containing the incident and calling the NRC if the event is a reportable cyber incident under 33 CFR, not completing a second federal form. Preserve facts that a later 72-hour CISA report or 24-hour ransom-payment report would need: systems affected, OT versus IT, whether a ransom was paid, when the entity became aware. Do not wait for OIRA to finish before naming the CySO-equivalent who will own that file.<\/li>\n<li><strong>Keep this off the Coast Guard STCW NPRM, off passenger-ship familiarization, and off Hormuz.<\/strong> Docket USCG-2025-0392 is a credentialing proposal. Docket USCG-2022-0649 is the 26 October passenger emergency-familiarization final rule. RIN 1670-AA04 is a CISA reporting rule at OIRA. They do not substitute for one another, and none of them is a transit-warning product.<\/li>\n<\/ul>\n<p>Regulas Shipping will keep lining RIN 1670-AA04\u2019s OIRA clock against the Coast Guard\u2019s already-running NRC-without-delay duty so operators can treat CIRCIA as a coming dual-report problem, not as a live CISA filing obligation or a reason to retire the National Response Center.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The White House Office of Information and Regulatory Affairs received the Cybersecurity and Infrastructure Security Agency\u2019s final rule implementing the Cyber Incident Reporting for Critical Infrastructure Act of 2022 on Thursday, 1 October. The pending Executive Order 12866 review is logged under RIN 1670-AA04, title \u201cCyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements,\u201d [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":949,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"wpai_generated_summary":"","wpai_meta_description":"","footnotes":""},"categories":[26,20,4,6],"tags":[],"class_list":["post-952","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-highlights","category-maritime-regulations","category-maritime-security","category-regulatory-updates"],"_links":{"self":[{"href":"https:\/\/regulasshipping.com\/blog\/wp-json\/wp\/v2\/posts\/952","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/regulasshipping.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/regulasshipping.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/regulasshipping.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/regulasshipping.com\/blog\/wp-json\/wp\/v2\/comments?post=952"}],"version-history":[{"count":1,"href":"https:\/\/regulasshipping.com\/blog\/wp-json\/wp\/v2\/posts\/952\/revisions"}],"predecessor-version":[{"id":953,"href":"https:\/\/regulasshipping.com\/blog\/wp-json\/wp\/v2\/posts\/952\/revisions\/953"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/regulasshipping.com\/blog\/wp-json\/wp\/v2\/media\/949"}],"wp:attachment":[{"href":"https:\/\/regulasshipping.com\/blog\/wp-json\/wp\/v2\/media?parent=952"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/regulasshipping.com\/blog\/wp-json\/wp\/v2\/categories?post=952"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/regulasshipping.com\/blog\/wp-json\/wp\/v2\/tags?post=952"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}