CISA's rescheduled virtual town hall meetings for CIRCIA ransomware reporting requirements (June 15-18, 2026) offer a unique chance for your organization to influence the final rule language. These sessions aren't required by federal rulemaking procedures; CISA is hosting them voluntarily. This means your input can significantly impact the outcome if you prepare effectively.
This checklist is designed to help your regulatory affairs and compliance teams make meaningful contributions. It's for organizations that want their concerns reflected in the regulation, not just to say they participated.
Prerequisites
Before using this checklist, ensure:
- Your organization is part of one of the 16 critical infrastructure sectors listed in the session schedule.
- You have executive support to allocate staff time for drafting and presenting materials.
- You can meet the registration deadline (two business days before your session) and the written submission deadline (seven calendar days after the meeting).
- You've reviewed the current CIRCIA proposed rule language in the rulemaking docket.
If you're a multi-sector organization, decide now whether to attend both your primary sector's session and a general session. The schedule allows for this: General Session 1 (June 15) and General Session 2 (June 17) are available.
Preparation Checklist
1. Map your reporting burden under current draft requirements
Identify every ransomware incident in the past 24 months that would trigger reporting under the proposed rule. Document:
- Time from detection to the proposed reporting deadline
- Information available at each stage
- Information required by the draft rule that you didn't have
Create a spreadsheet showing real incidents with timeline gaps between "what we knew when" and "what CIRCIA would require when," annotated with specific rule section references.
2. Calculate your operational cost delta
Quantify the additional cost of CIRCIA compliance beyond your current incident response process. Include:
- Staff hours for report preparation and submission
- Legal review time
- Technology changes for required data collection
- Ongoing monitoring and validation processes
Develop a cost model broken into one-time implementation and recurring annual costs, with assumptions documented and tied to specific draft rule requirements.
3. Identify ambiguous language that creates compliance risk
Review the draft rule for terms lacking clear definitions or thresholds. Flag:
- Subjective standards ("substantial," "significant," "material")
- Undefined technical terms
- Reporting triggers dependent on information you can't reliably obtain within the required timeframe
Create a table with three columns (ambiguous term, draft rule citation, proposed clarifying language) containing at least five substantive items.
4. Draft alternative language for problematic requirements
For each unworkable requirement, write replacement text that achieves CISA's objective while addressing your operational constraints. Use the rule's existing structure and numbering.
Provide redline edits showing current draft language struck through and your proposed language added, with a brief rationale explaining why your version better serves the rule's purpose.
5. Build your coalition position
Coordinate with peer organizations in your sector. Identify:
- Shared concerns multiple organizations will raise
- Unique issues specific to your operational model
- Technical expertise you can offer (threat intelligence, incident data, implementation experience)
Prepare a one-page summary of consensus positions from at least three peer organizations, with contact information for each, demonstrating that your concerns aren't outliers.
6. Prepare your town hall presentation
Assume limited speaking time and structure your intervention:
- Open with your sector and organization type (don't name your company unless comfortable with public attribution)
- State your core concern in one sentence
- Provide one concrete example
- Offer your proposed solution
- Close with your willingness to provide additional technical detail
Prepare a 90-second script that you've practiced, with a backup 30-second version if time runs short.
7. Compile your written submission package
Assemble materials for submission within seven calendar days after your session:
- Cover letter summarizing your key points
- Detailed comments organized by rule section
- Supporting documentation (cost analyses, technical specifications, incident examples with sensitive details redacted)
- Proposed alternative language
Ensure your submission package is under 25 pages (excluding appendices) for a CISA rulemaking officer to review in 30 minutes and extract three actionable recommendations.
8. Register before the deadline
Submit your registration at CISA's website no later than two business days before your target session. If attending multiple sessions, register for each separately.
Set calendar reminders for June 11 (Group A sectors), June 13 (General Session 1), and June 15 (Group B sectors), with registration confirmations saved.
Common Mistakes
Treating this as a listening session. CISA already published a proposed rule. They're gathering input on that specific text, not conducting open-ended discovery. Your comments should reference section numbers and propose concrete changes.
Submitting generic concerns. "This will be expensive" doesn't move the needle. "Section 4.2(b) requires threat actor attribution within 72 hours, but our IR team typically needs 5-7 days to complete forensic analysis with sufficient confidence" gives CISA something to work with.
Ignoring the written submission deadline. The seven-day window after each session is firm. Materials submitted later may not be considered part of the official rulemaking record. Start drafting before the town hall, not after.
Failing to coordinate sector-wide. CISA will give more weight to concerns raised by multiple organizations with supporting data than to isolated complaints. If you and four peer organizations independently raise the same issue with different proposed solutions, you've diluted your impact.
Next Steps
After submitting your written materials:
- Monitor the rulemaking docket for CISA's responses to comments and any supplemental notices
- Track whether your proposed language or concerns appear in revised draft text
- Prepare for potential follow-up requests from CISA staff seeking clarification
- Document your participation internally to demonstrate proactive regulatory engagement to your board or executive team
The funding impasse that forced CISA to reschedule these sessions shows how external factors can disrupt regulatory timelines. Don't assume you'll get another opportunity if you miss this one. The discretionary nature of these town halls means CISA could conclude the comment period without further public engagement if they determine they've gathered sufficient input.
Your goal isn't to stop CIRCIA. It's to shape the final rule so your organization can comply without breaking your incident response process or your budget.





