Report Smarter, Not Harder: HackerOne's Case for Better CIRCIA Rules
When a cyberattack hits a hospital, a power grid, or a financial institution, speed and clarity matter. Responders need to know what happened, how serious it is, and what it means for the broader national security picture. That's the core promise of the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA): a federal law requiring companies in critical sectors to report significant cybersecurity incidents to the government so threats can be better understood and stopped.
CIRCIA contains good ideas that HackerOne supports. But getting the details right matters enormously, and right now, some of those details need work.
The Cybersecurity and Infrastructure Security Agency (CISA) has been holding a series of town hall meetings this spring and summer to gather input before finalizing the rules that will implement CIRCIA. HackerOne participated in the IT services sector town hall on June 18 and submitted written comments to CISA on June 24. We made three core recommendations.
Focus on the Incidents that Actually Matter
Under the proposed rule, companies would be required to report any "substantial" cyber incident. But the current definition of "substantial" is too broad. As drafted, it could capture almost any loss of access to, or compromise of, a company's systems, regardless of how minor or routine. Think of it as a fire alarm calibrated to go off every time someone burns toast, not just when a building is on fire.
The practical consequence is predictable: CISA could be flooded with reports about low-severity events while analysts strain to find the signals that actually matter. We urged CISA to anchor the definition to real-world impact. Incidents should only be reportable when they cause meaningful harm to operations, end users, public health, national security, economic stability, or civil liberties. CISA already has tools designed for exactly this kind of risk-based assessment, including its own National Cyber Incident Scoring System. Using them to set the reporting threshold would concentrate both government and industry resources where they’re most useful.
Protect Independent Security Researchers
The proposed rule includes a welcome carve-out: cybersecurity testing done at the request of a company, such as through a bug bounty program or a formal vulnerability disclosure policy, would not count as a reportable incident. The gap is what happens when a researcher acts independently, finding and reporting a vulnerability without being formally invited to do so. This kind of unsolicited, good-faith research is routine and valuable. Researchers do it all the time, often to protect organizations that don't yet know they have a problem.
If that research can trigger a CIRCIA reporting obligation for the organization being researched, companies will be less willing to engage constructively with outside researchers, and researchers will think twice before flagging vulnerabilities at all. We asked CISA to close this gap with a simple clarification: good-faith security research should be protected whether or not it was formally requested.
Stop Asking Companies to File the Same report twice
A Department of Homeland Security council identified at least 52 separate federal cyber incident reporting requirements already on the books or in development, not counting state and local obligations. When a company is actively managing an incident, filing separate reports with multiple federal agencies simultaneously doesn't improve the government's visibility. It splits focus and burns resources that should be going toward containment and recovery.
CIRCIA was designed to be the unifying framework that simplifies this landscape. The final rule should adopt a reciprocity principle: if a company has already reported an incident to another federal agency, that report should satisfy CIRCIA's requirements by default, with CISA following up for any additional information it needs. We also renewed our recommendation that CISA publish clear, objective criteria for when another reporting requirement counts as "substantially similar" to CIRCIA's, so companies can reliably know whether they're compliant.
The Bottom Line
CIRCIA can be a genuine asset for national cybersecurity. But achieving that requires a rule that is focused on what matters, fair to the security research community, and realistic about the compliance burden companies face during an active incident. We remain committed to working with CISA to get this right. You can read our full written comments here.
Follow the HackerOne policy blog for expert insights and updates that matter to security leaders.