Industry groups are pushing back against the Cybersecurity and Infrastructure Security Agency's pending cyber incident notification regulation, seeking to limit the scope of the rule and reduce the amount of information they must disclose. In town hall meetings hosted by CISA, industry representatives consistently argued that the regulation should apply to fewer entities and require less detailed reporting of cyber incidents1. This feedback comes as CISA seeks to finalize the rule for the 2022 Cyber Incident Reporting for Critical Infrastructure Act, a landmark piece of cyber legislation. The agency has published transcripts from the town halls, providing insight into industry concerns about the regulation. The outcome of this regulatory process will have significant implications for compliance requirements, making it essential for entities to stay informed and assess the potential impact on their operations. So what matters to practitioners is that early assessment of these regulatory changes can create a significant advantage in navigating the evolving compliance landscape.