Enacted: March 15, 2022
Administered by: Cybersecurity and Infrastructure Security Agency (CISA)
Purpose: To improve national cybersecurity by requiring timely reporting of cyber incidents and ransomware payments by critical infrastructure entities.
🧭 Key Objectives
- Early warning system: Enable the federal government to detect and respond to major cyber threats faster.
- Information sharing: Facilitate coordinated defense across sectors.
- Accountability: Ensure critical infrastructure operators take cybersecurity seriously.
🏛️ Who Must Comply?
Entities in critical infrastructure sectors, including:
- Energy
- Financial services
- Healthcare
- Transportation
- Water and wastewater
- Communications
- Information technology
- Food and agriculture
- Government facilities
- Emergency services
- Chemical, nuclear, and defense sectors
CISA defines covered entities based on size, function, and risk profile.
📅 Reporting Requirements
- Cyber Incidents
Covered entities must report substantial cyber incidents to CISA within 72 hours of discovery.
Examples include:
- Unauthorized access to systems
- Disruption of operations
- Data breaches affecting sensitive or operational data
- Attacks that cause significant operational impact
- Ransomware Payments
Entities must report ransom payments to CISA within 24 hours of making the payment.
📄 What Must Be Reported?
Reports must include:
- Description of the incident or ransomware attack
- Affected systems and services
- Timing and discovery details
- Mitigation steps taken
- Contact information for follow-up
CISA may request supplemental information as investigations progress.
🔐 Protections for Reporting Entities
- No liability for good-faith reporting
- Confidentiality protections for submitted information
- Exemption from FOIA disclosure
- No waiver of legal privileges
These protections are designed to encourage prompt and honest reporting.
🧩 Enforcement and Penalties
CISA has authority to:
- Issue subpoenas for noncompliance
- Refer cases to the Department of Justice
- Impose civil penalties for failure to report
🛠️ Implementation Timeline
- Rulemaking process began in 2022
- Final rule expected by 2025
- Full enforcement begins after final rule is published
CISA is currently developing the regulatory framework, including definitions, procedures, and reporting portals.
