Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA)

Enacted: March 15, 2022
Administered by: Cybersecurity and Infrastructure Security Agency (CISA)
Purpose: To improve national cybersecurity by requiring timely reporting of cyber incidents and ransomware payments by critical infrastructure entities.

🧭 Key Objectives

  • Early warning system: Enable the federal government to detect and respond to major cyber threats faster.
  • Information sharing: Facilitate coordinated defense across sectors.
  • Accountability: Ensure critical infrastructure operators take cybersecurity seriously.

🏛️ Who Must Comply?

Entities in critical infrastructure sectors, including:

  • Energy
  • Financial services
  • Healthcare
  • Transportation
  • Water and wastewater
  • Communications
  • Information technology
  • Food and agriculture
  • Government facilities
  • Emergency services
  • Chemical, nuclear, and defense sectors

CISA defines covered entities based on size, function, and risk profile.

📅 Reporting Requirements

  1. Cyber Incidents

Covered entities must report substantial cyber incidents to CISA within 72 hours of discovery.

Examples include:

  • Unauthorized access to systems
  • Disruption of operations
  • Data breaches affecting sensitive or operational data
  • Attacks that cause significant operational impact
  1. Ransomware Payments

Entities must report ransom payments to CISA within 24 hours of making the payment.

📄 What Must Be Reported?

Reports must include:

  • Description of the incident or ransomware attack
  • Affected systems and services
  • Timing and discovery details
  • Mitigation steps taken
  • Contact information for follow-up

CISA may request supplemental information as investigations progress.

🔐 Protections for Reporting Entities

  • No liability for good-faith reporting
  • Confidentiality protections for submitted information
  • Exemption from FOIA disclosure
  • No waiver of legal privileges

These protections are designed to encourage prompt and honest reporting.

🧩 Enforcement and Penalties

CISA has authority to:

  • Issue subpoenas for noncompliance
  • Refer cases to the Department of Justice
  • Impose civil penalties for failure to report

🛠️ Implementation Timeline

  • Rulemaking process began in 2022
  • Final rule expected by 2025
  • Full enforcement begins after final rule is published

CISA is currently developing the regulatory framework, including definitions, procedures, and reporting portals.

See Also