The Cybersecurity and Infrastructure Security Agency (CISA) plans to finalize the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) rule this fall. You'll need a standardized process to meet the 72-hour cyber incident reporting requirement and the 24-hour ransomware payment reporting window.
This template provides a structure for documenting and submitting incident reports to CISA. It's based on the draft CIRCIA requirements, designed to capture what CISA needs while keeping your internal incident response moving.
Purpose of the Template
This template helps document cyber incidents affecting covered entities across the 16 critical infrastructure sectors CIRCIA covers. Use it to:
- Structure your 72-hour incident notification to CISA
- Track ransomware payment decisions requiring 24-hour reporting
- Maintain internal records supporting your CIRCIA obligations
- Coordinate incident details across your security operations, legal, and compliance teams
The template complements your incident response playbook. It provides a compliance-focused reporting structure that aligns with CISA's requirements without duplicating your operational documentation.
Prerequisites
Before customizing this template:
Determine your coverage status. Not every organization falls under CIRCIA. You're covered if you operate in one of the 16 critical infrastructure sectors and meet the final rule's entity definitions. The draft rules have been criticized for ambiguity, so expect clarification when CISA publishes the final version.
Map your existing reporting obligations. A Government Accountability Office report found that roughly 70% of the 117 incident reporting regulations reviewed overlap with other requirements. If you're already reporting to sector-specific regulators, coordinate your CIRCIA template with those processes. Avoid parallel documentation streams that drift out of sync.
Establish incident severity thresholds. CIRCIA doesn't require reporting every security event. Define what constitutes a reportable incident under the final rule's criteria. Your security operations center needs clear triggers for when an event escalates to a CIRCIA-reportable incident.
Identify your ransomware payment authority. The 24-hour ransomware payment reporting window is tight. Document who in your organization has authority to approve ransom payments and how that decision gets escalated. You can't meet a 24-hour deadline if your approval chain takes 48 hours to reach a decision.
The Template
CIRCIA INCIDENT REPORT
SECTION 1: ENTITY INFORMATION
Organization Legal Name: _______________
Primary Contact Name: _______________
Primary Contact Title: _______________
Primary Contact Email: _______________
Primary Contact Phone: _______________
Critical Infrastructure Sector: _______________
CISA Registration ID: _______________
SECTION 2: INCIDENT IDENTIFICATION
Incident Detection Date/Time (UTC): _______________
Incident Detection Method: [ ] SIEM Alert [ ] User Report
[ ] Third-Party Notification [ ] Audit Finding [ ] Other: _______
Initial Severity Assessment: [ ] High [ ] Medium [ ] Low
Incident Classification: [ ] Unauthorized Access [ ] Data Exfiltration
[ ] Ransomware [ ] Denial of Service [ ] Supply Chain Compromise
[ ] Other: _______________
SECTION 3: AFFECTED SYSTEMS AND DATA
Systems Affected: _______________
System Classification: [ ] Operational Technology [ ] IT Systems
[ ] Cloud Services [ ] Third-Party Systems
Data Types Involved: [ ] CUI [ ] PII [ ] Proprietary
[ ] Operational Data [ ] None Identified [ ] Under Investigation
Estimated Number of Records/Users Affected: _______________
SECTION 4: INCIDENT DESCRIPTION
Describe the incident, including known or suspected threat actor TTPs,
initial access vector, and timeline of key events:
_______________________________________________________________
Current Containment Status: [ ] Contained [ ] Partially Contained
[ ] Not Contained [ ] Unknown
SECTION 5: IMPACT ASSESSMENT
Business Operations Impact: [ ] Critical [ ] Significant
[ ] Minimal [ ] None [ ] Under Assessment
Safety/Health Impact: [ ] Yes [ ] No [ ] Potential [ ] Unknown
Service Disruption Duration (if applicable): _______________
Estimated Financial Impact: _______________
SECTION 6: RANSOMWARE PAYMENT (if applicable)
Ransomware Demand Received: [ ] Yes [ ] No
Demand Amount: _______________
Payment Currency: [ ] Bitcoin [ ] Other Cryptocurrency [ ] Other: _____
Payment Decision: [ ] Paid [ ] Declined [ ] Under Consideration
Payment Date/Time (UTC): _______________
Wallet Address (if known): _______________
SECTION 7: RESPONSE ACTIONS
Immediate Response Actions Taken:
_______________________________________________________________
Law Enforcement Notification: [ ] Yes [ ] No [ ] Pending
Law Enforcement Agency: _______________
Other Regulatory Notifications Made: _______________
SECTION 8: ONGOING INVESTIGATION
Known or Suspected Threat Actor: _______________
Indicators of Compromise Identified: _______________
Forensic Investigation Status: [ ] Initiated [ ] In Progress
[ ] Completed [ ] Not Started
Third-Party Incident Response Support: [ ] Yes [ ] No
If yes, firm name: _______________
SECTION 9: SUPPLEMENTAL REPORT TRACKING
Initial Report Submission Date/Time: _______________
CISA Confirmation Number: _______________
Supplemental Report 1 Date: _______________
Supplemental Report 2 Date: _______________
Final Report Date: _______________
SECTION 10: INTERNAL USE
Incident Response Team Lead: _______________
Legal Review Completed By: _______________
Executive Notification Date: _______________
Board Notification Required: [ ] Yes [ ] No
Board Notification Date: _______________
Customizing the Template
Align Section 1 with your CISA registration. When you register as a covered entity under CIRCIA, CISA will assign you an identifier. Pre-populate this section with your registration details so your team doesn't hunt for this information during an active incident.
Tailor Section 2 detection methods to your monitoring stack. The template lists common detection sources, but your environment might include specialized tools. Add detection methods that match your security operations center's workflow so analysts can quickly categorize how they identified the incident.
Adjust Section 3 for your system inventory. If you operate operational technology environments, expand the system classification options to reflect your OT architecture. Critical infrastructure operators often need more granular OT categorization than the generic buckets here provide.
Expand Section 4 for sector-specific context. Electric utilities need different operational details than hospitals. Customize this section to capture what matters for your sector's risk profile. If you're in healthcare, you might add fields for affected clinical systems. If you're in energy, you might track grid impact.
Link Section 6 to your payment decision tree. The 24-hour ransomware payment reporting requirement means you need a fast decision process. Document your payment authority chain and decision criteria in your incident response playbook, then reference that process here. Don't make payment decisions during an active incident without a pre-established framework.
Coordinate Section 7 with existing reporting obligations. This is where the 70% regulatory overlap identified by GAO becomes operational. If you're subject to Securities and Exchange Commission disclosure rules, DFARS 252.204-7012 reporting requirements, or sector-specific regulations, note those parallel notifications here. Avoid submitting conflicting timelines or impact assessments to different regulators.
Use Section 9 to manage the supplemental reporting cycle. CIRCIA's 72-hour window starts your reporting obligation, but it doesn't end it. Most incidents require supplemental reports as your investigation progresses. Track your submission dates and CISA confirmation numbers to demonstrate continuous reporting compliance during audits.
Validation Steps
Test your reporting path before you need it. Walk through the template with a tabletop exercise. Time how long it takes your team to populate each section during a simulated incident. If you can't complete the core sections within 48 hours of detection, you won't meet the 72-hour reporting window when managing containment, forensics, and business continuity simultaneously.
Verify your ransomware payment notification process. The 24-hour requirement for ransomware payments is tighter than the standard 72-hour incident window. Run a scenario where your team discovers ransomware at 5 PM on a Friday. Can you reach decision-makers, assess payment options, and submit a CIRCIA report within 24 hours? If not, document your after-hours escalation process now.
Cross-check against your other reporting templates. If you're using incident report templates for DFARS 252.204-7012, sector-specific regulations, or cyber insurance claims, compare the data elements. Inconsistent incident descriptions across regulatory reports create audit risk. Harmonize your templates so the core facts stay consistent even when reporting requirements differ.
Review with legal counsel. National Cyber Director Sean Cairncross noted that organizations sometimes hesitate to engage law enforcement due to regulatory or liability concerns. Your legal team should review this template to ensure it doesn't inadvertently create privilege issues or complicate your litigation posture if the incident leads to lawsuits or regulatory enforcement.
When CISA publishes the final CIRCIA rule, update this template immediately. The draft rules drew criticism for being overly broad and ambiguous. Expect the final version to clarify entity definitions, incident thresholds, and reporting procedures. Don't wait for your first reportable incident to discover that your template doesn't match the final requirements.





