Covered Cyber Incident
A covered cyber incident is a serious computer security event experienced by an organization that falls within a defined category of critical infrastructure and is therefore subject to mandatory reporting obligations. The concept comes from a U.S. federal law focused on getting timely reports of major cyber events. What specifically qualifies as "substantial" is set out in regulations that you should verify against the current official text.
As proposed by CISA under the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), a "covered cyber incident" is defined to mean a substantial cyber incident experienced by a covered entity. A cyber incident, per the NIST CSRC glossary, is an occurrence that actually or imminently jeopardizes, without lawful authority, the confidentiality, integrity, or availability of information or an information system. Under CIRCIA, the scope of what constitutes a "substantial" incident and which organizations are "covered entities" is established by CISA's implementing regulations, and can include incidents arising from a compromise at a vendor, managed service provider, or cloud provider that results in unauthorized access to a covered entity's systems. Practitioners should note that this term is specific to the CIRCIA regulatory framework and is distinct from incident definitions used in other regimes such as DFARS 252.204-7012 or agency FISMA reporting; because the CIRCIA rulemaking has been proceeding through phases, the precise qualifying criteria, thresholds, and effective dates should be confirmed against the current authoritative regulatory text.
Why it matters
The concept of a "covered cyber incident" is central to a shift in U.S. cyber policy toward mandatory, timely reporting of major cyber events affecting critical infrastructure. Under the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), organizations that qualify as covered entities may be required to report incidents that meet the "substantial" threshold within timeframes established by CISA's implementing regulations. For compliance officers and security leaders, correctly identifying whether an event is a covered cyber incident determines whether a reporting clock starts, making it a threshold determination with direct regulatory consequences rather than an internal classification exercise.
Who it's relevant to
Inside Covered Cyber Incident
Common questions
Answers to the questions practitioners most commonly ask about Covered Cyber Incident.