Skip to main content
Category: Incident Response & Reporting

Covered Cyber Incident

Simply put

A covered cyber incident is a serious computer security event experienced by an organization that falls within a defined category of critical infrastructure and is therefore subject to mandatory reporting obligations. The concept comes from a U.S. federal law focused on getting timely reports of major cyber events. What specifically qualifies as "substantial" is set out in regulations that you should verify against the current official text.

Formal definition

As proposed by CISA under the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), a "covered cyber incident" is defined to mean a substantial cyber incident experienced by a covered entity. A cyber incident, per the NIST CSRC glossary, is an occurrence that actually or imminently jeopardizes, without lawful authority, the confidentiality, integrity, or availability of information or an information system. Under CIRCIA, the scope of what constitutes a "substantial" incident and which organizations are "covered entities" is established by CISA's implementing regulations, and can include incidents arising from a compromise at a vendor, managed service provider, or cloud provider that results in unauthorized access to a covered entity's systems. Practitioners should note that this term is specific to the CIRCIA regulatory framework and is distinct from incident definitions used in other regimes such as DFARS 252.204-7012 or agency FISMA reporting; because the CIRCIA rulemaking has been proceeding through phases, the precise qualifying criteria, thresholds, and effective dates should be confirmed against the current authoritative regulatory text.

Why it matters

The concept of a "covered cyber incident" is central to a shift in U.S. cyber policy toward mandatory, timely reporting of major cyber events affecting critical infrastructure. Under the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), organizations that qualify as covered entities may be required to report incidents that meet the "substantial" threshold within timeframes established by CISA's implementing regulations. For compliance officers and security leaders, correctly identifying whether an event is a covered cyber incident determines whether a reporting clock starts, making it a threshold determination with direct regulatory consequences rather than an internal classification exercise.

Who it's relevant to

Compliance Officers and Legal Counsel
Those responsible for regulatory obligations need to determine whether their organization is a covered entity under CIRCIA and whether a given event meets the substantial-incident threshold that triggers reporting. They should track the phased rulemaking and confirm current criteria and deadlines against the authoritative regulatory text, and should not assume that CIRCIA obligations are satisfied by reporting done under DFARS 252.204-7012 or FISMA processes.
Information System Security Managers and Incident Responders
Personnel who classify and respond to security events must be able to apply the covered cyber incident definition at the moment an event is detected, since that determination may start a reporting clock. This includes recognizing that a compromise at a vendor, MSP, or cloud provider that results in unauthorized access to their systems can qualify, which requires visibility into third-party and supply chain exposure.
Critical Infrastructure Operators
Organizations that may be designated as covered entities under CISA's implementing regulations should assess whether they fall within the defined categories and prepare processes to identify and report substantial cyber incidents. Because covered-entity scope is set by the rulemaking and has been established in phases, operators should verify their status and obligations against current official sources.
Vendors, Managed Service Providers, and Cloud Providers
Third-party service providers should understand that a compromise on their side can constitute a covered cyber incident for a customer that is a covered entity when it results in unauthorized access to that customer's systems. This makes contractual notification arrangements and coordinated incident handling with covered-entity customers a practical consideration.

Inside Covered Cyber Incident

Statutory and Regulatory Basis
The term 'covered cyber incident' is defined primarily in the context of the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA), for which CISA is the implementing authority. Readers should note that CIRCIA reporting obligations depend on final implementing regulations, and the precise scope and effective dates should be verified against the current published rule.
Substantial Cyber Incident Threshold
A covered cyber incident generally refers to a substantial cyber incident experienced by a covered entity, as those terms are defined in the applicable statute and implementing regulation. The threshold of what qualifies as 'substantial' is set through the rulemaking process, so the specific criteria should be confirmed against the current authoritative text rather than assumed.
Covered Entity Scope
Applicability is tied to whether an organization is a 'covered entity' within a critical infrastructure sector, as determined by the implementing regulation. This scope is distinct from CUI-based obligations under DFARS clause 252.204-7012 or DoD RMF requirements, and readers should confirm which regime applies to their systems.
Reporting Obligation and Timeline
A covered cyber incident triggers a reporting obligation to CISA within a timeframe established by the implementing regulation. The exact reporting window and ransom payment reporting requirements should be verified against the finalized rule, as these are set through rulemaking and may be subject to change.
Relationship to Other Incident Reporting Regimes
The CIRCIA 'covered cyber incident' concept is separate from the cyber incident reporting requirements applicable to defense contractors under DFARS clause 252.204-7012, which requires reporting to DoD, and from FISMA-based incident reporting for federal agencies. These regimes have different authorities, thresholds, and recipients.

Common questions

Answers to the questions practitioners most commonly ask about Covered Cyber Incident.

Is a covered cyber incident the same thing as any data breach affecting my organization?
No. "Covered cyber incident" is a defined term tied to specific reporting regimes rather than a general synonym for any breach. The scope depends on the governing authority invoking the term, and not every security event or data breach will meet the definition of a covered cyber incident under a given rule. You should confirm the precise definition in the applicable regulation or contract clause, because the triggering criteria, covered entities, and affected system or information categories differ across regimes and may change across revisions.
Once I report a covered cyber incident, does that reporting obligation satisfy all my other incident-reporting requirements?
Not necessarily. Reporting a covered cyber incident under one authority generally does not automatically satisfy separate reporting obligations that may arise under other frameworks, contract clauses, or agency-specific requirements. An organization operating across federal civilian, defense, or national security contexts may face multiple, overlapping reporting duties with different recipients, thresholds, and timelines. You should verify each applicable obligation against its current authoritative text rather than assuming a single report discharges all of them.
How do I determine whether a specific event qualifies as a covered cyber incident?
Begin by identifying which authority or contract clause governs your systems and information, then apply the defining criteria in that specific text. The determination generally turns on factors such as the category of affected information or system, the nature and effect of the event, and the covered entities to which the rule applies. Because these criteria are established in the governing publication or regulation and may be tailored or revised, you should confirm the current controlling language and, where the interpretation is unclear, consult your compliance or legal function.
What timeframe applies for reporting a covered cyber incident?
Reporting timeframes are set by the specific governing regime and can differ substantially across authorities. This entry does not fix a particular deadline because such figures vary by rule and revision. To avoid missing a mandatory window, identify the applicable authority or contract clause and verify its stated reporting timeline in the current official source, and build internal procedures that account for the shortest applicable deadline you are subject to.
Who within an organization should be responsible for identifying and reporting covered cyber incidents?
Responsibility is typically assigned through internal policy rather than dictated uniformly by the term itself, though the governing regime identifies the covered entity that bears the obligation. In most implementations, roles such as the information system security manager, incident response team, and compliance or legal personnel coordinate identification, assessment, and reporting. You should map these responsibilities against the specific requirements applicable to your systems and confirm accountability in writing, since the details are organization- and regime-specific.
What information generally needs to be captured to support a covered cyber incident report?
The required content is specified by the applicable reporting regime, so you should consult that governing text for the definitive list. As a practical matter, organizations generally benefit from capturing details about the affected systems and information, the nature and timeline of the event, and actions taken, so that the specific data elements required by the controlling authority can be assembled. Because required fields and formats vary by regime and may change across revisions, verify the current reporting requirements before finalizing any submission.

Common misconceptions

A 'covered cyber incident' under CIRCIA is the same as a reportable cyber incident under the DFARS clause 252.204-7012 for defense contractors.
These are distinct obligations under different authorities. CIRCIA reporting is administered by CISA and applies to covered entities in critical infrastructure sectors, while DFARS 252.204-7012 requires defense contractors to report cyber incidents affecting covered defense information to DoD. Meeting one does not automatically satisfy the other; readers should confirm which regimes apply to their systems.
Any cybersecurity event a covered entity experiences must be reported as a covered cyber incident.
The obligation generally applies only to incidents meeting the 'substantial cyber incident' threshold defined in the applicable statute and implementing regulation. Whether a given event crosses that threshold depends on criteria set through rulemaking, which should be verified against the current authoritative text.
The reporting timelines and thresholds for covered cyber incidents are fixed and fully in effect.
CIRCIA reporting obligations depend on final implementing regulations issued by CISA. The precise thresholds, timelines, and effective dates are established through the rulemaking process and may change, so practitioners should confirm the current requirements against the published rule rather than relying on preliminary summaries.

Best practices

Determine whether your organization qualifies as a 'covered entity' in a critical infrastructure sector under the applicable CIRCIA implementing regulation, and document that determination rather than assuming applicability.
Verify the current definitions of 'covered cyber incident' and 'substantial cyber incident,' along with reporting timelines, against the finalized CISA implementing rule, since these are set through rulemaking and subject to change.
Maintain a mapping of all applicable incident reporting regimes that may apply to your systems, such as CIRCIA reporting to CISA, DFARS 252.204-7012 reporting to DoD, and FISMA-based reporting, so that overlapping obligations are handled without assuming one satisfies another.
Establish internal escalation and triage procedures that can quickly assess whether an event meets the applicable 'substantial' threshold and identify the correct recipient and timeframe for each reporting obligation.
Document incident details and reporting decisions contemporaneously to support timely submissions and to demonstrate diligence if the threshold determination is later questioned.
Periodically review your reporting procedures against the current authoritative text, as thresholds, timelines, and scope may be revised through subsequent rulemaking or agency guidance.