Cyber Incident Reporting for Critical Infrastructure Act of 2022
CIRCIA is a United States federal law signed in March 2022 that requires certain organizations in critical infrastructure sectors to report significant cyber incidents to the Cybersecurity and Infrastructure Security Agency (CISA). Its goal is to help the federal government detect threats faster and improve the nation's overall cybersecurity. The specific reporting obligations are being established through a CISA rulemaking process, so entities should confirm the current requirements against the official regulatory text.
CIRCIA, the Cyber Incident Reporting for Critical Infrastructure Act of 2022, is federal legislation signed into law in March 2022 that directs CISA to develop and administer requirements for covered entities to report covered cyber incidents and related information. Under the framework described in the associated rulemaking, covered entities are generally required to report a covered cyber incident to CISA within 72 hours after the entity reasonably believes the incident has occurred, with a covered cyber incident defined as a substantial cyber incident experienced by a covered entity. The precise definitions of 'covered entity' and 'covered cyber incident,' the applicable reporting timelines, and the effective dates are being finalized through CISA's rulemaking process (a Notice of Proposed Rulemaking was published in the Federal Register on April 4, 2024); practitioners should verify the current authoritative text, as proposed provisions may differ from the final rule. CIRCIA's scope is tied to critical infrastructure reporting to CISA and is distinct from, and does not by itself satisfy, other reporting or compliance regimes such as DFARS incident reporting obligations or FISMA requirements.
Why it matters
CIRCIA represents a significant shift in how the federal government gains visibility into cyber threats affecting critical infrastructure. By directing CISA to establish mandatory reporting of covered cyber incidents, the law is intended to help the federal government detect threats faster and improve the nation's overall cybersecurity posture. For entities operating in critical infrastructure sectors, this means that incident response planning must account for a potential federal reporting obligation in addition to any existing contractual, sector-specific, or state-level requirements.
The practical stakes are heightened by the compressed timeline contemplated in the rulemaking: covered entities are generally expected to report a covered cyber incident to CISA within 72 hours after the entity reasonably believes the incident has occurred. Meeting a window that short requires that detection, triage, escalation, and reporting workflows be established and rehearsed well before an incident occurs, because organizations that improvise these processes during an active event risk missing the reporting threshold.
It is important to understand that CIRCIA's requirements are still being finalized through CISA's rulemaking process, and that reporting to CISA under CIRCIA does not by itself satisfy other reporting or compliance regimes such as DFARS incident reporting obligations or FISMA requirements. Entities should not assume that a single report discharges all of their obligations, and should confirm the current requirements against the official regulatory text as the final rule takes shape.
Who it's relevant to
Inside CIRCIA
Common questions
Answers to the questions practitioners most commonly ask about CIRCIA.