Skip to main content
Category: Laws & Executive Orders

Cyber Incident Reporting for Critical Infrastructure Act of 2022

Also known as: CIRCIA, Cyber Incident Reporting for Critical Infrastructure Act
Simply put

CIRCIA is a United States federal law signed in March 2022 that requires certain organizations in critical infrastructure sectors to report significant cyber incidents to the Cybersecurity and Infrastructure Security Agency (CISA). Its goal is to help the federal government detect threats faster and improve the nation's overall cybersecurity. The specific reporting obligations are being established through a CISA rulemaking process, so entities should confirm the current requirements against the official regulatory text.

Formal definition

CIRCIA, the Cyber Incident Reporting for Critical Infrastructure Act of 2022, is federal legislation signed into law in March 2022 that directs CISA to develop and administer requirements for covered entities to report covered cyber incidents and related information. Under the framework described in the associated rulemaking, covered entities are generally required to report a covered cyber incident to CISA within 72 hours after the entity reasonably believes the incident has occurred, with a covered cyber incident defined as a substantial cyber incident experienced by a covered entity. The precise definitions of 'covered entity' and 'covered cyber incident,' the applicable reporting timelines, and the effective dates are being finalized through CISA's rulemaking process (a Notice of Proposed Rulemaking was published in the Federal Register on April 4, 2024); practitioners should verify the current authoritative text, as proposed provisions may differ from the final rule. CIRCIA's scope is tied to critical infrastructure reporting to CISA and is distinct from, and does not by itself satisfy, other reporting or compliance regimes such as DFARS incident reporting obligations or FISMA requirements.

Why it matters

CIRCIA represents a significant shift in how the federal government gains visibility into cyber threats affecting critical infrastructure. By directing CISA to establish mandatory reporting of covered cyber incidents, the law is intended to help the federal government detect threats faster and improve the nation's overall cybersecurity posture. For entities operating in critical infrastructure sectors, this means that incident response planning must account for a potential federal reporting obligation in addition to any existing contractual, sector-specific, or state-level requirements.

The practical stakes are heightened by the compressed timeline contemplated in the rulemaking: covered entities are generally expected to report a covered cyber incident to CISA within 72 hours after the entity reasonably believes the incident has occurred. Meeting a window that short requires that detection, triage, escalation, and reporting workflows be established and rehearsed well before an incident occurs, because organizations that improvise these processes during an active event risk missing the reporting threshold.

It is important to understand that CIRCIA's requirements are still being finalized through CISA's rulemaking process, and that reporting to CISA under CIRCIA does not by itself satisfy other reporting or compliance regimes such as DFARS incident reporting obligations or FISMA requirements. Entities should not assume that a single report discharges all of their obligations, and should confirm the current requirements against the official regulatory text as the final rule takes shape.

Who it's relevant to

Critical infrastructure operators
Organizations that may fall within the definition of a covered entity in a critical infrastructure sector need to track the CIRCIA rulemaking closely, since the final rule will establish who is obligated to report and what qualifies as a covered cyber incident. Because the definition of 'covered entity' is being finalized, these organizations should confirm their status against the official regulatory text as it is issued.
Incident response and security operations teams
Teams responsible for detecting and responding to cyber incidents must be prepared to support a reporting obligation that is generally expected to run within 72 hours of the point at which the entity reasonably believes a covered incident has occurred. This requires detection, escalation, and reporting workflows that are established and exercised in advance rather than assembled during an active event.
Compliance officers and legal counsel
Compliance and legal personnel need to reconcile CIRCIA with other reporting and compliance regimes, recognizing that CIRCIA is distinct from, and does not by itself satisfy, obligations such as DFARS incident reporting or FISMA requirements. They should also monitor the CISA rulemaking to determine when and how obligations become effective, verifying details against the final rule.
Government stakeholders relying on CISA visibility
CIRCIA is intended to help the federal government, through CISA, detect threats faster and improve national cybersecurity. Federal stakeholders that depend on aggregated incident information will find CIRCIA relevant as the reporting framework is implemented, though the scope of reporting will depend on the definitions finalized in the rulemaking.

Inside CIRCIA

Statutory Basis
CIRCIA refers to the Cyber Incident Reporting for Critical Infrastructure Act of 2022, enacted as part of a broader federal appropriations package. It establishes a statutory mandate directing CISA to develop and administer cyber incident reporting requirements for covered entities in critical infrastructure sectors. Readers should verify the exact statutory text and any amendments against current official sources.
Implementing Agency (CISA)
The Cybersecurity and Infrastructure Security Agency (CISA), within the Department of Homeland Security, is the body responsible for issuing the implementing regulations and administering the reporting program. CIRCIA obligations flow through CISA rulemaking rather than through NIST, the FedRAMP PMO, or the DoD CIO, and it should not be conflated with those authorities or their control sets.
Covered Entities and Covered Incidents
The Act contemplates reporting obligations for 'covered entities' operating in designated critical infrastructure sectors and for defined 'covered cyber incidents.' The precise definitions, thresholds, and sector applicability are established through CISA rulemaking, and the specific scope should be confirmed against the final rule and any subsequent revisions rather than assumed.
Reporting Timelines
CIRCIA generally contemplates reporting of covered cyber incidents and of ransom payments within timeframes specified in statute and implementing regulation. Exact deadlines and triggering conditions depend on the applicable regulatory text; practitioners should verify current timelines rather than rely on a fixed figure that may change across the rulemaking process.
Ransom Payment Reporting
In addition to incident reporting, CIRCIA contemplates a separate obligation to report ransom payments made in response to ransomware attacks. This is distinct from the covered cyber incident report and carries its own conditions and timelines as defined by CISA.
Relationship to Other Reporting Regimes
CIRCIA is a federal civilian critical infrastructure reporting authority and is distinct from defense contractual reporting such as DFARS clause 252.204-7012 cyber incident reporting to DoD, from FISMA-based agency reporting, and from sector-specific regulatory reporting. These regimes may overlap but are not interchangeable, and the Act contemplates efforts to harmonize duplicative federal reporting requirements.

Common questions

Answers to the questions practitioners most commonly ask about CIRCIA.

Does CIRCIA require covered entities to report every cybersecurity incident they experience?
No. CIRCIA is generally understood to require reporting of covered cyber incidents that meet defined significance thresholds, not every event or minor anomaly. The precise scope of what qualifies as a 'covered cyber incident,' and which entities are 'covered entities,' is being established through CISA's rulemaking process. Readers should verify the specific reporting triggers, covered entity definitions, and thresholds against the current CISA regulatory text rather than assuming a blanket obligation to report all incidents.
Is CIRCIA the same as other federal breach or incident reporting obligations, such as those under FISMA or DoD contract clauses?
No. CIRCIA is a distinct statutory reporting regime administered by CISA and should not be conflated with FISMA incident reporting for federal agency systems, DoD contractual reporting obligations, or sector-specific reporting requirements. An organization may be subject to multiple, overlapping reporting frameworks with different timelines, recipients, and definitions. CIRCIA compliance does not automatically satisfy those other obligations, and the reverse is also true. Confirm each applicable requirement separately against its own governing authority.
Which entities need to determine whether they qualify as CIRCIA 'covered entities'?
Organizations operating in or associated with critical infrastructure sectors should evaluate whether they fall within the 'covered entity' definition. Because the applicability criteria are being defined through CISA rulemaking, organizations should review the current regulatory text and any published sector-specific guidance to assess their status. This entry does not cover the legal determination of covered-entity status, which readers should confirm with counsel and against the authoritative rule.
What are the reporting timelines that covered entities should plan for under CIRCIA?
CIRCIA contemplates time-bound reporting obligations for covered cyber incidents and for ransom payments, with the specific deadlines set through CISA's implementing regulation. Because these timelines are established in the rule rather than assumed, organizations should build incident response and escalation procedures capable of meeting whatever deadlines the final regulation specifies, and verify the exact timeframes against the current CISA text before relying on them.
How should an organization prepare its incident response process to support CIRCIA reporting?
In most implementations, organizations align their incident response, detection, and escalation procedures so that qualifying events can be identified, characterized against the reporting thresholds, and reported within applicable deadlines. Preparation generally includes clarifying internal roles for reporting decisions, coordinating legal review, and establishing data-collection practices that capture the information a report would require. Organizations should map these procedures to the specific data elements and submission mechanisms defined in the current CISA regulation.
How does CIRCIA reporting interact with an organization's other regulatory and contractual reporting duties?
CIRCIA reporting may coexist with other obligations, and an organization should treat it as one component of a broader reporting posture rather than a substitute for others. Coordinating timelines, recipients, and content across multiple regimes helps avoid gaps or inconsistencies. Because the interplay depends on the entity's sector, contracts, and applicable frameworks, organizations should confirm how CIRCIA obligations align with their other requirements against current authoritative sources and with counsel.

Common misconceptions

CIRCIA reporting is the same as, or satisfies, DFARS 252.204-7012 incident reporting to DoD.
CIRCIA is administered by CISA for critical infrastructure covered entities under a civilian authority, while DFARS clause 252.204-7012 is a defense contractual requirement to report cyber incidents to the DoD. They are distinct regimes with different scopes, recipients, and triggers. A single incident may implicate both, and compliance with one does not automatically satisfy the other. Readers should confirm each applicable obligation independently.
The obligations took effect immediately when CIRCIA was enacted in 2022.
The statute directs CISA to conduct rulemaking to define covered entities, covered incidents, timelines, and procedures. The operative reporting obligations generally attach through the implementing regulation rather than upon enactment of the Act itself. Practitioners should verify the current status and effective dates of the rulemaking against official CISA sources rather than assuming immediate applicability.
CIRCIA imposes new security control requirements comparable to a control baseline.
CIRCIA is fundamentally an incident and ransom payment reporting authority, not a control catalog like NIST SP 800-53 or NIST SP 800-171. It should not be treated as a source of prescriptive technical safeguards; meeting a reporting obligation is not the same as achieving a secure or otherwise compliant security posture.

Best practices

Confirm whether your organization qualifies as a covered entity under the applicable CISA implementing regulation, since sector applicability and thresholds are established through rulemaking and may differ from initial statutory assumptions.
Monitor CISA rulemaking status and effective dates directly through official sources, and treat any reporting timelines as subject to verification against the current final rule rather than a fixed figure.
Maintain an incident response process that can identify and characterize a covered cyber incident and any ransom payment quickly enough to meet the applicable reporting deadlines once they are in effect.
Map CIRCIA reporting against your other federal reporting obligations, such as DFARS-based reporting to DoD or FISMA agency reporting, to identify overlaps and avoid assuming that one report satisfies another.
Document decision points and timestamps supporting when an incident was detected and reported, so you can demonstrate the basis for reporting timeliness if reviewed.
Coordinate legal, compliance, and security stakeholders before an incident to confirm reporting responsibilities, and verify implementation, contractual, and legal specifics against current authoritative text rather than relying on this summary.