Skip to main content
Category: Incident Response & Reporting

Cyber Incident Reporting Portal

Also known as: Cyber Incident Reporting System, Incident Reporting Portal
Simply put

A cyber incident reporting portal is an online system that lets organizations or individuals notify a government agency or authority when they experience a cybersecurity problem, such as a breach, phishing attempt, or malware infection. Different agencies operate their own portals, so where and how you report generally depends on who you are and which authority you fall under. A cyber incident is broadly understood as an event that could jeopardize the confidentiality, integrity, or availability of digital information or information systems.

Formal definition

A cyber incident reporting portal is a designated intake channel through which constituents, partners, or regulated entities submit notifications of cyber incidents, phishing, malware, or vulnerabilities to a governing body. Reporting destinations are authority- and sector-specific rather than universal: CISA provides secure means for reporting incidents at the federal level; the Commonwealth of Virginia operates a separate state-level notification form; law enforcement networks are generally directed to report through the FBI's eGuardian; and defense contractors report through DoD-designated mechanisms. As of the evidence provided, the DoD's DIBNet portal has been reported as decommissioned as part of a modernization effort, meaning defense contractors should verify the current DoD-designated reporting channel and applicable DFARS obligations against authoritative sources. Practitioners should not assume that a single portal or a single report satisfies all applicable federal civilian, defense, state, or sector-specific reporting obligations, which may run concurrently; the specific portal, timelines, and content requirements must be confirmed against current official guidance for each applicable authority.

Why it matters

Cyber incident reporting portals are the operational front door to a patchwork of overlapping reporting obligations, and getting the destination wrong can leave an organization out of compliance even when it acted in good faith. Because reporting destinations are authority- and sector-specific rather than universal, where and how you report generally depends on who you are and which authority governs your systems. CISA provides secure means for federal-level reporting of incidents, phishing, malware, and vulnerabilities; the Commonwealth of Virginia operates a separate state-level notification form; law enforcement networks are generally directed to the FBI's eGuardian; and defense contractors report through DoD-designated mechanisms. A single portal or a single report should not be assumed to satisfy every applicable obligation, because federal civilian, defense, state, and sector-specific requirements may run concurrently.

Who it's relevant to

Defense contractors
Contractors handling defense information have historically reported through DoD-designated mechanisms, and the DoD's DIBNet portal has been reported as decommissioned as part of a modernization effort. Because of this, contractors should confirm the current DoD-designated reporting channel and their applicable DFARS obligations against authoritative sources rather than assuming a prior portal remains active.
Federal civilian entities and partners
Organizations reporting at the federal civilian level can use the secure means CISA provides for reporting incidents, phishing attempts, malware, and vulnerabilities. These reporters should not assume that a federal civilian report to CISA satisfies separate defense, state, or sector-specific obligations that may apply concurrently.
State-regulated organizations
Entities falling under state authority may face separate state-level reporting requirements; for example, the Commonwealth of Virginia operates its own notification form for reporting a cybersecurity breach. State, local, tribal, and territorial obligations may differ from federal ones, so reporters should verify which state channels and timelines apply to them.
Law enforcement organizations
Agencies that experience a cyber incident in a law enforcement network are generally directed to report through the FBI's eGuardian website as a first step. Reporters in this sector should confirm current guidance for that channel and whether additional obligations apply.
Compliance officers and incident response teams
Personnel responsible for coordinating reporting must map an organization's applicable authorities, because a single portal or single report does not necessarily satisfy all federal civilian, defense, state, or sector-specific obligations, which may run concurrently. The specific portal, timelines, and content requirements should be confirmed against current official guidance for each applicable authority.

Inside Cyber Incident Reporting Portal

Reporting Submission Interface
The web-based mechanism through which contractors and covered entities submit reports of cyber incidents. In the DoD context, mandatory cyber incident reporting under DFARS clause 252.204-7012 is generally directed to the DoD-designated portal, which typically requires a valid DoD-approved medium assurance certificate to authenticate submissions. Reader should verify the current authoritative submission requirements against official sources.
Incident Report Fields
Structured data elements the submitter is generally asked to provide, such as identifying information about the affected system, a description of the incident, affected information (including whether Controlled Unclassified Information may be involved), and the time frame of the event. Specific required fields vary by portal and by the governing regulation or clause, and should be confirmed against current guidance.
Reporting Timeline Obligation
The time-bound requirement to report after discovery of a reportable incident. Under DFARS 252.204-7012, rapid reporting is generally required within a defined window following discovery; the reader should confirm the exact time frame in the current clause text, as absolute figures should not be assumed to be static.
Scope Determination
The determination of which incidents and which entities are subject to a given portal's reporting obligation. Requirements differ across federal civilian systems under FISMA, DoD systems under the RMF, defense contractors handling CUI under DFARS, and classified systems under the NISPOM. State, local, tribal, and territorial obligations may differ and are typically out of scope for a DoD or federal portal.
Downstream Handling and Coordination
The routing of submitted reports to the relevant government stakeholders for review, correlation, and potential follow-up, which may include requests for malicious software or media for forensic analysis. The specific handling process and which authorities receive the report depend on the governing program and are generally described in official guidance rather than assumed.

Common questions

Answers to the questions practitioners most commonly ask about Cyber Incident Reporting Portal.

Does reporting a cyber incident through a portal like DIBNet satisfy all of a contractor's incident reporting obligations at once?
Not necessarily. Submitting a report through a designated portal generally addresses a specific reporting requirement tied to a particular authority, such as the rapid reporting requirement under DFARS clause 252.204-7012 for covered defense information. It does not automatically satisfy other obligations a contractor may hold under separate contracts, agency-specific clauses, or civilian frameworks. Requirements can also differ for CUI handling, classified systems under the NISPOM, and state, local, tribal, or territorial obligations. Confirm each applicable requirement against the current governing contract and regulation rather than assuming a single submission covers all of them.
Is filing an incident report the same as being in compliance or having a secure system?
No. Reporting is one procedural obligation, and completing it does not by itself establish that a system is secure or that the organization is fully compliant. Compliance generally involves implementing and maintaining the applicable control set, meeting contractual and regulatory obligations, and supporting continuous monitoring, while security is a broader operational outcome. An incident report documents that an event occurred and was communicated; it neither remediates the underlying weakness nor demonstrates that safeguarding requirements were met. Readers should treat reporting as a distinct step separate from assessment, authorization, and ongoing risk management.
How do I determine which incident reporting portal or channel applies to my situation?
The applicable channel generally depends on the governing authority for your contract or system. Defense contractors handling covered defense information typically report through the DoD's designated mechanism tied to DFARS requirements, while civilian agency systems and certain incident categories may route to CISA or an agency-specific point of contact. Because these designations and thresholds are set by the relevant regulation, contract, or agency policy and can change, verify the current official reporting destination in your contract terms and the applicable published guidance before an incident occurs.
What information is typically expected when submitting a cyber incident report?
Reporting portals generally request identifying details about the affected organization and system, a description of the incident, and information relevant to the specific reporting requirement, which for DFARS-related reporting can include elements tied to covered defense information and affected systems. The precise data fields, required detail, and any supporting artifacts are defined by the governing authority and may vary by portal and revision. Rather than relying on a fixed list, prepare by reviewing the current portal instructions and the applicable clause or policy so the submission meets the established format.
Are there time constraints for submitting a cyber incident report?
Many reporting requirements impose a defined timeframe measured from discovery of the incident, and the rapid reporting expectation under DFARS clause 252.204-7012 is a commonly cited example for defense contractors. The exact window, the event that starts the clock, and any follow-up reporting obligations are set by the specific regulation or contract and can differ across authorities and revisions. Because a specific figure should not be assumed, confirm the current required timeframe in the applicable clause and portal guidance and build internal procedures to meet it.
What credentials or access are generally needed to use an official reporting portal?
Access to certain official reporting portals may require pre-established credentials or identity verification, and some defense-related mechanisms have historically involved a medium assurance certificate or comparable authentication. Because access prerequisites are determined by the operating authority and can change, organizations should confirm the current registration and authentication requirements in advance rather than attempting to establish access during an active incident. Establishing eligible personnel and access ahead of time is a practical step to avoid delays against any applicable reporting timeframe.

Common misconceptions

Submitting a cyber incident report through the portal demonstrates that an organization is compliant and secure.
Reporting is one obligation among many and satisfies a specific reporting requirement; it does not by itself establish overall compliance or security. Compliance and security are distinct, and meeting a reporting requirement does not confirm that safeguarding controls were adequate or effective.
A single portal covers all cyber incident reporting obligations regardless of the type of system or information involved.
Reporting channels and requirements are scoped to particular authorities. Obligations for federal civilian systems under FISMA, DoD contractor systems handling CUI under DFARS, and classified systems under the NISPOM may involve different destinations, thresholds, and time frames. Practitioners should confirm which obligation applies to their specific situation.
Reporting can wait until an internal investigation is fully complete.
Applicable requirements such as those under DFARS 252.204-7012 generally impose a time-bound obligation to report after discovery, before an investigation concludes. The exact window should be verified in the current clause text, but delaying until full resolution can put an organization out of compliance.

Best practices

Confirm which reporting obligation and portal apply to your specific systems and information type, distinguishing FISMA-covered civilian systems, DoD/DFARS CUI obligations, and NISPOM classified-system requirements before assuming a single channel suffices.
Verify the current required reporting time frame and required data fields directly against the governing clause or official guidance, since these can change across revisions and should not be assumed from memory.
Obtain and maintain any required authentication credentials in advance, such as a DoD-approved medium assurance certificate where the DoD portal requires one, so that reporting is not delayed during an actual incident.
Establish an internal incident identification and escalation process so that discovery is recognized promptly and reporting timelines can be met before an investigation concludes.
Preserve relevant evidence, including potentially malicious software and affected media, in case follow-up requests for forensic analysis are made after submission.
Do not treat submission of a report as evidence of compliance or security; continue to maintain, assess, and document your safeguarding controls separately, and confirm implementation specifics against current authoritative sources.