US-CERT / CISA Reporting
US-CERT / CISA Reporting refers to the process of notifying the U.S. Cybersecurity and Infrastructure Security Agency (CISA) about cyber incidents, phishing attempts, malware, and vulnerabilities. Organizations can report anomalous cyber activity to CISA at any time through secure channels such as [email protected] or CISA Central (1-844-Say-CISA). In return, CISA shares alerts and advisories to help the broader community detect and respond to cyber threats.
US-CERT / CISA Reporting encompasses the mechanisms by which constituents and partners report cyber incidents, phishing, malware, and vulnerabilities to CISA, which provides secure reporting means and operates CISA Central as a 24/7 point of contact ([email protected] or 1-844-Say-CISA / 1-844-729-2472). Reporting may be voluntary, with CISA publishing guidance on the why, when, what, and how of reporting, or may be required under specific statutory authorities such as the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA); practitioners should note that CIRCIA's mandatory reporting requirements are subject to CISA rulemaking and applicability determinations that must be verified against the current authoritative text. CISA correspondingly disseminates Cybersecurity Advisories detailing threat actor tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs), and offers incident response tools and resources. This entry does not address entity-specific reporting timelines, covered-entity determinations, or the interplay with separate reporting obligations (for example DoD or contractual reporting), which readers must confirm against current official sources.
Why it matters
Reporting cyber incidents, phishing, malware, and vulnerabilities to CISA is a foundational element of national cyber defense because it enables the agency to correlate activity across organizations and disseminate warnings that individual entities could not develop on their own. When a constituent reports anomalous activity, CISA can incorporate that information into Cybersecurity Advisories that detail threat actor tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs), helping the broader community detect and respond to threats more effectively. In this sense, reporting is not merely a compliance formality but part of a reciprocal information-sharing model in which timely notification improves collective situational awareness.
For compliance and security practitioners, it is important to distinguish between voluntary and mandatory reporting. CISA provides secure means to report at any time and publishes guidance on the why, when, what, and how of voluntary reporting. Separately, the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) established statutory authority for mandatory reporting; however, CIRCIA's mandatory requirements are subject to CISA rulemaking and applicability determinations that must be verified against the current authoritative text. Practitioners should not assume that reporting to CISA satisfies every applicable obligation.
A common expert-level caution is that reporting to CISA does not necessarily discharge separate reporting duties, such as DoD or contractual reporting obligations, which operate under their own authorities and timelines. Organizations should confirm entity-specific reporting timelines, covered-entity determinations, and the interplay between CISA reporting and other regimes against current official sources rather than treating a single report as universally sufficient.
Who it's relevant to
Inside US-CERT
Common questions
Answers to the questions practitioners most commonly ask about US-CERT.