Skip to main content
Category: Incident Response & Reporting

US-CERT / CISA Reporting

Also known as: US-CERT, CISA Incident Reporting, Cyber Incident Reporting to CISA, CISA Central Reporting
Simply put

US-CERT / CISA Reporting refers to the process of notifying the U.S. Cybersecurity and Infrastructure Security Agency (CISA) about cyber incidents, phishing attempts, malware, and vulnerabilities. Organizations can report anomalous cyber activity to CISA at any time through secure channels such as [email protected] or CISA Central (1-844-Say-CISA). In return, CISA shares alerts and advisories to help the broader community detect and respond to cyber threats.

Formal definition

US-CERT / CISA Reporting encompasses the mechanisms by which constituents and partners report cyber incidents, phishing, malware, and vulnerabilities to CISA, which provides secure reporting means and operates CISA Central as a 24/7 point of contact ([email protected] or 1-844-Say-CISA / 1-844-729-2472). Reporting may be voluntary, with CISA publishing guidance on the why, when, what, and how of reporting, or may be required under specific statutory authorities such as the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA); practitioners should note that CIRCIA's mandatory reporting requirements are subject to CISA rulemaking and applicability determinations that must be verified against the current authoritative text. CISA correspondingly disseminates Cybersecurity Advisories detailing threat actor tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs), and offers incident response tools and resources. This entry does not address entity-specific reporting timelines, covered-entity determinations, or the interplay with separate reporting obligations (for example DoD or contractual reporting), which readers must confirm against current official sources.

Why it matters

Reporting cyber incidents, phishing, malware, and vulnerabilities to CISA is a foundational element of national cyber defense because it enables the agency to correlate activity across organizations and disseminate warnings that individual entities could not develop on their own. When a constituent reports anomalous activity, CISA can incorporate that information into Cybersecurity Advisories that detail threat actor tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs), helping the broader community detect and respond to threats more effectively. In this sense, reporting is not merely a compliance formality but part of a reciprocal information-sharing model in which timely notification improves collective situational awareness.

For compliance and security practitioners, it is important to distinguish between voluntary and mandatory reporting. CISA provides secure means to report at any time and publishes guidance on the why, when, what, and how of voluntary reporting. Separately, the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) established statutory authority for mandatory reporting; however, CIRCIA's mandatory requirements are subject to CISA rulemaking and applicability determinations that must be verified against the current authoritative text. Practitioners should not assume that reporting to CISA satisfies every applicable obligation.

A common expert-level caution is that reporting to CISA does not necessarily discharge separate reporting duties, such as DoD or contractual reporting obligations, which operate under their own authorities and timelines. Organizations should confirm entity-specific reporting timelines, covered-entity determinations, and the interplay between CISA reporting and other regimes against current official sources rather than treating a single report as universally sufficient.

Who it's relevant to

Information System Security Managers and Incident Response Teams
Personnel responsible for detecting and responding to cyber incidents can use CISA's secure reporting channels and 24/7 CISA Central point of contact to notify the agency of anomalous activity, and can leverage CISA advisories detailing TTPs and IOCs to strengthen detection and response. They should confirm any applicable reporting timelines against current official sources.
Compliance Officers and Government Contractors
Those managing regulatory and contractual obligations should understand the distinction between CISA's voluntary reporting guidance and mandatory reporting authorities such as CIRCIA. Because CIRCIA requirements are subject to CISA rulemaking and applicability determinations, and because separate DoD or contractual reporting obligations may apply, contractors should verify covered-entity status and reporting duties against current authoritative text.
Critical Infrastructure Owners and Operators
Entities in critical infrastructure sectors are a focus of CISA's information-sharing mission and are the subject of CIRCIA's reporting framework. They should monitor CISA rulemaking to determine whether and how mandatory reporting requirements apply to them, while making use of voluntary reporting channels and CISA advisories in the interim.
Authorizing Officials and Security Leadership
Leaders accountable for organizational risk decisions can incorporate CISA reporting and advisory consumption into their broader security and information-sharing posture. They should recognize that reporting to CISA supports collective defense but does not automatically satisfy every separate statutory or contractual reporting obligation.

Inside US-CERT

Incident Reporting Channel
The mechanism by which federal agencies and, in some cases, contractors report cybersecurity incidents to CISA, which now performs the operational functions historically associated with US-CERT. Readers should verify the current reporting portal, contacts, and submission formats against official CISA sources, as these have evolved.
US-CERT to CISA Transition
US-CERT functions were consolidated under CISA, the Cybersecurity and Infrastructure Security Agency within the Department of Homeland Security. References to 'US-CERT' generally now point to CISA-operated capabilities; the two should not be treated as separate, coequal authorities.
Reportable Incident Criteria
The set of conditions or thresholds that determine whether an event must be reported. These criteria are defined in applicable federal guidance and agency policy and can differ by system type; the specific triggers and categories should be confirmed against current authoritative text rather than assumed.
Reporting Timelines
Time windows within which reports are expected after detection or determination of an incident. Exact timeframes depend on the governing requirement and system category and should be verified against current official guidance rather than treated as fixed.
Scope of Applicability
Which entities and systems are covered. Federal civilian agency obligations under FISMA-related guidance may differ from DoD reporting under the RMF or contractual clauses, and from requirements for classified systems. State, local, tribal, and territorial obligations may differ as well.
Coordination and Information Sharing Role
CISA's function in receiving reports, coordinating response, and disseminating alerts and advisories to affected stakeholders, distinct from the reporting entity's internal incident handling responsibilities.

Common questions

Answers to the questions practitioners most commonly ask about US-CERT.

Does reporting an incident to CISA satisfy all of my organization's incident reporting obligations?
No. Reporting to CISA generally does not automatically discharge other reporting duties an organization may have. Defense contractors handling covered defense information, for example, typically face separate reporting requirements under their contractual DFARS obligations that run to the DoD, not to CISA. Federal civilian agencies, national security systems, and organizations subject to sector-specific or state-level obligations may each have distinct reporting channels, timelines, and recipients. Treating a single CISA report as universally sufficient is a common mistake; readers should confirm the full set of applicable obligations against their contracts, agency policy, and current authoritative sources.
Is 'US-CERT' still a separate organization I report to, distinct from CISA?
The functions historically associated with US-CERT are now carried out within CISA, so the two should not be treated as separate, independent reporting bodies. Older guidance, contracts, and policy documents may still reference 'US-CERT,' but the operational and reporting functions have been consolidated under CISA. When encountering legacy terminology, readers should interpret it in light of CISA's current role and verify the correct, current reporting mechanism rather than assuming a standalone US-CERT entity persists.
Who within our organization should be responsible for submitting a report to CISA?
Responsibility is generally assigned through internal incident response policy rather than dictated uniformly by CISA. In most implementations, organizations designate specific roles, such as an incident response lead, information system security manager, or security operations personnel, with clear authority to report. Because reporting can trigger downstream contractual and agency notifications, coordination with legal, contracts, and management functions is commonly built into the process. Organizations should define these responsibilities in advance and confirm them against their own governing policies and any applicable contractual requirements.
What information should we be prepared to include when reporting to CISA?
Reporting generally calls for enough detail to characterize the incident, though exact fields and formats can vary by reporting channel and may change over time. Organizations commonly prepare to describe what was observed, affected systems, timing, and known impact, while recognizing that some details may be incomplete at the time of initial reporting. Because expected content and submission formats are subject to change and may differ across reporting mechanisms, readers should consult CISA's current guidance for the specific information requested rather than relying on a fixed checklist.
How quickly are we expected to report an incident to CISA?
Timeliness expectations depend on the applicable requirement and the reporting channel, and they can differ from timelines imposed by other authorities. Contractual, agency-specific, and statutory obligations may each set their own reporting windows that apply in parallel. Because these timeframes vary and are subject to revision, organizations should not assume a single deadline applies universally; they should verify the current expected timeline for their situation against the governing guidance, contract, or regulation.
How should CISA reporting be integrated into our incident response plan?
In most implementations, CISA reporting is treated as one defined step within a broader incident response process rather than a standalone action. Organizations commonly document when reporting is triggered, who is responsible, what information to gather, and how CISA reporting coordinates with other required notifications such as contractual or agency reporting. Building these procedures in advance, and periodically reviewing them against current CISA guidance and any applicable obligations, helps avoid gaps. Specific procedural details should be confirmed against the organization's own policies and current authoritative sources.

Common misconceptions

US-CERT and CISA are separate organizations with different reporting requirements.
US-CERT's operational functions have been consolidated under CISA. References to US-CERT reporting generally correspond to CISA-operated capabilities today; practitioners should treat CISA as the current authority and verify present-day channels.
Reporting an incident to CISA satisfies all of an organization's incident reporting obligations.
Reporting to CISA is one channel and does not necessarily discharge other obligations. DoD systems, contractors handling CUI under applicable contractual clauses, and classified systems may have separate or additional reporting requirements that must be confirmed against the governing authorities.
The same reporting criteria and timelines apply uniformly across all federal, defense, and non-federal systems.
Reportable-incident criteria and timelines vary by governing requirement and system category, and can change across revisions. Practitioners should confirm the specific thresholds and deadlines applicable to their environment against current official sources.

Best practices

Confirm the current CISA reporting channel, contacts, and submission format directly from official CISA sources rather than relying on legacy US-CERT references.
Identify all reporting obligations that apply to your specific system category (federal civilian, DoD/RMF, CUI under applicable contractual clauses, or classified) and treat CISA reporting as one channel that may not satisfy the others.
Verify the applicable reportable-incident criteria and timelines against current authoritative guidance, since thresholds and deadlines vary by requirement and can change across revisions.
Document internal detection-to-report workflows and roles so that reporting deadlines can be met consistently once an incident is determined.
Coordinate reporting responsibilities across information system security personnel, contracting stakeholders, and legal or compliance staff to avoid gaps between overlapping obligations.
Retain records of reports submitted and any acknowledgments or coordination correspondence to support audit and continuous monitoring needs.