Skip to main content
U.S. flag

An official website of the United States government

Here’s how you know

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

HTTPS

Secure .gov websites use HTTPS
A lock (LockA locked padlock) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Free Cyber ServicesSecure by design Secure Our WorldShields UpReport A Cyber Issue

Cybersecurity & Infrastructure Security Agency logo America’s Cyber Security Defense Agency National Coordinator For Critical Infrastructure Security and ResilienceCybersecurity & Infrastructure Security Agency logo America’s Cyber Security Defense Agency National Coordinator For Critical Infrastructure Security and Resilience
CISA Logo

Search

 

America's Cyber Defense Agency
 
  • Topics
    Cybersecurity Best Practices
    Cyber Threats and Advisories
    Critical Infrastructure Security and Resilience
    Election Security
    Emergency Communications
    Industrial Control Systems
    Information and Communications Technology Supply Chain Security
    Partnerships and Collaboration
    Physical Security
    Risk Management
    How can we help?
    GovernmentEducational InstitutionsIndustryState, Local, Tribal, and TerritorialIndividuals and FamiliesSmall and Medium BusinessesFind Help LocallyFaith-Based CommunityExecutivesHigh-Risk Communities
  • Spotlight
  • Resources & Tools
    All Resources & Tools
    Services
    Programs
    Resources
    Training
    Groups
  • News & Events
    News
    Events
    Cybersecurity Alerts & Advisories
    Directives
    Request a CISA Speaker
    Congressional Testimony
    CISA Conferences
    CISA Live!
  • Careers
    Benefits & Perks
    HireVue Applicant Reasonable Accommodations Process
    Hiring
    Resume & Application Tips
    Students & Recent Graduates
    Veteran and Military Spouses
  • About
    Divisions & Offices
    Regions
    Leadership
    Doing Business with CISA
    Site Links
    CISA GitHub
    CISA Central
    Contact Us
    Subscribe
    Transparency and Accountability
    Policies & Plans

Free Cyber ServicesSecure by design Secure Our WorldShields UpReport A Cyber Issue

Breadcrumb
  1. Home
  2. Topics
  3. Cyber Threats and Advisories
  4. Information Sharing
  5. Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA)
Share:

Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA)

Related topics:
Cybersecurity Best Practices, Cyber Threats and Advisories
Report a Cyber Issue
Organizations should report anomalous cyber activity and/or cyber incidents 24/7 to report@cisa.gov or 1-844-Say-CISA.

In March 2022, President Biden signed into law the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA). Enactment of CIRCIA marked an important milestone in improving America’s cybersecurity by, among other things, requiring the Cybersecurity and Infrastructure Security Agency (CISA) to develop and implement regulations requiring covered entities to report covered cyber incidents and ransomware payments to CISA. These reports will allow CISA to rapidly deploy resources and render assistance to victims suffering attacks, analyze incoming reporting across sectors to spot trends, and quickly share that information with network defenders to warn other potential victims.

Rulemaking Process

Some of CISA’s authorities under CIRCIA are regulatory in nature and require CISA to complete mandatory rulemaking activities before the reporting requirements go into effect. CISA developed a Notice of Proposed Rulemaking (NPRM), which was published on April 4, 2024 in the Federal Register and was open for public comment until July 3. The NPRM is available at www.federalregister.gov.  The public comments submitted in response to the NPRM have been posted to the rulemaking docket on regulations.gov and can be found searching for CISA-2022-0010-0163.   

CISA consulted with various entities throughout the rulemaking process for the NPRM, including Sector Risk Management Agencies, the Department of Justice, other appropriate Federal agencies, and the DHS-chaired Cyber Incident Reporting Council. CISA has also consulted with various non-federal stakeholders throughout the rulemaking process. CISA will review and consider the comments received during the public comment period in developing the Final Rule, which CISA is required to publish 18 months after the publication of the NPRM. 

Frequently Asked Questions (FAQs)

CIRCIA FAQs

Voluntary Sharing of Information about Cyber Incidents

While covered cyber incident and ransomware payment reporting under CIRCIA will not be required until the CIRCIA Final Rule goes into effect, CISA encourages all entities to voluntarily share with CISA information on cyber incidents prior to the effective date of the Final Rule. 

When information about cyber incidents is shared quickly, CISA can use this information to render assistance and provide warning to prevent other organizations from falling victim to a similar incident. This information is also critical to identifying trends that can help efforts to protect the homeland.

CISA encourages all organizations to share information about unusual cyber activity and/or cyber incidents via cisa.gov/report.

Sharing Cyber Event Information Fact Sheet(PDF, 199.32 KB )
Voluntary Cyber Incident Reporting

Voluntary Cyber Incident Reporting Resource

This resource is designed to help entities that may be considering voluntarily reporting cyber incidents understand “who” CISA recommends report an incident, “why and when” CISA recommends they report, as well as “what and how to report.” 

View the Resource!

Additional Resources

PUBLICATION

Cyber Incident Reporting for Critical Infrastructure Act of 2022 Publication

Download File (PDF, 149.47 KB)
PUBLICATION

Cyber Incident Reporting for Critical Infrastructure Act of 2022 Fact Sheet

Download File (PDF, 302.05 KB)
PUBLICATION

Cyber Incident Reporting for Critical Infrastructure Act of 2022 - Notice of Proposed Rulemaking Informational Overview

This is an unofficial, informational resource summarizing aspects of the CIRCIA Notice of Proposed Rulemaking (NPRM) created to assist stakeholders in reviewing the NRPM.
Download File (PDF, 631.32 KB)
FACT SHEET

Covered Cyber Incident Fact Sheet

Under the CIRCIA NPRM, a covered entity that experiences a covered cyber incident is required to report. Find out what covered cyber incident are.
Download File (PDF, 349.69 KB)
FACT SHEET

Covered Entity Fact Sheet

Under the CIRCIA NPRM, a covered entity that experiences a covered cyber incident is required to report. Find out what covered entities are.
Download File (PDF, 502.08 KB)
MARCH 13, 2023 | PUBLICATION

Ransomware Vulnerability Warning Pilot (RVWP) Fact Sheet

Stop Ransomware

StopRansomware.gov

CISA hosts the federal government’s official one-stop location for resources to tackle ransomware more effectively. This website includes information, guidance and other tools to help organization protect, prepare for and respond to ransomware.

StopRansomware.gov

Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements; Correction

The Federal Register posted a Notice issued by CISA pertaining to the CIRCIA Notice of Proposed Rulemaking (NPRM). The purpose of this Notice is to provide stakeholders with information to understand and comment on CIRCIA’s proposed coverage for pipeline facilities and systems under the CIRCIA proposed regulations.

Learn More

Background on CIRCIA

In March 2022, President Biden signed into law the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA). Enactment of CIRCIA marked an important milestone in improving America’s cybersecurity by, among other things, requiring the Cybersecurity and Infrastructure Security Agency (CISA) to develop and implement regulations requiring covered entities to report to CISA covered cyber incidents and ransom payments. These reports will allow CISA to rapidly deploy resources and render assistance to victims suffering attacks, analyze incoming reporting across sectors to spot trends, and quickly share that information with network defenders to warn other potential victims.

Cyber Incident Reporting Initiatives 

CIRCIA includes a number of requirements related to the required reporting and sharing of covered cyber incidents, including the following:

  • Cyber Incident Reporting Requirements: CIRCIA requires CISA to develop and issue regulations requiring covered entities to report to CISA any covered cyber incidents no later than 72 hours from the time the entity reasonably believes the incident occurred. CISA’s proposed regulations that would implement this requirement are reflected in the CIRCIA NPRM.
  • Federal Cyber Incident Report Sharing: Any federal agency, including independent establishments, receiving a report on a cyber incident after the effective date of the Final Rule must share that report with CISA no later than 24 hours. Similarly, after the effective date of the Final Rule, CISA will also have to make information received under CIRCIA, including reports received from other federal agencies, available to appropriate federal agencies within 24 hours.
  • Cyber Incident Reporting Council: DHS was required to establish and chair an intergovernmental Cyber Incident Reporting Council (CIRC) to coordinate, deconflict, and harmonize federal incident reporting requirements. On September 19, 2023, DHS delivered to Congress a report, informed by the work of the CIRC, entitled “Harmonization of Cyber Incident Reporting to the Federal Government.”

Ransomware Initiatives 

CIRCIA additionally authorizes or requires a number of initiatives related to defending against ransomware, to include the following:

  • Ransom Payment Reporting Requirements: CIRCIA requires CISA to develop and issue regulations requiring covered entities to report to CISA within 24 hours of making any ransom payments made as a result of a ransomware attack. CISA must share such reports with federal agencies, similar to above. CISA’s proposed regulations that would implement this requirement are reflected in the CIRCIA NPRM.
  • Ransomware Vulnerability Warning Pilot (RVWP) Program: On January 30, 2023, CISA established the RVWP, leveraging existing authorities and technology to identify systems with vulnerabilities commonly associated with known ransomware exploitation and warn entities of those vulnerabilities, thus enabling timely mitigation before damaging intrusions occur.
  • Joint Ransomware Task Force: Since 2022, CISA and the Federal Bureau of Investigation (FBI) have led the Joint Ransomware Task Force (JRTF), an interagency body established to unify and strengthen efforts against the ongoing threat of ransomware. The JRTF continues its work to accelerate progress and work closely across the cybersecurity community on several activities to include victim support, partner engagement, intelligence integration, and campaign coordination. 

Implementing CIRCIA's Reporting Requirement 

  • Some of CISA’s authorities under CIRCIA are regulatory in nature and require CISA to complete rulemaking activities before the reporting requirements go into effect.
  • As part of the rulemaking process, CIRCIA required CISA to publish a Notice of Proposed Rulemaking (NPRM) within 24 months of the enactment of CIRCIA, and to issue a Final Rule setting forth the regulatory requirements within 18 months of the publication of the NPRM.
    • The NPRM was published in the Federal Register and became open for public comment on April 4, 2024 and the comment period closed on July 3, 2024.
    • The NPRM is available here.
    • The public comments submitted in response to the NPRM have been posted to the rulemaking docket on regulations.gov and can be found searching for CISA-2022-0010-0163.  
  • Consistent with statutory requirements, CISA consulted with various entities throughout the rulemaking process for the NPRM, including Sector Risk Management Agencies (SRMAs), the Department of Justice (DOJ), other appropriate Federal agencies, and the DHS-led CIRC in developing the NPRM.
  • To ensure that the proposed rule benefited from the perspective of our broad partner community, beginning in September 2022, CISA published a Request for Information (RFI), hosted 10 in-person public listening sessions across the country, and conducted virtual, sector-specific listening sessions. These mechanisms provided opportunities for stakeholders to provide CISA with their perspectives on potential aspects of the proposed regulation prior to publication of the NPRM.
  • CISA also hosted virtual, sector-specific listening sessions with each of the 16 critical infrastructure sectors and with the Aviation Subsector.
  • CISA is grateful to the hundreds of individuals, groups, and organizations who attended the in-person and virtual listening sessions and submitted written comments in response to the RFI and NPRM.
  • CISA is reviewing and adjudicating comments received in response to the NPRM. This work will continue as we work through the thorough and deliberative process of implementing CIRCIA consistent with authorities given to us by Congress in the Final Rule.
  • Following publication of the Final Rule, CISA will engage with the public and stakeholder community to educate and inform stakeholders on the details of the Final Rule.
  • This engagement is part of CISA’s continued effort to foster transparency, collaboration, and partnership with directly affected stakeholders and the general public.

Sharing Information with CISA About Cyber Incidents or Ransom Payments 

  • Until the effective date of the Final Rule, organizations are not required to submit covered cyber incident or ransom payment reports under CIRCIA.
  • However, CISA strongly encourages organizations to continue voluntarily sharing cyber event information with CISA throughout the rulemaking period prior to the Final Rule’s effective date.
  • When information about cyber incidents is shared quickly, we can use this information to render assistance and provide warning to prevent other organizations from falling victim to a similar incident. This information is also critical to identifying trends that can help efforts to protect the homeland.

Share Information About a Cyber Incident

Organizations can share information about unusual cyber activity and/or cyber incidents to www.cisa.gov/report, report@cisa.gov or 1-844-Say-CISA (1-844-729-2472).

Report via email

 

Return to top
  • Topics
  • Spotlight
  • Resources & Tools
  • News & Events
  • Careers
  • About
Cybersecurity & Infrastructure Security Agency
  • Facebook
  • X
  • LinkedIn
  • YouTube
  • Instagram
  • RSS
CISA Central 1-844-Say-CISA SayCISA@cisa.dhs.gov
DHS Seal
CISA.gov
An official website of the U.S. Department of Homeland Security
  • About CISA
  • Budget and Performance
  • DHS.gov
  • FOIA Requests
  • No FEAR Act
  • Office of Inspector General
  • Privacy Policy
  • Subscribe
  • The White House
  • USA.gov
  • Website Feedback