Skip to main content
Category: Regulatory & Privacy Compliance

Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA)

Also known as: CIRCIA, Cyber Incident Reporting for Critical Infrastructure Act of 2022
Simply put

CIRCIA is a U.S. federal law, signed in March 2022, that will require certain organizations in critical infrastructure sectors to report significant cyber incidents to the Cybersecurity and Infrastructure Security Agency (CISA). It also directs CISA to write the detailed regulations that spell out exactly who must report and what counts as a reportable incident. The reporting obligation is a legal and compliance requirement and is separate from any cyber insurance coverage an organization may carry.

Formal definition

CIRCIA (the Cyber Incident Reporting for Critical Infrastructure Act of 2022, signed into law in March 2022) is a U.S. statute that directs CISA to develop and issue regulations requiring 'covered entities' to report 'covered cyber incidents' to CISA within 72 hours, and to report ransomware payments within 24 hours. As of the evidence provided, the operative definitions of covered entity and covered cyber incident, along with the full scope of reporting obligations, were being established through a Notice of Proposed Rulemaking (NPRM) rather than a final rule; practitioners should confirm the current regulatory status and the precise definitions before relying on them. CIRCIA is a mandatory regulatory reporting regime, not an insurance policy provision or a resilience framework: compliance with its notification timelines does not by itself constitute incident response, business continuity, or a covered loss, and it neither triggers nor substitutes for coverage under a cyber policy, though a policy's own notice conditions and any regulatory-defense or regulatory-fine coverage would be governed separately by the specific policy wording. The precise definitional thresholds, exclusions, and covered sectors are determined by the implementing regulations and are out of scope for a summary definition.

Why it matters

CIRCIA marks a shift toward mandatory federal cyber incident reporting in the United States. Once its implementing regulations take effect, organizations designated as covered entities in critical infrastructure sectors will face a legal obligation to report covered cyber incidents to CISA within 72 hours and to report ransomware payments within 24 hours. For risk managers and compliance professionals, this creates a distinct regulatory workstream that must be tracked and operationalized alongside, but separate from, any contractual notice obligations owed to insurers.

The distinction between regulatory reporting and insurance is critical and easily blurred under the pressure of an active incident. Meeting CIRCIA's notification timelines does not by itself constitute incident response, business continuity, or a covered loss, and reporting to CISA neither triggers nor substitutes for coverage under a cyber policy. A cyber policy has its own notice conditions, and any regulatory-defense or regulatory-fine coverage is governed separately by the specific policy wording. Organizations should not assume that satisfying one obligation satisfies the other; the two run on different timelines, to different recipients, and for different purposes.

Because the operative definitions of covered entity and covered cyber incident, along with the full scope of reporting obligations, were being established through a Notice of Proposed Rulemaking rather than a final rule as of the evidence provided, practitioners should confirm the current regulatory status and precise definitions before relying on them. Building reporting workflows around thresholds and definitions that have not been finalized carries the risk that those thresholds will change.

Who it's relevant to

Compliance and legal professionals
CIRCIA is a mandatory regulatory reporting regime, and legal and compliance teams are responsible for determining whether their organization is a covered entity, what counts as a covered cyber incident, and how to meet the reporting timelines. Because the operative definitions were being set through an NPRM rather than a final rule as of the evidence provided, these professionals should track the regulatory status and confirm the precise definitions before building processes around them.
Risk managers and resilience planners
CIRCIA reporting is a distinct obligation that runs separately from incident response and business continuity work. Meeting CISA's 72-hour and 24-hour timelines does not by itself constitute incident response or a resilience outcome, so reporting steps should be integrated into incident playbooks without being treated as a substitute for actual response and recovery activity.
Cyber insurance brokers and underwriters
CIRCIA neither triggers nor substitutes for coverage under a cyber policy. A policy has its own notice conditions that are governed by the specific policy wording, and any regulatory-defense or regulatory-fine coverage is a separate matter. Brokers and underwriters should help insureds understand that a CISA report is not the same as an insurer notice and that the two obligations may run on different timelines.
Chief information security officers and security teams
CISOs and their teams are typically the first to identify an incident and are central to determining whether it meets a reportable threshold and to gathering the information required within the reporting windows. Given that ransomware payments carry a shorter 24-hour reporting timeline than the 72-hour general incident timeline, security teams need workflows that can distinguish and act on these obligations quickly.

Inside CIRCIA

Covered Entity Scope
CIRCIA applies to entities within designated critical infrastructure sectors. The precise definition of which entities qualify is established through implementing regulations rather than the statute alone, so practitioners should consult the applicable rule text for their sector rather than assuming coverage or exemption.
Covered Cyber Incident Reporting
The framework requires covered entities to report qualifying cyber incidents to the federal agency responsible for administering the program. What constitutes a reportable 'covered cyber incident' is defined by the implementing regulations, and the threshold for reporting is a regulatory determination rather than a matter of insurance policy wording.
Ransom Payment Reporting
Separately from incident reporting, the framework contemplates reporting of ransom payments made in response to ransomware. This is a regulatory reporting obligation and should not be conflated with cyber extortion coverage under a cyber insurance policy, which is a first-party coverage question governed by the specific policy terms.
Reporting Timeframes
The framework establishes deadlines within which covered incidents and ransom payments must be reported. The specific timeframes are set by statute and refined through the implementing rule; practitioners should verify the exact deadlines applicable to their obligations rather than relying on general recollection.
Regulatory Reporting, Not Coverage Trigger
CIRCIA is a mandatory regulatory reporting regime. It is distinct from the notice conditions in a cyber insurance policy, which are conditions precedent to coverage and operate on their own timelines and definitions. Satisfying one obligation does not automatically satisfy the other.

Common questions

Answers to the questions practitioners most commonly ask about CIRCIA.

Does filing a CIRCIA report with CISA satisfy my other breach-notification obligations?
No. CIRCIA reporting to CISA is a distinct federal obligation and does not, by itself, discharge separate notification duties that may arise under state breach-notification laws, sector-specific regulators, contractual obligations, or other regimes. Each of those obligations can have its own triggers, timelines, recipients, and content requirements. Treat CIRCIA reporting as one item in a broader notification map rather than a substitute for the others, and confirm the specific requirements applicable to your incident and jurisdiction.
Is CIRCIA an insurance requirement or a coverage term in my cyber policy?
No. CIRCIA is a regulatory reporting obligation, not an insurance concept. It does not create, trigger, or expand coverage, and it is not a policy condition unless a specific policy's wording references it. Whether costs associated with regulatory reporting or investigation are covered depends entirely on your policy's terms, endorsements, exclusions, and conditions. Do not assume compliance with CIRCIA has any automatic effect on a claim; review the specific wording and consult your broker or coverage counsel.
Who within our organization should own CIRCIA reporting readiness?
Ownership is typically shared and should be assigned before an incident occurs, subject to the final rule's applicability and timing requirements as implemented. In many organizations, legal or compliance coordinates the reporting decision, the CISO or incident response function supplies the technical facts, and executive or crisis-management leadership approves external communications. Because reporting is time-sensitive, clarifying decision authority and escalation paths in advance is generally more effective than resolving roles during an active incident.
How should CIRCIA obligations be reflected in our incident response plan?
It is common practice to build regulatory reporting steps directly into the incident response runbook, including a step to assess whether an incident falls within the applicable reporting criteria, who makes that determination, and the internal timeline for preparing a submission. Note that incident response (the technical containment and investigation process) is distinct from the reporting workflow; the plan should connect them so that factual findings feed the reporting decision without conflating the two functions.
What information should we be prepared to capture to support a potential CIRCIA report?
Organizations generally benefit from preserving and documenting the facts an authority would expect in a report, such as the nature of the incident, affected systems, timeline of events, and response actions taken, consistent with the content and format specified in the applicable final rule. Establishing consistent evidence-preservation and logging practices in advance supports both accurate reporting and the underlying investigation. The precise data elements and thresholds are set by the implementing rule, so validate your capture checklist against the current requirements rather than assumptions.
How does CIRCIA reporting readiness relate to our broader resilience program?
Reporting readiness is a compliance and governance capability, not a resilience metric like RTO or RPO, and it does not by itself reduce the likelihood or impact of an incident. It sits alongside business continuity, disaster recovery, and crisis management as part of overall preparedness. Integrating the reporting workflow into crisis-management exercises and tabletop testing is a common way to confirm that decision-making and communication paths function under pressure, but it complements rather than replaces technical recovery and mitigation measures.

Common misconceptions

Reporting an incident under CIRCIA satisfies the notice requirements of my cyber insurance policy.
These are separate obligations. Regulatory reporting under CIRCIA is directed to a federal agency, while policy notice is a condition precedent to coverage directed to the insurer, typically governed by different definitions, deadlines, and recipients. Subject to the specific policy wording, failing to give timely notice to the insurer can jeopardize coverage regardless of whether a regulatory report was filed.
CIRCIA determines whether my cyber losses are covered.
CIRCIA is a regulatory reporting framework and does not create, expand, or restrict insurance coverage. Whether a given loss is covered depends on the policy's insuring agreements, endorsements, exclusions, conditions, and applicable jurisdiction, not on any reporting obligation.
Because CIRCIA covers ransom payment reporting, it addresses my cyber extortion exposure.
Reporting a ransom payment is a compliance action, not a risk transfer or risk mitigation mechanism. Whether extortion payments and related costs are reimbursable is a first-party cyber insurance question subject to the specific policy terms, sublimits, and conditions, and CIRCIA reporting does not change that analysis.

Best practices

Confirm whether your organization qualifies as a covered entity by consulting the applicable implementing regulation for your critical infrastructure sector rather than assuming inclusion or exemption.
Map CIRCIA reporting deadlines and definitions separately from your cyber insurance notice conditions, and build both into your incident response playbook as distinct workstreams.
Verify the specific reporting timeframes for covered incidents and ransom payments against the current rule text, since these are regulatory determinations that must be met precisely.
Coordinate legal, compliance, and insurance stakeholders early in an incident so regulatory reporting and insurer notice are handled in parallel without one being overlooked in favor of the other.
Do not treat CIRCIA compliance as a substitute for resilience measures; maintain business continuity and incident response capabilities independently, since reporting obligations do not reduce the likelihood or impact of an incident.
Document your reporting decisions and timelines contemporaneously so you can demonstrate compliance with both the regulatory regime and any policy conditions precedent.
Promotional banner for the Penetration Report Template Kit