Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA)
CIRCIA is a U.S. federal law, signed in March 2022, that will require certain organizations in critical infrastructure sectors to report significant cyber incidents to the Cybersecurity and Infrastructure Security Agency (CISA). It also directs CISA to write the detailed regulations that spell out exactly who must report and what counts as a reportable incident. The reporting obligation is a legal and compliance requirement and is separate from any cyber insurance coverage an organization may carry.
CIRCIA (the Cyber Incident Reporting for Critical Infrastructure Act of 2022, signed into law in March 2022) is a U.S. statute that directs CISA to develop and issue regulations requiring 'covered entities' to report 'covered cyber incidents' to CISA within 72 hours, and to report ransomware payments within 24 hours. As of the evidence provided, the operative definitions of covered entity and covered cyber incident, along with the full scope of reporting obligations, were being established through a Notice of Proposed Rulemaking (NPRM) rather than a final rule; practitioners should confirm the current regulatory status and the precise definitions before relying on them. CIRCIA is a mandatory regulatory reporting regime, not an insurance policy provision or a resilience framework: compliance with its notification timelines does not by itself constitute incident response, business continuity, or a covered loss, and it neither triggers nor substitutes for coverage under a cyber policy, though a policy's own notice conditions and any regulatory-defense or regulatory-fine coverage would be governed separately by the specific policy wording. The precise definitional thresholds, exclusions, and covered sectors are determined by the implementing regulations and are out of scope for a summary definition.
Why it matters
CIRCIA marks a shift toward mandatory federal cyber incident reporting in the United States. Once its implementing regulations take effect, organizations designated as covered entities in critical infrastructure sectors will face a legal obligation to report covered cyber incidents to CISA within 72 hours and to report ransomware payments within 24 hours. For risk managers and compliance professionals, this creates a distinct regulatory workstream that must be tracked and operationalized alongside, but separate from, any contractual notice obligations owed to insurers.
The distinction between regulatory reporting and insurance is critical and easily blurred under the pressure of an active incident. Meeting CIRCIA's notification timelines does not by itself constitute incident response, business continuity, or a covered loss, and reporting to CISA neither triggers nor substitutes for coverage under a cyber policy. A cyber policy has its own notice conditions, and any regulatory-defense or regulatory-fine coverage is governed separately by the specific policy wording. Organizations should not assume that satisfying one obligation satisfies the other; the two run on different timelines, to different recipients, and for different purposes.
Because the operative definitions of covered entity and covered cyber incident, along with the full scope of reporting obligations, were being established through a Notice of Proposed Rulemaking rather than a final rule as of the evidence provided, practitioners should confirm the current regulatory status and precise definitions before relying on them. Building reporting workflows around thresholds and definitions that have not been finalized carries the risk that those thresholds will change.
Who it's relevant to
Inside CIRCIA
Common questions
Answers to the questions practitioners most commonly ask about CIRCIA.