DEFCON 3 · ELEVATED OBSERVATORY STATUS
04:24:00 UTC
EXPLORE DIRECTORY
LAST SYNCHRONIZED: 2026-08-20
lawin_force

Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA)

EXECUTIVE INTELLIGENCE SUMMARY

Federal statute mandating critical infrastructure entities report covered cyber incidents to CISA within 72 hours and ransomware payments within 24 hours.

Enacted to establish unified national situational awareness of cyber threats targeting 16 critical infrastructure sectors. Grants CISA administrative subpoena authorities to compel incident data and provides legal safe harbor and confidentiality protections for submitted reports.

SOURCE CITATIONS & ATTESTATIONS (1)
Federal Register: CIRCIA Reporting Requirements Final RuleCybersecurity and Infrastructure Security Agency (CISA)

CIRCIA Reporting Regulations 6 CFR Part 226

TELEMETRY CARDID: law-us-circia
ENTITY TYPE
law
INDEXED TAGS
#united_states#cisa#incident_reporting#ransomware_payment_disclosure#critical_infrastructure