The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) will require many critical infrastructure organizations to report significant cyber incidents to the Cybersecurity and Infrastructure Security Agency (CISA). The details are now on the table. CISA published its proposed rule on April 4, 2024, and comments are due June 3, 2024. Under the proposal, covered entities would report a covered cyber incident within 72 hours of reasonably believing it occurred, send supplemental reports as new information emerges, and preserve related data. None of this applies yet. Reporting obligations begin only once a final rule takes effect, which the law expects about 18 months after the proposal.
Because the proposed definition of "covered entity" is broad, many mid-sized organizations that don't think of themselves as critical infrastructure may find they're in scope. Here's what CISA has proposed and how to prepare.
What is CIRCIA?
CIRCIA was signed into law on March 15, 2022, as part of the Consolidated Appropriations Act, 2022. It directs CISA to write regulations requiring covered entities to report covered cyber incidents to the agency. The statute sets the framework, including the 72-hour deadline, but leaves CISA to define who is covered, what counts as a reportable incident and what reports must contain.
The law set two rulemaking deadlines. CISA had to publish a proposed rule within 24 months of enactment, and it must publish a final rule within 18 months after the proposal.
Where does the CIRCIA rulemaking stand?
| Date | Milestone |
|---|---|
| March 15, 2022 | CIRCIA signed into law |
| April 4, 2024 | Proposed rule published in the Federal Register |
| June 3, 2024 | Public comment deadline |
| About October 2025 | Final rule due, 18 months after the proposal |
| Final rule's effective date | Reporting requirements begin |
The proposal is long and detailed, and CISA will review public comments before finalizing anything. Expect changes. Everything below describes what CISA has proposed, not settled requirements.
Who would be a covered entity under CIRCIA?
CISA proposes a two-step test. First, the entity must be in one of the critical infrastructure sectors. Second, it must meet either of two criteria:
- Size-based. The entity exceeds the Small Business Administration's small business size standard for its industry, which varies by industry code and is usually based on annual revenue or number of employees.
- Sector-based. The entity meets one or more criteria CISA has written for specific sectors, regardless of its size.
The proposal includes sector-based criteria for 13 sectors:
- Chemical
- Communications
- Critical Manufacturing
- Defense Industrial Base
- Emergency Services
- Energy
- Financial Services
- Government Facilities
- Healthcare and Public Health
- Information Technology
- Nuclear Reactors, Materials, and Waste
- Transportation Systems
- Water and Wastewater Systems
The size-based test is what makes the scope so wide. Any organization in a critical infrastructure sector that is larger than the SBA's small business threshold for its industry would be covered, whether or not it meets a sector-specific criterion. Smaller organizations can still be covered through the sector-based criteria. CISA estimates that 316,244 entities would meet the proposed definition of a covered entity.
To work out where you stand, identify the industry codes that describe your business, check the corresponding SBA size standards, and then read the sector-based criteria for any sector you operate in.
Which incidents would have to be reported?
A "covered cyber incident" is a substantial cyber incident experienced by a covered entity. CISA proposes that an incident is substantial if it leads to any of the following:
- A substantial loss of confidentiality, integrity or availability of an information system or network.
- A serious impact on the safety and resiliency of operational systems and processes.
- A disruption of the ability to engage in business or industrial operations, or to deliver goods or services.
- Unauthorized access facilitated through or caused by a compromise of a cloud service provider, managed service provider or other third-party data hosting provider, or by a supply chain compromise.
The fourth category matters for organizations that rely heavily on outside providers. An incident that starts at a provider can still create a reporting obligation for you if it results in unauthorized access to your systems.
What are the proposed CIRCIA reporting deadlines?
72-hour covered cyber incident reports
A covered entity would report a covered cyber incident to CISA no later than 72 hours after it reasonably believes the incident occurred. The clock starts at reasonable belief, not at the end of an investigation. Organizations won't have complete facts at that point and aren't expected to.
The proposal would also require a report within 24 hours of making a ransom payment.
Supplemental reports
A covered entity would have to submit supplemental reports promptly if substantial new or different information becomes available. That obligation continues until the entity notifies CISA that the incident has concluded and been fully mitigated and resolved.
Reports filed by third parties
A covered entity could authorize a third party, such as an incident response firm, law firm or service provider, to submit reports on its behalf. The legal obligation to report would stay with the covered entity.
The substantially similar reporting exception
Many critical infrastructure organizations already report cyber incidents to a sector regulator or another federal agency. CIRCIA includes an exception for entities that report substantially similar information, within a substantially similar timeframe, to another federal agency. Under the proposal, the exception would apply where CISA and that agency have entered into a CIRCIA Agreement. Until those agreements exist, it's hard to know how much duplicate reporting the exception will remove.
What would a CIRCIA report include?
The statute lists the core content for covered cyber incident reports, and the proposal builds on it. Expect to provide, to the extent known:
- a description of the incident, including the affected systems, networks and devices and their functions
- the estimated date range of the incident
- the impact on the entity's operations
- the vulnerabilities exploited, the security defenses in place, and the tactics, techniques and procedures used
- any identifying or contact information for the actor believed to be responsible
- the categories of information believed to have been accessed or acquired
- identifying and contact information for the covered entity
Much of this information is incomplete at the 72-hour mark. That's what the supplemental reports are for.
What data would have to be preserved?
The statute requires covered entities to preserve data relevant to a covered cyber incident, following procedures set in the final rule. The proposal sets out the types of data and records that must be kept and for how long.
In practice, this means your incident response plan needs a preservation step early on, before systems are rebuilt or logs roll over. Check that your log retention periods, forensic imaging practices and evidence handling can support a preservation obligation that may run well after the incident is closed.
How would CISA enforce the rule?
CIRCIA gives CISA escalating tools. If CISA believes a covered entity failed to report, it can issue a request for information. If the entity doesn't respond adequately, CISA can issue a subpoena, and it can refer a failure to comply with a subpoena to the Attorney General for a civil action. The proposal lays out procedures for each step.
The statute also protects information submitted in reports. Reports are exempt from disclosure under the Freedom of Information Act, submitting one doesn't waive legal privilege, and reports generally can't be used to regulate the reporting entity, with limited exceptions. The statute also bars lawsuits based on the submission of a compliant report, with narrow exceptions for actions by the federal government.
How should organizations prepare for CIRCIA?
The final rule is likely more than a year away, but several steps are worth taking now.
- Assess whether you'd be covered. Check your sector, your industry codes and the SBA size standards, then read the sector-based criteria that apply to you. Record the analysis so you can update it when the final rule arrives.
- Map your existing reporting obligations. List every regulator, contract and law that already requires you to report cyber incidents, with deadlines. You'll need that list to see where CIRCIA overlaps.
- Align incident classification with the four impact types. Your severity scheme should make it easy to spot a potential substantial cyber incident early, since the 72-hour clock starts at reasonable belief.
- Decide who files. Name the person or team responsible for CIRCIA reports and decide whether you'd authorize a third party to submit on your behalf.
- Review provider contracts. Given the third-party impact category, check that key cloud, managed service and hosting providers must notify you of security incidents promptly.
- Build preservation into response. Add an explicit data preservation step to your incident response plan and check your log retention.
- Consider commenting. If the proposal would create practical problems for your organization or sector, the deadline is June 3, 2024.
Frequently asked questions
Do we have to report incidents to CISA under CIRCIA now?
No. CIRCIA's reporting requirements take effect only after CISA issues a final rule and that rule becomes effective. CISA continues to accept voluntary incident reports in the meantime.
When will the CIRCIA final rule be published?
The statute requires a final rule within 18 months of the proposal's April 4, 2024 publication, which points to around October 2025. The effective date will be set in the final rule.
Are small businesses covered?
Not under the size-based criterion, which by design excludes organizations below the SBA's small business size standard. A small organization can still be a covered entity if it meets a sector-based criterion.
What if we already report incidents to another federal agency?
You may qualify for the substantially similar reporting exception, but only if CISA and that agency have a CIRCIA Agreement in place and your existing report meets the conditions.
Key takeaways
- CISA's proposed rule would require covered entities to report covered cyber incidents within 72 hours of reasonable belief, with supplemental reports as facts change.
- Coverage would reach any critical infrastructure entity above the SBA small business size standard, plus smaller entities that meet sector-based criteria.
- Incidents that originate at cloud, managed service and hosting providers can be reportable.
- These are proposals. Comments are due June 3, 2024, and the final rule is expected around October 2025.
- Use the time to assess coverage, map overlapping obligations and tighten incident classification and data preservation.
This summary reflects the proposed rule and isn't legal advice. Confirm your organization's status and obligations with counsel.