ACE Rebrand Update: The Alliance for Citizen Engagement is now the Alliance for Civic Engagement.

CIRCIA Explained: What the Cyber Incident Reporting Law Requires and Why It’s Controversial 

circia cyber incident

Key points 

  • The Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) is a mandatory cyber incident reporting law passed in 2022 that requires critical infrastructure organizations to report major cyber incidents
  • The law was designed to organize the cyber threat reporting system 
  • CIRCIA faces significant controversy over scope and feasibility 

Why has Cyber Incident Reporting Become a National Priority?

In recent years, cyberattacks have grown into a serious threat to national security. Two incidents in particular showed just how vulnerable the country’s critical systems were. In 2020, the SolarWinds attack allowed foreign hackers to break into multiple U.S. government agencies by hiding malicious code inside a widely used software update. In 2021, the Colonial Pipeline ransomware attack forced the company to shut down fuel delivery across much of the East Coast, causing gas shortages in several states. Together, these attacks made clear that the country needed a stronger, more coordinated system for detecting and responding to cyber threats before they could cause widespread harm. 

The Problem that CIRCIA Was Built to Fix: Blind Spots and Fragmentation

Before CIRCIA, the federal government had no reliable way to collect and analyze information about cyberattacks across different industries. This meant that there was no way to get a clear, complete picture of the threats facing the country’s critical infrastructure. Without that information, the government could not organize an effective national response. Furthermore, no single agency ever had a complete picture of what was happening across critical infrastructure as voluntary reporting programs failed to bring major incidents to light quickly enough to allow for a government response. As a result, the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) was created to solve this problem by making cyber incident reporting mandatory for critical infrastructure organizations. 

What is CIRCIA?

The overall goal of CIRCIA is to create a centralized reporting system that gives the government better awareness of cyber threats and allows them to coordinate a faster, more organized response. CIRCIA requires organizations in critical sectors – including healthcare, energy, and parts of the financial services industry – to report major cyber attacks to CISA within 72 hours of discovering the incident. If an organization pays a ransom in response to a ransomware attack, a separate report must be submitted to CISA within 24 hours of making that payment. 

CIRCIA was signed into law in March 2022 as part of the Consolidated Appropriations Act. It is the first law to create a comprehensive federal requirement for reporting cyber incidents, meaning it applies across multiple industries rather than just one sector. However, the Cybersecurity and Infrastructure Agency (CISA) is still in the process of writing the rules to implement the legislation. CISA originally planned to finalize these rules earlier, but delayed the final rule to May 2026 after pushback from Congress and industry groups who argued the proposed requirements would place too heavy a burden on organizations. 

Key Statutory Requirements 

CIRCIA has several specific legal requirements that covered organizations must follow. These requirements cover who has to report, what counts as a reportable incident, and what happens if an organization fails to comply. 

Reporting Timelines

  • Covered entities must report substantial cyber incidents to CISA within 72 hours of discovering the attack.
  • If a ransom payment is made in response to a ransomware attack, that payment must be reported to CISA within 24 hours. 
  • A “substantial cyber incident” is defined as one that impacts the integrity, confidentiality, resiliency or security of a covered entity’s systems. 

Covered sectors

  • CIRCIA applies to organizations operating in 16 critical infrastructure sectors that the government has identified as essential to national security, economic security, or public health. These include industries like energy, healthcare, water systems, transportation, and financial services.

CISA’s Authority

  • Congress gave CISA the responsibility of defining two key terms: “covered entity” and “substantial cyber incident.” By giving CISA this power, they have broad discretion in shaping exactly who the law applies to and what kinds of incidents must be reported 
  • An incident is eligible for reporting only when it was carried out by an actor with malicious intent
  • Organizations can qualify as covered entities either by the sector they operate in or by their size. The law applies to organizations that exceed the Small Business Administration’s size standards for their industry.

Enforcement

  • If an organization fails to comply, CISA has the authority to issue a subpoena to force the organization to report.
  • If the organization still does not comply, CISA can refer the violation to the Attorney General for further legal action. 

The Debate Surrounding CIRCIA 

Supporters of CIRCIA argue that mandatory reporting closes a real national security gap that voluntary frameworks never could. The federal government needs real-time visibility into threats across critical infrastructure, and fragmented, sector-by-sector approaches simply cannot keep up with attacks that cross industry lines. Centralizing reporting also makes it possible to share threat intelligence across agencies and industries, giving everyone a clearer picture of the threat landscape. 

Critics, however, raise serious concerns about how the law works in practice. The 72-hour and 24-hour reporting timelines are seen as unrealistic. During an active attack, organizations are focused on containing damage and restoring systems, not filing government reports. CISA’s proposed rule would apply to more than 316,000 entities, which many argue reflects statutory language that was far too vague from the start. Compliance also adds costs and duplicates existing reporting obligations without removing them. 

A Law Under Pressure As the Final Rule Approaches

CISA is expected to publish the final ruel implementing CIRCA in May 2026. When published, it will represent the first comprehensive federal cyber incident reporting mandate in U.S. history. However, given the ongoing concerns from Congress and industry professionals, the final rule may look much different from what was originally proposed. The exact timeline for when reporting obligations will begin for covered entities will be explicitly stated in the final rule. 

FAQ

  1. What types of organizations have to report under CIRCIA?
    1. CIRCIA covers organizations in 16 critical infrastructure sectors deemed essential to national security, economy security, or public health. Examples of these sectors include healthcare, energy, and financial services. Organizations must exceed the Small Business Administration’s size standards for their sector to be considered a “covered entity.” 
  2. What counts as a “substantial cyber incident” that must be reported?
    1. A substantial cyber incident is one that impacts the integrity, confidentiality, resiliency, or security of a covered entity’s system and was carried out by an actor with malicious intent. 
  3. Why are the reporting timelines controversial?
    1. Critics argue that the 72-hour timeline for reporting cyber incidents and the 24-hour timeline for ransomware payments are unrealistic because organizations are often still in the middle of assessing breach, constraining the damage, and restoring systems during the critical early hours. 
  4. When will CIRCIA actually take effect?
    1. CISA delayed the final rule implementing CIRCIA to May 2026 following pushback from Congress and industry about the law being too burdensome. Once published, it will be the first comprehensive federal cyber incident reporting mandate, though the exact timeline for when reporting obligations begin will be specified in that final rule.

[pvc_stats postid="" increase="1" show_views_today="0"]

Share this post

Related Briefs

Give feedback on this brief:

Free to read. Funded by people like you. Support the Fellows making it possible.