Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
Commencement not set.
A vulnerability and incident reporting rule binding public and private bodies.
As of 20 September 2026.
What it requires
- None of this instrument's reporting duties binds anyone yet: the covered cyber incident report, the ransom payment report, the supplemental report, and the data-preservation duty in 6 U.S.C. 681b(a) take effect only on the dates a final rule prescribes, and the Cybersecurity and Infrastructure Security Agency had not issued that final rule as of September 20, 2026. When the rule takes effect, it will reach your organization only if you are a covered entity in one of sixteen critical-infrastructure sectors, a status the statute leaves to the rule to define; declare operates_essential_service if your organization is a designated critical-infrastructure operator, since the Agency's April 2024 proposal would define that class by a small-business size threshold or a sector-specific criterion rather than by anything a general software or AI vendor does.
- Once the final rule takes effect, report a covered cyber incident to the Agency not later than 72 hours after your organization reasonably believes that the covered cyber incident has occurred.
- Once the final rule takes effect, report a ransom payment to the Agency not later than 24 hours after your organization makes the payment, even where the underlying ransomware attack is not itself a covered cyber incident.
- Once the final rule takes effect, promptly submit an update to a previously submitted covered cyber incident report whenever substantial new or different information becomes available or a ransom payment is later made, continuing until your organization notifies the Agency that the incident has concluded and been fully mitigated and resolved, and preserve data relevant to the incident or payment under the procedures the final rule establishes.
- A cloud service provider or managed service provider whose own compromise caused the impact at one of your customers is not, by virtue of that fact alone, a covered entity required to report; the duty runs to the covered entity whose systems were affected, unless the provider independently meets the covered-entity criteria in its own right.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The Cyber Incident Reporting for Critical Infrastructure Act of 2022 is a federal statute enacted March 15, 2022 that would require a covered entity to report a covered cyber incident and a ransom payment to the Cybersecurity and Infrastructure Security Agency. A covered entity must report a covered cyber incident to the Agency not later than 72 hours after the covered entity reasonably believes the incident has occurred.
A covered entity that makes a ransom payment must report the payment to the Agency not later than 24 hours after the payment is made, even where the underlying attack is not itself a covered cyber incident. A covered entity must also submit a prompt supplemental report whenever substantial new information becomes available or a later ransom payment is made, continuing until the covered entity reports the incident concluded, and must preserve data relevant to the incident or payment.
The statute leaves the definition of covered entity, and the effective date of all four of these duties, to a final rule the Agency must issue. The Agency published a notice of proposed rulemaking on April 4, 2024 at 89 FR 23644, docket CISA-2022-0010, proposing to define covered entity by a small-business size standard or by one of several sector-based criteria across sixteen critical infrastructure sectors.
The statute required the Agency to issue the final rule not later than 18 months after that publication, a deadline of October 4, 2025, and the Agency has not met it. As of September 20, 2026 the Agency has not published a final rule, and its own published status page states that it continues to work on the final rule after multiple lapses in its own funding disrupted the rulemaking.
Until the final rule takes effect none of these four duties binds anyone, and the Agency asks entities only to volunteer cyber incident information in the meantime.
The proposed rule states that a cloud service provider or a managed service provider is not itself obligated to report merely because a compromise of its own systems caused the impact at a customer, since the reporting duty runs to the covered entity whose systems were affected rather than to the vendor, unless that vendor independently meets the covered-entity criteria in its own right.
When LexLint raises it
operates_essential_service
Read the law
United States Code, 6 U.S.C. 681b, official House Office of the Law Revision Counsel text
the covered-entity definition sits at 6 U.S.C. 681(4)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.