Privacy Law Library

Cyber Incident Reporting for Critical Infrastructure Act of 2022

CIRCIA

Breach notification · Data security

CIRCIA will require covered critical infrastructure entities to report covered cyber incidents to CISA within 72 hours and ransom payments within 24 hours. The reporting duties take effect only on the dates set in CISA's final rule; as of September 2026 the final rule had not been published (CISA held further town halls in 2026 and targeted fall 2026).

Where
Federal
Citation
6 U.S.C. 681-681g (Pub. L. 117-103, div. Y); proposed 6 CFR Part 226
Status
Enacted, not yet in force
Enforced by
Cybersecurity and Infrastructure Security Agency (DHS)
People can sue
No
Penalties
CISA may issue requests for information and subpoenas to noncompliant entities and refer them to DOJ for civil enforcement; there are no statutory fines.
Applies to
  • Covered entities in critical infrastructure sectors, as defined in CISA's final rule (proposed rule estimated over 300,000 entities)

Breach duties

  • Report a covered cyber incident to CISA within 72 hours after reasonably believing it occurred.6 U.S.C. 681b(a)(1) · Only if: Operative only once CISA's final rule sets the effective date (6 U.S.C. 681b(a)(7))
  • Report a ransom payment made in response to a ransomware attack within 24 hours.6 U.S.C. 681b(a)(2) · Only if: Operative only once CISA's final rule sets the effective date

Other duties

  • Preserve data relevant to a reported incident or ransom payment.6 U.S.C. 681b(a)(4) · Only if: Operative only once CISA's final rule sets the effective date

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: Final rule timing (fall 2026) is from secondary news sources | CISA final rule status after mid-September 2026 not confirmed

Research reference, not legal advice.