Cyber Incident Reporting for Critical Infrastructure Act of 2022
CIRCIA
Breach notification · Data security
CIRCIA will require covered critical infrastructure entities to report covered cyber incidents to CISA within 72 hours and ransom payments within 24 hours. The reporting duties take effect only on the dates set in CISA's final rule; as of September 2026 the final rule had not been published (CISA held further town halls in 2026 and targeted fall 2026).
- Where
- Federal
- Citation
- 6 U.S.C. 681-681g (Pub. L. 117-103, div. Y); proposed 6 CFR Part 226
- Status
- Enacted, not yet in force
- Enforced by
- Cybersecurity and Infrastructure Security Agency (DHS)
- People can sue
- No
- Penalties
- CISA may issue requests for information and subpoenas to noncompliant entities and refer them to DOJ for civil enforcement; there are no statutory fines.
- Applies to
- Covered entities in critical infrastructure sectors, as defined in CISA's final rule (proposed rule estimated over 300,000 entities)
Breach duties
- Report a covered cyber incident to CISA within 72 hours after reasonably believing it occurred.6 U.S.C. 681b(a)(1) · Only if: Operative only once CISA's final rule sets the effective date (6 U.S.C. 681b(a)(7))
- Report a ransom payment made in response to a ransomware attack within 24 hours.6 U.S.C. 681b(a)(2) · Only if: Operative only once CISA's final rule sets the effective date
Other duties
- Preserve data relevant to a reported incident or ransom payment.6 U.S.C. 681b(a)(4) · Only if: Operative only once CISA's final rule sets the effective date
Sources
- Official text
- 6 U.S.C. 681b (OLRC)
- CISA, CIRCIA Rulemaking Town Hall Meetings notice, Federal Register (May 26, 2026)
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Unverified: Final rule timing (fall 2026) is from secondary news sources | CISA final rule status after mid-September 2026 not confirmed
Research reference, not legal advice.