CIRCIA
Enacted United States (Federal) · Enacted Mar 15, 2022 · no upcoming deadlines
Deadlines
Summaries for reference, not legal advice. Check the official text.
What it does
Directs CISA to require covered critical infrastructure entities to report covered cyber incidents within 72 hours of reasonably believing one occurred and ransom payments within 24 hours of payment, and to preserve related data. Reporting obligations begin only once CISA's final rule takes effect.
- Who it applies to
- As proposed: entities in any of the 16 critical infrastructure sectors that exceed the SBA small business size standard for their industry, or meet sector-based criteria (e.g. hospitals, certain IT and communications providers, water systems). CISA estimated about 316,244 covered entities.
- Penalties
- CISA may issue requests for information and subpoenas; failure to comply with a subpoena may be referred to DOJ for a civil action and contempt. False statements are subject to 18 U.S.C. 1001; federal contractors may face procurement actions including suspension or debarment.
- Enforced by
- Cybersecurity and Infrastructure Security Agency (CISA), DHS; DOJ for civil enforcement of subpoenas
- Official name
- Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) and proposed implementing rule (6 CFR Part 226)
- Citation
- 6 U.S.C. 681-681g; Pub. L. 117-103, div. Y; NPRM 89 FR 23644 (Apr. 4, 2024), RIN 1670-AA04
- Topics
- cybersecurity, breach-notification
Research notes
Final rule not yet published as of 2026-09-22 (Federal Register search). CISA missed the statutory October 2025 deadline, then targeted May 2026, and the latest Unified Agenda lists the final rule for 09/2026 (month only). CISA held further town halls in 2026 (Federal Register notices of Feb. 13 and May 26, 2026) and has said it intends to streamline scope. Obligations will start on the final rule's effective date, expected to be well after publication.
Related
Questions about CIRCIA
- What are the CIRCIA compliance deadlines?
- Jul 3, 2024: NPRM comment period closed.
- Who does CIRCIA apply to?
- As proposed: entities in any of the 16 critical infrastructure sectors that exceed the SBA small business size standard for their industry, or meet sector-based criteria (e.g. hospitals, certain IT and communications providers, water systems). CISA estimated about 316,244 covered entities.
- What are the penalties under CIRCIA?
- CISA may issue requests for information and subpoenas; failure to comply with a subpoena may be referred to DOJ for a civil action and contempt. False statements are subject to 18 U.S.C. 1001; federal contractors may face procurement actions including suspension or debarment.