Skip to content

CIRCIA

Enacted United States (Federal) · Enacted Mar 15, 2022 · no upcoming deadlines

Deadlines

DateWhat happens
Jul 3, 2024NPRM comment period closed2.2 years ago

Summaries for reference, not legal advice. Check the official text.

What it does

Directs CISA to require covered critical infrastructure entities to report covered cyber incidents within 72 hours of reasonably believing one occurred and ransom payments within 24 hours of payment, and to preserve related data. Reporting obligations begin only once CISA's final rule takes effect.

Who it applies to
As proposed: entities in any of the 16 critical infrastructure sectors that exceed the SBA small business size standard for their industry, or meet sector-based criteria (e.g. hospitals, certain IT and communications providers, water systems). CISA estimated about 316,244 covered entities.
Penalties
CISA may issue requests for information and subpoenas; failure to comply with a subpoena may be referred to DOJ for a civil action and contempt. False statements are subject to 18 U.S.C. 1001; federal contractors may face procurement actions including suspension or debarment.
Enforced by
Cybersecurity and Infrastructure Security Agency (CISA), DHS; DOJ for civil enforcement of subpoenas
Official name
Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) and proposed implementing rule (6 CFR Part 226)
Citation
6 U.S.C. 681-681g; Pub. L. 117-103, div. Y; NPRM 89 FR 23644 (Apr. 4, 2024), RIN 1670-AA04
Topics
cybersecurity, breach-notification
Verified 2026-09-22 cisa.gov reginfo.gov federalregister.gov hunton.com
Research notes

Final rule not yet published as of 2026-09-22 (Federal Register search). CISA missed the statutory October 2025 deadline, then targeted May 2026, and the latest Unified Agenda lists the final rule for 09/2026 (month only). CISA held further town halls in 2026 (Federal Register notices of Feb. 13 and May 26, 2026) and has said it intends to streamline scope. Obligations will start on the final rule's effective date, expected to be well after publication.

Related

Questions about CIRCIA
What are the CIRCIA compliance deadlines?
Jul 3, 2024: NPRM comment period closed.
Who does CIRCIA apply to?
As proposed: entities in any of the 16 critical infrastructure sectors that exceed the SBA small business size standard for their industry, or meet sector-based criteria (e.g. hospitals, certain IT and communications providers, water systems). CISA estimated about 316,244 covered entities.
What are the penalties under CIRCIA?
CISA may issue requests for information and subpoenas; failure to comply with a subpoena may be referred to DOJ for a civil action and contempt. False statements are subject to 18 U.S.C. 1001; federal contractors may face procurement actions including suspension or debarment.

When the rules change: new data, privacy and AI laws and deadlines, the next morning.