Skip to main content

SECURITY OPERATIONS & ROLES

What Is CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act)?

DEFINITION

CIRCIA is the Cyber Incident Reporting for Critical Infrastructure Act, a 2022 U.S. federal law directing CISA to require covered critical infrastructure entities to report substantial cyber incidents within 72 hours and ransom payments within 24 hours. The implementing final rule has not yet been published; CISA has targeted September 2026, and obligations begin once the rule takes effect.

CIRCIA, the Cyber Incident Reporting for Critical Infrastructure Act of 2022, is the U.S. federal law that directs CISA to establish mandatory cyber incident reporting for critical infrastructure. Once its implementing rule takes effect, covered entities must report substantial cyber incidents to CISA within 72 hours and ransom payments within 24 hours, with supplemental reports as new information emerges.

Coverage will reach entities across the 16 critical infrastructure sectors, including energy, water, healthcare, financial services, the defense industrial base, and critical manufacturing, subject to the size and criticality criteria set in the final rule. As of August 2026, the final rule has not been published. CISA has targeted September 2026, and reporting obligations begin only when the rule is in effect.

The practical move is to prepare now rather than parse the rule under deadline pressure later. A 72-hour clock is unforgiving without a tested incident response plan, a decision tree for what counts as a reportable incident, and clarity on how CIRCIA interacts with overlapping regimes such as SEC disclosure rules, state breach laws, and sector-specific requirements. For utilities, CIRCIA reporting will sit alongside existing NERC CIP incident reporting obligations, so the two workflows should be designed together.

Running a program that has to satisfy this?

A Z Cyber advisor can walk your current posture against the requirement and show you what a running program looks like on Glance.

Meet Your Security Team →