Policy Briefing — U.S. Cyber Incident Reporting for Critical Infrastructure Act Signed
President Biden signed the Cyber Incident Reporting for Critical Infrastructure Act on 15 March 2022, establishing federal mandates for covered entities to report significant cyber incidents and ransom payments to CISA.
On 15 March 2022 the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) became law as part of the Consolidated Appropriations Act. The statute directs the Cybersecurity and Infrastructure Security Agency (CISA) to require covered critical infrastructure owners and operators to report substantial cyber incidents within 72 hours and ransomware payments within 24 hours. It also gives CISA subpoena authority to compel reports, establishes liability protections, and sets timelines for notice of supplemental information.
The law launches a rulemaking that will define covered entities and reportable incidents, with a two-year window for final rules. Security leaders should begin aligning incident response playbooks to rapid-reporting expectations and inventorying what telemetry and forensic artifacts will be necessary to satisfy CISA requests.
- Congress.gov bill page provides the enacted statutory text and timeline triggers.
- CISA CIRCIA overview summarizes reporting thresholds, enforcement tools, and forthcoming rulemaking milestones.
Continue in the Policy pillar
Return to the hub for curated research and deep-dive guides.
Latest guides
-
Semiconductor Industrial Strategy Policy Guide — Zeph Tech
Coordinate CHIPS and Science Act, EU Chips Act, and Defense Production Act programmes with capital planning, compliance, and supplier readiness.
-
Digital Markets Compliance Guide — Zeph Tech
Implement EU Digital Markets Act, EU Digital Services Act, UK Digital Markets, Competition and Consumers Act, and U.S. Sherman Act requirements with cross-functional operating…
-
Export Controls and Sanctions Policy Guide — Zeph Tech
Integrate U.S. Export Control Reform Act, International Emergency Economic Powers Act, and EU Dual-Use Regulation requirements into trade compliance, engineering, and supplier…




