Skip to content

Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements

ProposedCISA · Proposed rule · April 4, 2024

Summary

Proposes rules under the Cyber Incident Reporting for Critical Infrastructure Act of 2022 that would require covered critical infrastructure entities to report significant cyber incidents to CISA within 72 hours and ransom payments within 24 hours.

Read it on www.federalregister.gov

What FedXchange has recorded

No changes recorded. The watch records a new document and any change in its status.

Issuer
Cybersecurity and Infrastructure Security Agency (CISA)
Type
Proposed rule
Issued
April 4, 2024
Status
Proposed

A proposed rule or draft. It may change before it takes effect.

No final rule had been published as of October 2026; the August 2026 federal regulatory agenda lists it at the final rule stage.

Get new governance by email

A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.

Send me

We use your address only to send what you choose, and every email has a one-click unsubscribe. Read the privacy notice.