Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements
ProposedCISA · Proposed rule · April 4, 2024
Summary
Proposes rules under the Cyber Incident Reporting for Critical Infrastructure Act of 2022 that would require covered critical infrastructure entities to report significant cyber incidents to CISA within 72 hours and ransom payments within 24 hours.
What FedXchange has recorded
No changes recorded. The watch records a new document and any change in its status.
- Issuer
- Cybersecurity and Infrastructure Security Agency (CISA)
- Type
- Proposed rule
- Issued
- April 4, 2024
- Status
- Proposed
A proposed rule or draft. It may change before it takes effect.
No final rule had been published as of October 2026; the August 2026 federal regulatory agenda lists it at the final rule stage.
Get new governance by email
A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.