CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act)
CIRCIA: Required Reporting (Sec. 2242)

CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) CIRCIA-2242d: Third-Party Report Submission

A covered entity may use a third party (incident response firm, insurer, service provider, ISAO or law firm) to submit a required report, but this does not relieve the entity of its duty to comply; a third party that knowingly makes a ransom payment on the entity's behalf must advise the entity of its reporting responsibilities.

Other controls in CIRCIA: Required Reporting (Sec. 2242)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.