CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act)
The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (Pub.L. 117-103, Division Y) requires covered critical infrastructure entities to report covered cyber incidents to CISA within 72 hours and ransom payments within 24 hours. Administered by the Cybersecurity and Infrastructure Security Agency (CISA). NPRM published April 2024; final rule expected Fall 2025.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (6)
Covered Entities and Scope
| Code | Title |
|---|---|
| Sec. 2240(a) | Definitions |
| Sec. 2240(b) | Covered entities determination |
| Sec. 2240(c) | Sector-based criteria |
Enforcement and Compliance
| Code | Title |
|---|---|
| AIDA-14 | AI and Data Commissioner |
| AIDA-15 | Penalties for Non-Compliance |
| AIDA-16 | Criminal Provisions |
| AIDA-17 | Audit and Inspection Powers |
| Art. 49 | Collective Dispute Resolution |
| Art. 51 | Entry into Force |
| Art. 52 | Appropriate Safeguards |
| Sec. 2244(a) | Subpoena authority |
| Sec. 2244(b) | Referral to Attorney General |
| Sec. 2244(c) | Civil penalties |
| Sec. 2244(d) | Liability protections |
Incident Reporting Requirements
| Code | Title |
|---|---|
| Dir. 1 | Mandatory Incident Reporting |
| Dir. 2 | Expanded Incident Categories |
| Dir. 3 | Incident Report Format |
| Dir. 4 | Point of Contact Designation |
| Sec. 2242(a) | Covered cyber incident report |
| Sec. 2242(b) | Ransom payment report |
| Sec. 2242(c) | Supplemental reports |
| Sec. 2242(d) | Report contents |
| Sec. 2242(e) | Preservation of information |
Information Sharing and Use
| Code | Title |
|---|---|
| Sec. 2243(a) | Sharing with federal agencies |
| Sec. 2243(b) | Privacy and civil liberties protections |
| Sec. 2243(c) | Use limitations |
| Sec. 2243(d) | Anonymisation and aggregation |
Interagency Coordination
| Code | Title |
|---|---|
| Sec. 2246(a) | Cyber Incident Reporting Council |
| Sec. 2246(b) | Harmonisation of reporting requirements |
| Sec. 2246(c) | Voluntary reporting mechanisms |
| Sec. 2246(d) | Threat intelligence sharing |
Scope and Definitions
Defines nursing personnel as all categories of persons providing nursing care and services, wherever they work.
| Code | Title |
|---|---|
| 64.2001 | Basis and Purpose |
| 64.2003 | Definitions |
| 64.2004 | Customer Approval Mechanisms |
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
| ILO-C149-01 | Article 1 — Definition of nursing personnel covering all categories providing nursing care and services |
Maps to 618 other frameworks
Frequently Asked Questions
What is CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act)?
CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) is a compliance framework from United States with 6 domains and 38 controls. The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (Pub.L. 117-103, Division Y) requires covered critical infrastructure entities to report covered cyber incidents to CISA within 72 hours and ransom payments within 24 hours. Administered by the Cybersecurity and Infrastructure Security Agency (CISA). NPRM published April 2024; final rule expected Fall 2025. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) have?
CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) has 38 controls organised across 6 domains. The largest domains are Enforcement and Compliance (11 controls), Incident Reporting Requirements (9 controls), Scope and Definitions (7 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) map to?
CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) maps to 618 other compliance frameworks. The top mapping partners are FAA Cybersecurity Framework for Aviation (26% coverage), ISO/IEC 27400:2022 (24% coverage), ILO Nursing Personnel Convention C149 (1977) (24% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) compliance?
Start your CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 38 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required