CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act)
The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (Pub.L. 117‑103, Division Y) requires covered critical infrastructure entities to report covered cyber incidents to the Cybersecurity and Infrastructure Security Agency (CISA) within 72 hours of discovery and to report ransom payments within 24 hours. The act establishes reporting requirements, defines covered entities, and mandates the Secretary of Homeland Security to issue guidance and maintain a public database of reported incidents.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (17)
Communications
| Code | Title |
|---|---|
| CIRCIA-19 | Public Communications Coordination |
Covered Entities and Scope
| Code | Title |
|---|---|
| Sec. 2240(a) | Definitions |
| Sec. 2240(b) | Covered entities determination |
| Sec. 2240(c) | Sector-based criteria |
Detection
| Code | Title |
|---|---|
| CIRCIA-8 | Incident Detection Capability |
| CIRCIA-9 | Triage and Determination Process |
Enforcement and Compliance
| Code | Title |
|---|---|
| AIDA-14 | Third-Party AI Components |
| AIDA-15 | Security of AI Systems |
| AIDA-16 | Generative AI Specific Measures |
| AIDA-17 | User Redress |
| Art. 49 | Collective Dispute Resolution |
| Art. 51 | Classification of General-Purpose AI Models as General-Purpose AI Models with Systemic Risk |
| Art. 52 | Procedure |
| Sec. 2244(a) | Subpoena authority |
| Sec. 2244(b) | Referral to Attorney General |
| Sec. 2244(c) | Civil penalties |
| Sec. 2244(d) | Liability protections |
Governance
| Code | Title |
|---|---|
| CIRCIA-11 | Roles and Responsibilities |
| CIRCIA-20 | Metrics and Reporting |
| CIRCIA-22 | Continuous Monitoring of Rule Updates |
Incident Reporting Requirements
| Code | Title |
|---|---|
| Dir. 1 | Mandatory Incident Reporting |
| Dir. 2 | Expanded Incident Categories |
| Dir. 3 | Incident Report Format |
| Dir. 4 | Point of Contact Designation |
| Sec. 2242(a) | Covered cyber incident report |
| Sec. 2242(b) | Ransom payment report |
| Sec. 2242(c) | Supplemental reports |
| Sec. 2242(d) | Report contents |
| Sec. 2242(e) | Preservation of information |
Information Sharing and Use
| Code | Title |
|---|---|
| Sec. 2243(a) | Sharing with federal agencies |
| Sec. 2243(b) | Privacy and civil liberties protections |
| Sec. 2243(c) | Use limitations |
| Sec. 2243(d) | Anonymisation and aggregation |
Interagency Coordination
| Code | Title |
|---|---|
| Sec. 2246(a) | Cyber Incident Reporting Council |
| Sec. 2246(b) | Harmonisation of reporting requirements |
| Sec. 2246(c) | Voluntary reporting mechanisms |
| Sec. 2246(d) | Threat intelligence sharing |
Legal
| Code | Title |
|---|---|
| CIRCIA-14 | Protections of Reported Information |
| CIRCIA-18 | OFAC Screening for Ransom Payments |
People
| Code | Title |
|---|---|
| CIRCIA-21 | Training and Awareness |
Records
| Code | Title |
|---|---|
| CIRCIA-7 | Records Retention |
Reporting
| Code | Title |
|---|---|
| CIRCIA-13 | Duplicative Reporting Substitution |
| CIRCIA-16 | Notification Channels |
| CIRCIA-3 | 72 Hour Incident Reporting |
| CIRCIA-4 | 24 Hour Ransom Payment Reporting |
| CIRCIA-5 | Supplemental Reporting |
| CIRCIA-6 | Information Required in Reports |
Response
| Code | Title |
|---|---|
| CIRCIA-10 | Incident Response Plan |
| CIRCIA-17 | Coordination with Law Enforcement |
Scope
| Code | Title |
|---|---|
| CIRCIA-1 | Covered Entity Determination |
| CIRCIA-2 | Covered Cyber Incident Definition |
Scope and Definitions
Defines nursing personnel as all categories of persons providing nursing care and services, wherever they work.
| Code | Title |
|---|---|
| 64.2001 | Basis and Purpose |
| 64.2003 | Definitions |
| 64.2004 | Customer Approval Mechanisms |
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
| ILO-C149-01 | Article 1 - Definition of nursing personnel covering all categories providing nursing care and services |
Testing
| Code | Title |
|---|---|
| CIRCIA-15 | Tabletop Exercises |
Third Party
| Code | Title |
|---|---|
| CIRCIA-12 | Third Party Reporting Coordination |
Your Compliance Coverage
If you comply with CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act), you already cover:
FAA Cybersecurity Framework for Aviation
17%
10 controls mapped
Compare →ISO/IEC 27400:2022
15%
9 controls mapped
Compare →ILO Nursing Personnel Convention C149 (1977)
15%
9 controls mapped
Compare →+ 638 more: CSA STAR (Security, Trust, Assurance, and Risk) (15%), NIST AI Risk Management Framework (AI RMF 1.0) (15%)
See all 641 mapped frameworks ↓Maps to 641 other frameworks
Frequently Asked Questions
What is CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act)?
CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) is a compliance framework from United States with 17 domains and 60 controls. The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (Pub.L. 117‑103, Division Y) requires covered critical infrastructure entities to report covered cyber incidents to the Cybersecurity and Infrastructure Security Agency (CISA) within 72 hours of discovery and to report ransom payments within 24 hours. The act establishes reporting requirements, defines covered entities, and mandates the Secretary of Homeland Security to issue guidance and maintain a public database of reported incidents. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) have?
CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) has 60 controls organised across 17 domains. The largest domains are Enforcement and Compliance (11 controls), Incident Reporting Requirements (9 controls), Scope and Definitions (7 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) map to?
CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) maps to 641 other compliance frameworks. The top mapping partners are FAA Cybersecurity Framework for Aviation (17% coverage), ISO/IEC 27400:2022 (15% coverage), ILO Nursing Personnel Convention C149 (1977) (15% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) compliance?
Start your CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 60 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 701 frameworks.
Get Started Free →Free forever — no credit card required