# Cyber Incident Reporting for Critical Infrastructure Act of 2022
Short Answer
CIRCIA is the 2022 statute that directs CISA to create mandatory cyber-incident and ransom-payment reporting rules for covered critical-infrastructure entities. It matters to contractors because some government contractors operate in critical-infrastructure sectors or support covered entities, but the statute’s reporting duties depend on the implementing rule and should not be described as fully operative final obligations unless the final rule has issued.
Why this matters for government contractors
CIRCIA is not a replacement for DFARS incident reporting, FedRAMP reporting, HIPAA breach notification, state breach notices, or agency-specific rules. It is a separate federal critical-infrastructure reporting framework. A contractor may care because it operates critical infrastructure, supports a covered entity, provides managed services to a covered entity, pays or facilitates ransom, or has contract duties requiring customer notice and cooperation.
What the law does
CIRCIA requires covered entities to report covered cyber incidents to CISA and to report ransom payments. The statute sets key timing concepts: covered cyber incidents are associated with a 72-hour reporting deadline and ransom payments with a 24-hour reporting deadline after payment. CISA is required to implement the details through rulemaking, including who is covered, what incidents qualify, what information must be included, and how supplemental reports work.
How it reaches contractors
CIRCIA reaches contractors by sector and function, not simply because a company has a federal contract. A defense contractor, health contractor, transportation contractor, energy contractor, managed service provider, cloud provider, or other supplier may become relevant if it falls into a covered critical-infrastructure category or supports an entity that does. Prime/subcontract terms may require notice to the customer even when the contractor itself is not the reporting entity.
Procurement and cybersecurity significance
CIRCIA should influence incident-response planning. Contractors should not build a single report path and assume it covers all obligations. A significant incident may trigger DFARS 252.204-7012, agency clauses, FedRAMP, sector rules, state breach laws, contract notice provisions, law-enforcement reporting, insurance notice, and eventually CIRCIA. The right approach is a reporting matrix that identifies each obligation, deadline, recipient, and evidence requirement.
Related requirements
CIRCIA relates to DFARS 252.204-7012, FedRAMP, HIPAA/HITECH, GLBA, TSA/SSI rules, state breach laws, and critical-infrastructure security directives. It should appear near incident-reporting and critical-infrastructure results, not as a CUI safeguarding control.
What contractors should do
- Determine whether the organization operates in a critical-infrastructure sector or supports covered entities.
- Track CISA rulemaking and update reporting procedures when the final rule becomes effective.
- Build an incident reporting matrix covering DFARS, CIRCIA, agency, FedRAMP, state, sector, customer, insurance, and law-enforcement paths.
- Preserve forensic evidence and reporting decision records.
- Include customer-notice and subcontractor-notice obligations in incident playbooks.
- Avoid stating that proposed regulatory details are final until verified.
Current status
Enacted statute. Implementing rulemaking remains the operative status item unless a final rule has been verified. As of the source review for this package, the 2024 NPRM and 2026 CISA supplemental engagement notices indicate rulemaking activity; final-rule status must be checked immediately before publication.
Primary citations
- 6 U.S.C. §§ 681–681g.
- Cyber Incident Reporting for Critical Infrastructure Act of 2022, Pub. L. 117-103.
- 89 Fed. Reg. 23644 (Apr. 4, 2024) (NPRM).
- Final rule status: Pending as of June 2026. CISA published an NPRM at 89 Fed. Reg. 23644 (Apr. 4, 2024), proposing a 72-hour covered-incident reporting clock and a 24-hour ransom-payment reporting clock. No final rule has been issued; reporting obligations become operative only upon finalization of the implementing rule.
---
Source type: federal_statute. Implementation status: enacted_rulemaking_pending.