X-CIRCIA-RPT Informational
Report Covered Cyber Incidents and Ransom Payments to CISA
Official citation: CIRCIA (Pub. L. 117-103)
Class: informational · Severity: high
Statement of the obligation — verify against source
CIRCIA (Pub. L. 117-103)
What it means
CIRCIA creates a government-wide incident-reporting duty for critical-infrastructure entities, separate from any contract clause. If you are a covered entity, a serious incident goes to CISA within 72 hours and any ransom payment within 24 hours — even if you never sign a federal contract.
Required by
- CIRCIA — Pub. L. 117-103
Educational reference only — not legal advice. Consult a qualified assessor or attorney for binding compliance determinations.