Skip to main content
Back to results
X-CIRCIA-RPT Informational

Report Covered Cyber Incidents and Ransom Payments to CISA

Official citation: CIRCIA (Pub. L. 117-103)

Class: informational · Severity: high

Statement of the obligation — verify against source

CIRCIA (Pub. L. 117-103)

What it means

CIRCIA creates a government-wide incident-reporting duty for critical-infrastructure entities, separate from any contract clause. If you are a covered entity, a serious incident goes to CISA within 72 hours and any ransom payment within 24 hours — even if you never sign a federal contract.

Required by

  • CIRCIAPub. L. 117-103

Educational reference only — not legal advice. Consult a qualified assessor or attorney for binding compliance determinations.