RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The incident desk · 100 retrospective records ↗

The incident desk / Policy & law

Policy & law / From the archive · 15 March 2022 event · prepared 16 September 2026

A 2022 law created reporting duties still waiting on a final rule

CIRCIA set 72-hour incident and 24-hour ransom-payment reporting deadlines that do not take effect until CISA finalizes its rule.

Visual published with the cited source for this record: A 2022 law created reporting duties still waiting on a final rule
Visual published with the cited source, shown for identification of the record. Credit: cisa.gov · source page ↗ Rights: owner-review-pending.

What the document says

On 15 March 2022, the Cyber Incident Reporting for Critical Infrastructure Act became law as part of the Consolidated Appropriations Act, 2022, according to its legislative record. The statute requires covered entities in critical infrastructure sectors to report a covered cyber incident to CISA within 72 hours of reasonably believing it occurred, and to report a ransom payment within 24 hours of making it. Those duties, however, do not take effect on their own; the law directed CISA to write implementing regulations defining exactly who counts as a covered entity and what counts as a covered incident. CISA published its proposed rule on 4 April 2024, describing an estimated 316,000 affected entities and roughly 210,000 reports over the rule's ten-year analysis period, at an estimated cost near $2.6 billion. As of this writing, CISA's own topic page, retrieved 16 September 2026, states the agency is still reviewing comments and working toward a final rule; the reporting deadlines are not yet mandatory.

Confidence and limits

The enactment date and statutory deadlines are established by the public law text and the legislative record. The rule's cost and volume estimates are CISA's own projections in a proposed, not final, rule, and are properly read as the agency's modeling rather than a measured outcome. This article does not predict when a final rule will publish or what it will ultimately require, since CISA had not finalized it as of the date this was prepared.

Why it mattered

CIRCIA was written to close a specific gap Congress identified: no single federal agency had visibility into cyberattacks against critical infrastructure across sectors, because the dozens of existing reporting rules were scattered across regulators with different deadlines, definitions and recipients. Whatever the final rule requires, the act's structure, a statute that creates duties contingent on a not-yet-final regulation, means the practical question for any organization is not whether CIRCIA applies in principle but whether, and on what date, the specific rule defining covered entities takes effect.

Defensive takeaway

Do not assume CIRCIA's 72-hour and 24-hour deadlines apply to your organization today; instead, track the final rule's publication date and, once it exists, confirm your incident response plan's reporting timeline against the definitions it uses for covered entity and covered incident.

  • Would your organization be classified as a covered entity under the definitions CISA has proposed for your sector?
  • Does your incident response plan already assume reporting timelines faster than what any current regulation requires of you?
  • Who owns tracking the CIRCIA rulemaking's status so the deadline is not missed when it becomes final?

An enacted statute and an effective regulation are not the same thing, and the gap between them, now measured in years rather than months, is itself the most important fact for a defender trying to plan around this law.

Defensive takeaway

Do not assume CIRCIA's deadlines apply to you yet; track the final rule's publication and confirm your incident response plan's reporting timeline against its eventual definitions.

The enactment date and statutory deadlines are established by the public law text; the cost and volume figures are CISA's own projections in a proposed, not final, rule, and the reporting deadlines are not yet mandatory as of the date this was prepared.

Sources & reading trail

Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) ↗

CISA's living summary of CIRCIA's reporting deadlines and the current, not-yet-final status of the implementing rule, as retrieved 16 September 2026.

government-primary · Source published: Not established · Retrieved: 16 September 2026

Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements ↗

The proposed rule's text, confirming CIRCIA's 15 March 2022 enactment as Public Law 117-103 and setting out the proposed reporting deadlines, covered-entity definitions and cost estimates.

government-primary · Source published: 4 April 2024 · Retrieved: 16 September 2026

H.R.2471 - Consolidated Appropriations Act, 2022 ↗

Confirms CIRCIA's enactment on 15 March 2022 as part of the Consolidated Appropriations Act, 2022, Public Law 117-103.

government-primary · Source published: 15 March 2022 · Retrieved: 16 September 2026

Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.