CIRCIA’s Coming: Is Your Business Ready for Mandatory Cyber Reporting?

09:03:2026

In March 2022, the Cyber Incident Reporting for Critical Infrastructure Act(opens in new tab) (CIRCIA) was signed into law, creating the federal government’s first comprehensive, cross-sector framework for mandatory cyber incident reporting. 

The Cybersecurity and Infrastructure Security Agency (CISA) is finalizing regulations that will soon require covered entities (estimated at over 300,000 organizations across the U.S.) to report substantial cyber incidents and ransomware payments within strict deadlines. With the final rule pending, proactive compliance planning is essential for businesses operating in critical sectors.

What Qualifies as a “Covered Cyber Incident” Under CIRCIA?

A “covered cyber incident” is defined broadly as any occurrence that results in one of the following outcomes(opens in new tab):

  • Substantial loss of confidentiality, integrity, or availability of an information system or network
  • Serious impact on the safety or resilience of operational systems and processes
  • Disruption of an entity’s ability to deliver goods or services
  • Unauthorized access facilitated through supply chain compromise, including breaches at a cloud service provider, managed service provider, or other third‑party vendor

Which Entities Must Report? (Defining ‘Critical Infrastructure’)

CIRCIA applies to covered entities. These are organizations that operate in one of the 16 critical infrastructure sectors identified in Presidential Policy Directive 21(opens in new tab):

  1. Chemical
  2. Commercial Facilities
  3. Communications
  4. Critical Manufacturing
  5. Dams
  6. Defense Industrial Base
  7. Emergency Services
  8. Energy
  9. Financial Services
  10. Food and Agriculture
  11. Government Facilities
  12. Healthcare and Public Health
  13. Information Technology
  14. Nuclear Reactors, Materials, and Waste
  15. Transportation Systems
  16. Water and Wastewater Systems
The Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) was signed into law, creating the federal government’s first comprehensive, cross-sector framework for mandatory cyber incident reporting. 

In 2026, water and wastewater facilities in at least a dozen U.S. states have succumbed to cyberattacks.

To determine coverage, CISA uses a two‑track test. Track one is size‑based: any entity operating in a critical infrastructure sector that exceeds the Small Business Administration’s size standards is a covered entity. Those thresholds vary by industry, generally ranging from 100 to 1,500 employees or 2.25 million to 47 million in annual revenue. Track two comprises sector‑specific criteria that can capture entities regardless of size because of the outsized risk their disruption would pose.

Many organizations that have never considered themselves “critical infrastructure” may still fall within these broad definitions.

What Specific Data Must the Report Contain?

Under the proposed rule, covered entities must provide CISA with a wide range of technical and operational details, including:

  • Incident timeline: date, time, and duration of the incident
  • Impacted systems: affected networks, devices, and categories of impacted information
  • Technical indicators: indicators of compromise, samples of malicious software, and details of any security controls in place at the time of the incident
  • Response actions: steps taken to mitigate the incident and prevent recurrence
  • Ransomware details: for ransom payments, the amount, date, and method of payment

Additionally, when an entity reasonably believes a covered incident has occurred, it must preserve all relevant data (including logs) for two years. Supplemental reports are required when substantial new or different information becomes available.

SealingTech's AegisEdge MicroServers

SealingTech’s AegisEdge MicroServers protect OT and ICS environments, including critical infrastructure.

At SealingTech, we design and deploy purpose‑built cybersecurity solutions for operational technology (OT) and industrial control systems (ICS) environments like yours. From critical manufacturing to energy and water systems, our AegisEdge MicroServers(opens in new tab) help protect the assets that keep our communities safe. 

Contact SealingTech today(opens in new tab) to learn how we can help you build cyber resilience and prepare for CIRCIA compliance.

CIRCIA Compliance FAQs

What Are The Exact Reporting Deadlines?

Once the final rule takes effect, covered entities must report a “covered cyber incident” to CISA within 72 hours of reasonably believing the incident has occurred. Covered entities are required to report ransomware payments within 24 hours of making the payment. These timelines are statutory and not expected to change in the final rule. For updates, see CISA’s CIRCIA(opens in new tab) page.

What If I’m Not Sure Whether My Entity Is “Critical Infrastructure” Yet?

If you are uncertain, CISA recommends reviewing available guidance (including publicly available sector plans for each critical infrastructure sector) to determine whether you are a covered entity. You may also begin with a simple self‑assessment: identify whether your organization operates in any of the 16 critical sectors, then assess whether you exceed the relevant size thresholds or meet sector‑specific criteria. When in doubt, consult legal counsel or a cybersecurity partner for clarity.

What Happens If I Fail to Report?

Penalties for non‑compliance are severe. False statements or representations can result in fines and imprisonment of up to five years, or eight years if the offense involves international or domestic terrorism. CISA also has the authority to issue subpoenas, refer matters to the Attorney General for civil action, and pursue punitive measures such as contempt of court, suspension, or disbarment.

Related Articles

Understanding Zero Trust Network Access (ZTNA)

Zero Trust Network Access replaces implicit network trust with continuous, identity-based verification of every access request. Rather than placing a user on the network, it grants application-level access after confirming…

Learn More

National Infrastructure Priority Status: Benefit, Impact, and Why It Matters

The United States is in the midst of a generational investment in the nation’s infrastructure. This modernization effort (spanning energy, transportation, water, and digital systems) arrives alongside an era of…

Learn More

Autonomous AI Attacks: How Machine-Driven Threats Plan, Execute, and Adapt

Cybersecurity is entering a new phase characterized by autonomous AI attacks, where operations are driven by AI systems rather than direct human control. These systems operate at speeds and scales…

Learn More

Could your news use a jolt?

Find out what’s happening across the cyber landscape every month with The Lightning Report. 

Be privy to the latest trends and evolutions, along with strategies to safeguard your government agency or enterprise from cyber threats. Subscribe now.