CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act)
Evidence request list. 22 controls, 22 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
CIRCIA: Cyber Incident Reporting Council (Sec. 2246)
The Secretary of Homeland Security leads an intergovernmental Cyber Incident Reporting Council to coordinate, deconflict and harmonize Federal incident-reporting requirements, including those issued through regulations, without creating new regulatory authority.
- Monitoring of harmonised Federal incident-reporting requirements affecting the entity
- Inventory of overlapping Federal reporting obligations
- No tracking of evolving Federal reporting harmonisation
CIRCIA: Cyber Incident Review (Sec. 2241)
CISA receives, aggregates, analyses and enriches covered cyber incident and ransom payment reports, then rapidly disseminates anonymized actionable cyber threat indicators and defensive measures. Reporting entities interface with this review function and benefit from the shared indicators.
- Capability to receive and action CISA-shared cyber threat indicators and defensive measures
- Procedure linking inbound threat indicators to detection/response
- No process to consume CISA threat-indicator products
CIRCIA: Definitions and Scope (Sec. 2240)
Defines the operative scope: a covered entity is an entity in a critical infrastructure sector (PPD-21) meeting the criteria set by the CISA final rule; a covered cyber incident is a substantial cyber incident (substantial loss of confidentiality, integrity or availability; serious impact on the safety and resiliency of operational systems; disruption of business/industrial operations; or unauthorized access enabled by a third-party/supply-chain or cloud/MSP compromise); a ransom payment is the transfer of money or other property as the result of a ransomware attack.
- Covered-entity determination record mapped to the CISA final rule criteria
- Incident-severity classification standard distinguishing covered vs non-covered incidents
- Critical-infrastructure sector identification
- No assessment of whether the organisation is a covered entity
- Severity criteria not aligned to the statutory covered-cyber-incident definition
CIRCIA: Enforcement and Noncompliance (Sec. 2244)
If CISA has reason to believe a covered entity experienced a covered cyber incident or made a ransom payment but failed to report, it may request additional information; the entity should respond to confirm whether a reportable event occurred.
- Procedure to receive, triage and respond to a CISA request for information
- Tracked, timely response with supporting records
- No process to handle a CISA RFI
- Inadequate or late RFI response triggering escalation
If, 72 hours after a CISA request, the entity provides no or an inadequate response, CISA may issue a non-delegable, cryptographically authenticated subpoena; failure to comply may be referred to the Attorney General for a civil action in district court and punished as contempt.
- Legal escalation playbook for a CISA subpoena
- Controls ensuring timely RFI response to avoid subpoena/civil action
- No legal escalation path for CISA enforcement
- Ignored RFI escalating to subpoena and AG referral
Where information obtained through a subpoena indicates the facts may constitute grounds for a regulatory enforcement action or criminal prosecution, CISA may provide that information to the Attorney General or the appropriate Federal regulator, who may use it accordingly.
- Awareness that subpoena-compelled information loses the voluntary-reporting protections
- Legal review of enforcement exposure
- Assuming all interactions with CISA are protected from enforcement use
The enforcement authorities of Section 2244 do not apply to a State, local, Tribal or territorial government entity.
- Applicability determination for government entities
- Government entity assumes enforcement applies / does not apply without basis
CIRCIA: Federal Sharing of Reports (Sec. 2247)
Any Federal agency that receives a report of a cyber incident, including a ransomware attack, must provide it to CISA as soon as possible and not later than 24 hours after receipt (unless a shorter period is agreed), supporting harmonized Federal sharing.
- Awareness that reports made to other Federal agencies may be shared with CISA
- Tracking of which agency receives a given report
- Assuming a report to another agency is not shared with CISA
CIRCIA: Information Protections (Sec. 2245)
Reported information may be disclosed, retained and used only for defined purposes (cybersecurity, identifying a cyber threat or vulnerability, mitigating specific threats of harm, or prosecuting an offence arising from a reported incident); reports must be stored and protected at a minimum at the FIPS-199 moderate baseline and personal information protected.
- Handling/storage controls for CISA-provided information at FIPS-199 moderate minimum
- Purpose-limitation controls on reported information
- Reported information used beyond authorised purposes
- Storage below the FIPS-199 moderate baseline
A Federal, State, local or Tribal government may not use information about a covered cyber incident or ransom payment obtained solely through direct reporting to CISA to regulate (including by enforcement) the reporting entity, unless that government expressly allows CISA reports to meet its regulatory reporting obligations.
- Awareness that direct CISA reporting carries regulatory-use protection
- Assessment of which regulators accept CISA reports for their obligations
- Failure to rely on the regulatory-use protection
- Duplicating reports unnecessarily and forfeiting protection
Submitted reports are treated as the commercial, financial and proprietary information of the entity when so designated, are exempt from FOIA and analogous State/Tribal/local disclosure laws, do not waive any applicable privilege or trade-secret protection, and are not subject to ex parte communication rules.
- Designation of reports as commercial/proprietary at submission
- Reliance on the FOIA and privilege-preservation protections
- Reports not designated proprietary
- Assuming reports are publicly disclosable
No cause of action lies for submitting a conforming report; reports and records created solely to prepare or submit a report may not be received in evidence, subjected to discovery, or otherwise used in any proceeding (except an Attorney General civil action under Section 2244).
- Segregation of materials created solely for the purpose of reporting
- Legal-privilege handling to preserve the evidentiary and liability protections
- Mixing report-only material with operational records, weakening the protection
CIRCIA: Required Reporting (Sec. 2242)
A covered entity that experiences a covered cyber incident must report it to CISA not later than 72 hours after the entity reasonably believes the incident has occurred.
- Documented 72-hour reporting procedure with a defined reasonable-belief trigger
- Incident detection and triage timestamps
- CISA report submission confirmation/receipt
- No 72-hour clock or unclear reasonable-belief trigger
- Reports submitted late or never to CISA
A covered entity that makes a ransom payment as the result of a ransomware attack must report the payment to CISA not later than 24 hours after the payment is made, even if the attack is not a covered cyber incident.
- Ransom-payment authorisation and reporting workflow with a 24-hour deadline
- OFAC sanctions screening prior to payment
- Record of payment-report submission
- No 24-hour ransom-payment reporting path
- Payment made without sanctions screening or reporting
A covered entity must promptly submit an update or supplement to a previously submitted covered cyber incident report when substantial new or different information becomes available, or if it makes a ransom payment after the initial report, until it notifies CISA the incident has concluded and is fully mitigated and resolved.
- Supplemental-report procedure tied to the incident lifecycle
- Log of supplemental submissions and the closure notification
- No mechanism to file supplemental updates
- Incident closed without final notification to CISA
Any covered entity subject to the reporting requirements must preserve data relevant to the covered cyber incident or ransom payment in accordance with the procedures established in the CISA final rule.
- Data-preservation / legal-hold procedure for incident-relevant data
- Retention of logs, forensic images and ransom-payment records for the prescribed period
- No preservation hold on incident data
- Relevant logs overwritten or rotated out
Reporting is exempted where the entity is required by law/regulation/contract to report substantially similar information to another Federal agency within a substantially similar timeframe once a CIRCIA Agreement and sharing mechanism is in place; functions governed by DNS multistakeholder bodies (e.g. ICANN/IANA) are also excluded.
- Mapping of overlapping Federal reporting obligations to assess the substantially-similar exemption
- Record of any applicable CIRCIA Agreement reliance
- Exemption assumed without a CIRCIA Agreement in place
- Overlapping Federal obligations not mapped
The report must include, to the extent applicable and available: a description of the incident and affected systems/networks/devices; the nature of unauthorized access and impact on operations; the estimated date range; vulnerabilities exploited and security defenses in place plus tactics/techniques/procedures; identifying/contact information for the responsible actor; categories of information accessed; and the covered entity identity and contact information.
- Covered cyber incident report template covering every mandated content element
- Evidence capture process (affected assets, TTPs, actor indicators, data categories)
- Report template missing mandated elements
- Incomplete incident characterisation
The ransom payment report must include, to the extent applicable and available: a description of the ransomware attack including estimated date range; vulnerabilities/TTPs; actor identifying/contact information; the covered entity identity and contact; the date of payment; the ransom demand including virtual-currency type; payment instructions including the virtual-currency or physical address; and the amount paid.
- Ransom-payment report template capturing payment date/amount/instructions/demand and virtual-currency addresses
- Procedure to capture attacker and payment-channel detail
- Payment details not captured for reporting
- Virtual-currency address/demand not recorded
A covered entity may use a third party (incident response firm, insurer, service provider, ISAO or law firm) to submit a required report, but this does not relieve the entity of its duty to comply; a third party that knowingly makes a ransom payment on the entity's behalf must advise the entity of its reporting responsibilities.
- Third-party / incident-response engagement terms specifying who submits the CIRCIA report
- Retained accountability for report completeness and timeliness
- Reliance on a third party with no verification the report was filed
- Duty-to-report responsibility unclear in contracts
CISA conducts an outreach and education campaign on the reporting requirements, protections and mechanisms; covered entities should maintain awareness of the final rule and designate how reports are submitted.
- Designated CIRCIA reporting point of contact
- Internal awareness/playbook reflecting the final-rule reporting mechanism
- No owner for CIRCIA reporting
- Staff unaware of reporting obligations
CIRCIA: Voluntary Reporting (Sec. 2243)
Entities may voluntarily report cyber incidents or ransom payments that are not required, and may include additional information in required reports, to enhance situational awareness; the Section 2245 protections apply to voluntary reports in the same manner.
- Policy distinguishing mandatory from voluntary reporting
- Awareness that voluntary reports carry the same statutory protections
- No use of voluntary reporting for sub-threshold incidents
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) framework page.