Skip to content

Evidence request lists

CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act)

Evidence request list. 22 controls, 22 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

CIRCIA: Cyber Incident Reporting Council (Sec. 2246)

CIRCIA-2246
Cyber Incident Reporting Council Harmonization

The Secretary of Homeland Security leads an intergovernmental Cyber Incident Reporting Council to coordinate, deconflict and harmonize Federal incident-reporting requirements, including those issued through regulations, without creating new regulatory authority.

Artefacts an auditor will ask for
  • Monitoring of harmonised Federal incident-reporting requirements affecting the entity
  • Inventory of overlapping Federal reporting obligations
Where this commonly fails
  • No tracking of evolving Federal reporting harmonisation

CIRCIA: Cyber Incident Review (Sec. 2241)

CIRCIA-2241
Cyber Incident Review and Threat Indicator Sharing

CISA receives, aggregates, analyses and enriches covered cyber incident and ransom payment reports, then rapidly disseminates anonymized actionable cyber threat indicators and defensive measures. Reporting entities interface with this review function and benefit from the shared indicators.

Artefacts an auditor will ask for
  • Capability to receive and action CISA-shared cyber threat indicators and defensive measures
  • Procedure linking inbound threat indicators to detection/response
Where this commonly fails
  • No process to consume CISA threat-indicator products

CIRCIA: Definitions and Scope (Sec. 2240)

CIRCIA-2240
Definitions: Covered Entity, Covered Cyber Incident, Ransom Payment

Defines the operative scope: a covered entity is an entity in a critical infrastructure sector (PPD-21) meeting the criteria set by the CISA final rule; a covered cyber incident is a substantial cyber incident (substantial loss of confidentiality, integrity or availability; serious impact on the safety and resiliency of operational systems; disruption of business/industrial operations; or unauthorized access enabled by a third-party/supply-chain or cloud/MSP compromise); a ransom payment is the transfer of money or other property as the result of a ransomware attack.

Artefacts an auditor will ask for
  • Covered-entity determination record mapped to the CISA final rule criteria
  • Incident-severity classification standard distinguishing covered vs non-covered incidents
  • Critical-infrastructure sector identification
Where this commonly fails
  • No assessment of whether the organisation is a covered entity
  • Severity criteria not aligned to the statutory covered-cyber-incident definition

CIRCIA: Enforcement and Noncompliance (Sec. 2244)

CIRCIA-2244b
Response to a CISA Request for Information

If CISA has reason to believe a covered entity experienced a covered cyber incident or made a ransom payment but failed to report, it may request additional information; the entity should respond to confirm whether a reportable event occurred.

Artefacts an auditor will ask for
  • Procedure to receive, triage and respond to a CISA request for information
  • Tracked, timely response with supporting records
Where this commonly fails
  • No process to handle a CISA RFI
  • Inadequate or late RFI response triggering escalation
CIRCIA-2244c
Subpoena and Civil Enforcement for Noncompliance

If, 72 hours after a CISA request, the entity provides no or an inadequate response, CISA may issue a non-delegable, cryptographically authenticated subpoena; failure to comply may be referred to the Attorney General for a civil action in district court and punished as contempt.

Artefacts an auditor will ask for
  • Legal escalation playbook for a CISA subpoena
  • Controls ensuring timely RFI response to avoid subpoena/civil action
Where this commonly fails
  • No legal escalation path for CISA enforcement
  • Ignored RFI escalating to subpoena and AG referral
CIRCIA-2244d
Referral to the Attorney General

Where information obtained through a subpoena indicates the facts may constitute grounds for a regulatory enforcement action or criminal prosecution, CISA may provide that information to the Attorney General or the appropriate Federal regulator, who may use it accordingly.

Artefacts an auditor will ask for
  • Awareness that subpoena-compelled information loses the voluntary-reporting protections
  • Legal review of enforcement exposure
Where this commonly fails
  • Assuming all interactions with CISA are protected from enforcement use
CIRCIA-2244f
Exclusion of State, Local, Tribal and Territorial Governments

The enforcement authorities of Section 2244 do not apply to a State, local, Tribal or territorial government entity.

Artefacts an auditor will ask for
  • Applicability determination for government entities
Where this commonly fails
  • Government entity assumes enforcement applies / does not apply without basis

CIRCIA: Federal Sharing of Reports (Sec. 2247)

CIRCIA-2247
Federal Sharing of Incident Reports

Any Federal agency that receives a report of a cyber incident, including a ransomware attack, must provide it to CISA as soon as possible and not later than 24 hours after receipt (unless a shorter period is agreed), supporting harmonized Federal sharing.

Artefacts an auditor will ask for
  • Awareness that reports made to other Federal agencies may be shared with CISA
  • Tracking of which agency receives a given report
Where this commonly fails
  • Assuming a report to another agency is not shared with CISA

CIRCIA: Information Protections (Sec. 2245)

CIRCIA-2245a
Authorized Use, Retention and Digital Security of Reports

Reported information may be disclosed, retained and used only for defined purposes (cybersecurity, identifying a cyber threat or vulnerability, mitigating specific threats of harm, or prosecuting an offence arising from a reported incident); reports must be stored and protected at a minimum at the FIPS-199 moderate baseline and personal information protected.

Artefacts an auditor will ask for
  • Handling/storage controls for CISA-provided information at FIPS-199 moderate minimum
  • Purpose-limitation controls on reported information
Where this commonly fails
  • Reported information used beyond authorised purposes
  • Storage below the FIPS-199 moderate baseline
CIRCIA-2245a5
Prohibition on Use of Reported Information in Regulatory Actions

A Federal, State, local or Tribal government may not use information about a covered cyber incident or ransom payment obtained solely through direct reporting to CISA to regulate (including by enforcement) the reporting entity, unless that government expressly allows CISA reports to meet its regulatory reporting obligations.

Artefacts an auditor will ask for
  • Awareness that direct CISA reporting carries regulatory-use protection
  • Assessment of which regulators accept CISA reports for their obligations
Where this commonly fails
  • Failure to rely on the regulatory-use protection
  • Duplicating reports unnecessarily and forfeiting protection
CIRCIA-2245b
Protections for Reporting Entities (FOIA, Privilege, Proprietary)

Submitted reports are treated as the commercial, financial and proprietary information of the entity when so designated, are exempt from FOIA and analogous State/Tribal/local disclosure laws, do not waive any applicable privilege or trade-secret protection, and are not subject to ex parte communication rules.

Artefacts an auditor will ask for
  • Designation of reports as commercial/proprietary at submission
  • Reliance on the FOIA and privilege-preservation protections
Where this commonly fails
  • Reports not designated proprietary
  • Assuming reports are publicly disclosable
CIRCIA-2245c
Liability Protections and Evidentiary Restrictions

No cause of action lies for submitting a conforming report; reports and records created solely to prepare or submit a report may not be received in evidence, subjected to discovery, or otherwise used in any proceeding (except an Attorney General civil action under Section 2244).

Artefacts an auditor will ask for
  • Segregation of materials created solely for the purpose of reporting
  • Legal-privilege handling to preserve the evidentiary and liability protections
Where this commonly fails
  • Mixing report-only material with operational records, weakening the protection

CIRCIA: Required Reporting (Sec. 2242)

CIRCIA-2242a1
72-Hour Covered Cyber Incident Report

A covered entity that experiences a covered cyber incident must report it to CISA not later than 72 hours after the entity reasonably believes the incident has occurred.

Artefacts an auditor will ask for
  • Documented 72-hour reporting procedure with a defined reasonable-belief trigger
  • Incident detection and triage timestamps
  • CISA report submission confirmation/receipt
Where this commonly fails
  • No 72-hour clock or unclear reasonable-belief trigger
  • Reports submitted late or never to CISA
CIRCIA-2242a2
24-Hour Ransom Payment Report

A covered entity that makes a ransom payment as the result of a ransomware attack must report the payment to CISA not later than 24 hours after the payment is made, even if the attack is not a covered cyber incident.

Artefacts an auditor will ask for
  • Ransom-payment authorisation and reporting workflow with a 24-hour deadline
  • OFAC sanctions screening prior to payment
  • Record of payment-report submission
Where this commonly fails
  • No 24-hour ransom-payment reporting path
  • Payment made without sanctions screening or reporting
CIRCIA-2242a3
Supplemental Reports

A covered entity must promptly submit an update or supplement to a previously submitted covered cyber incident report when substantial new or different information becomes available, or if it makes a ransom payment after the initial report, until it notifies CISA the incident has concluded and is fully mitigated and resolved.

Artefacts an auditor will ask for
  • Supplemental-report procedure tied to the incident lifecycle
  • Log of supplemental submissions and the closure notification
Where this commonly fails
  • No mechanism to file supplemental updates
  • Incident closed without final notification to CISA
CIRCIA-2242a4
Preservation of Data Relevant to the Incident

Any covered entity subject to the reporting requirements must preserve data relevant to the covered cyber incident or ransom payment in accordance with the procedures established in the CISA final rule.

Artefacts an auditor will ask for
  • Data-preservation / legal-hold procedure for incident-relevant data
  • Retention of logs, forensic images and ransom-payment records for the prescribed period
Where this commonly fails
  • No preservation hold on incident data
  • Relevant logs overwritten or rotated out
CIRCIA-2242a5
Reporting Exceptions: Substantially Similar Reporting and DNS

Reporting is exempted where the entity is required by law/regulation/contract to report substantially similar information to another Federal agency within a substantially similar timeframe once a CIRCIA Agreement and sharing mechanism is in place; functions governed by DNS multistakeholder bodies (e.g. ICANN/IANA) are also excluded.

Artefacts an auditor will ask for
  • Mapping of overlapping Federal reporting obligations to assess the substantially-similar exemption
  • Record of any applicable CIRCIA Agreement reliance
Where this commonly fails
  • Exemption assumed without a CIRCIA Agreement in place
  • Overlapping Federal obligations not mapped
CIRCIA-2242c4
Required Contents of a Covered Cyber Incident Report

The report must include, to the extent applicable and available: a description of the incident and affected systems/networks/devices; the nature of unauthorized access and impact on operations; the estimated date range; vulnerabilities exploited and security defenses in place plus tactics/techniques/procedures; identifying/contact information for the responsible actor; categories of information accessed; and the covered entity identity and contact information.

Artefacts an auditor will ask for
  • Covered cyber incident report template covering every mandated content element
  • Evidence capture process (affected assets, TTPs, actor indicators, data categories)
Where this commonly fails
  • Report template missing mandated elements
  • Incomplete incident characterisation
CIRCIA-2242c5
Required Contents of a Ransom Payment Report

The ransom payment report must include, to the extent applicable and available: a description of the ransomware attack including estimated date range; vulnerabilities/TTPs; actor identifying/contact information; the covered entity identity and contact; the date of payment; the ransom demand including virtual-currency type; payment instructions including the virtual-currency or physical address; and the amount paid.

Artefacts an auditor will ask for
  • Ransom-payment report template capturing payment date/amount/instructions/demand and virtual-currency addresses
  • Procedure to capture attacker and payment-channel detail
Where this commonly fails
  • Payment details not captured for reporting
  • Virtual-currency address/demand not recorded
CIRCIA-2242d
Third-Party Report Submission

A covered entity may use a third party (incident response firm, insurer, service provider, ISAO or law firm) to submit a required report, but this does not relieve the entity of its duty to comply; a third party that knowingly makes a ransom payment on the entity's behalf must advise the entity of its reporting responsibilities.

Artefacts an auditor will ask for
  • Third-party / incident-response engagement terms specifying who submits the CIRCIA report
  • Retained accountability for report completeness and timeliness
Where this commonly fails
  • Reliance on a third party with no verification the report was filed
  • Duty-to-report responsibility unclear in contracts
CIRCIA-2242e
Awareness of Reporting Obligations

CISA conducts an outreach and education campaign on the reporting requirements, protections and mechanisms; covered entities should maintain awareness of the final rule and designate how reports are submitted.

Artefacts an auditor will ask for
  • Designated CIRCIA reporting point of contact
  • Internal awareness/playbook reflecting the final-rule reporting mechanism
Where this commonly fails
  • No owner for CIRCIA reporting
  • Staff unaware of reporting obligations

CIRCIA: Voluntary Reporting (Sec. 2243)

CIRCIA-2243
Voluntary Reporting of Other Cyber Incidents

Entities may voluntarily report cyber incidents or ransom payments that are not required, and may include additional information in required reports, to enhance situational awareness; the Section 2245 protections apply to voluntary reports in the same manner.

Artefacts an auditor will ask for
  • Policy distinguishing mandatory from voluntary reporting
  • Awareness that voluntary reports carry the same statutory protections
Where this commonly fails
  • No use of voluntary reporting for sub-threshold incidents
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) framework page.