CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act)
What is CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act)?
The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (Pub.L. 117‑103, Division Y) requires covered critical infrastructure entities to report covered cyber incidents to the Cybersecurity and Infrastructure Security Agency (CISA) within 72 hours of discovery and to report ransom payments within 24 hours. It comprises 22 controls organised across 8 domains, and applies in the United States.
How CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) maps to other frameworks
All 22 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 8 domains CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) groups its controls into
Where CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) overlaps with the standards you already hold
What CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) means in your sector
What CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) means for your job
Questions people ask about CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act)
What is CIRCIA?
How many controls does CIRCIA have?
Where does CIRCIA apply?
What frameworks does CIRCIA map to?
How do I get started with CIRCIA compliance?
Query CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) programmatically
CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act), its 22 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) API reference and MCP config →What CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) requires, control by control
Each page carries the requirement text for one CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) control and what an assessor expects to see as evidence.
- CIRCIA-2240 Definitions: Covered Entity, Covered Cyber Incident, Ransom Payment
- CIRCIA-2241 Cyber Incident Review and Threat Indicator Sharing
- CIRCIA-2242A1 72-Hour Covered Cyber Incident Report
- CIRCIA-2242A2 24-Hour Ransom Payment Report
- CIRCIA-2242A3 Supplemental Reports
- CIRCIA-2242A4 Preservation of Data Relevant to the Incident
- CIRCIA-2242C4 Required Contents of a Covered Cyber Incident Report
- CIRCIA-2242C5 Required Contents of a Ransom Payment Report
- CIRCIA-2242E Awareness of Reporting Obligations
- CIRCIA-2244B Response to a CISA Request for Information
How ready are you for CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act)?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.