Standards & regulatory

CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act)

CIRCIA is a 2022 U.S. law that will require covered critical infrastructure entities to report substantial cyber incidents to CISA within 72 hours, and ransomware payments within 24 hours. The law itself is already in effect, but its specific reporting obligations don't take effect until CISA finalizes the implementing regulation (see the CIRCIA reporting rule), so as of this writing, covered entities aren't yet required to actually file these reports.