In part one, we discussed how covered entity status gets determined under the proposed CIRCIA rule, including the sector criteria that reach beyond the sectors they name. Now we’ll cover what follows if you land inside that scope.
The CIRCIA reporting requirements break into four parts: what counts as a reportable incident, how long you have, what the report has to contain, and what you keep afterward.
Sourcing and caveats carry over from part one: everything here comes from the April 2024 NPRM and CISA’s overview of it, the final rule may differ, and we aren’t lawyers. CISA received substantial comment on the incident definition specifically, and on how much information affected organizations would be required to provide, so expect movement there.
What Counts as a Reportable Incident
A covered entity must report a Covered Cyber Incident, defined as a Substantial Cyber Incident experienced by a covered entity. The proposed definition of Substantial Cyber Incident is an incident leading to any one of four outcomes:
- Substantial loss of confidentiality, integrity, or availability of an information system or network
- A serious impact on the safety and resiliency of operational systems and processes
- Disruption of the ability to engage in business or industrial operations, or to deliver goods or services
- Unauthorized access to a system, network, or nonpublic information within it, facilitated through or caused by a compromise of a cloud service provider, managed service provider, or other third-party data hosting provider, or by a supply chain compromise
The second and third reach an OT environment directly, and neither requires data loss to trigger.
CISA also proposes that for the first three prongs, the cause is generally irrelevant. An incident producing one of those consequences is reportable regardless of how it happened.
Three exclusions are proposed. Lawfully authorized activity by a US or SLTT government entity. Events perpetrated in good faith in response to a specific request by the system owner or operator, which covers authorized testing. And threats of disruption used as extortion, as distinct from actual disruption.
The Clocks
72 hours to report a Covered Cyber Incident, running from the point at which the covered entity reasonably believes the incident occurred.
24 hours to report a ransom payment, running from disbursement, whether the entity made the payment itself or another party made it on its behalf.
Promptly for supplemental reports, required when substantial new or different information about a previously reported incident becomes available, or when a ransom payment follows an incident already reported.
The trigger is the part that you’ll need to plan around. For Covered Cyber Incidents, the proposed CIRCIA reporting requirements give covered entities 72 hours from reasonable belief, not final confirmation. CISA’s commentary describes this as a much lower threshold than confirmation, and notes an entity may need to conduct a preliminary analysis to reach it. In practice that means the 72 hours are spent producing the report, not deciding whether something happened.
Decide now which role makes that call and at what point. A judgment call with a federal clock attached to it should not be made for the first time under pressure.
What CIRCIA Reporting Requirements Ask for in a Report
CISA proposes that Covered Cyber Incident Reports include:
- Identifying and contact information for the entity, and for any third party submitting on its behalf
- A description of the incident, including impacts, covering affected networks, devices, and systems, and impact on operations
- The vulnerabilities exploited
- The tactics, techniques, and procedures used
- Indicators of compromise
- Information related to the identity of the perpetrator
- Mitigation and response activities
Ransom Payment Reports carry the same core content plus the ransom demand and payment details, including instructions, asset or currency type, and amount.
Reports are submitted through a web-based form, dynamic in structure, with later questions determined by earlier answers. A third party may submit on an entity’s behalf with an attestation of authorization, though responsibility for compliance stays with the covered entity.
Take that content list to an industrial environment and it resolves into a few specific questions. Which devices were affected, and how would you establish that? What was exploited, and where would the evidence sit? Which operations were impacted, and to what degree?
Those are answerable questions. Answering them inside 72 hours depends on what was being recorded before the incident began.
The Preservation Requirement
A covered entity required to submit a CIRCIA report must preserve data and records relevant to the incident. That preservation obligation is part of the proposed CIRCIA reporting requirements, not a separate afterthought. The requirement applies even to entities excused from reporting directly to CISA under the Substantially Similar Reporting Exception.
Period. Begins on the date the entity established a reasonable belief that a Covered Cyber Incident occurred, or the date a ransom payment was disbursed. Ends two years after submission of the last CIRCIA report.
Scope. CISA’s proposed examples include indicators of compromise and relevant log entries; forensic artifacts including memory captures, forensic images, relevant network data, and system information; and communications with the threat actor.
Method. Significant flexibility is proposed. Electronic or hard copy, onsite or offsite, network or cloud, active or archived, provided the material retains all salient details and stays readily accessible and retrievable in response to a lawful government request.
Look closely at “relevant network data.” Preserving network data from the incident window requires that the data existed during the incident window, which is a decision made in advance of it. This is the layer EmberOT is built around, and the requirement holds regardless of what produces the record.
The two-year clock starting from the last report means preservation obligations can run well past the point where an incident feels closed. A supplemental report filed months later resets the end date.
The Exception that May Not Apply
The Substantially Similar Reporting Exception excuses a covered entity from reporting to CISA when it reports substantially similar information, in a substantially similar timeframe, to another federal agency under a legal or contractual obligation, and CISA has both an information sharing agreement and a sharing mechanism in place with that agency.
Two limits matter for planning. CISA cannot finalize which programs qualify until the final rule publishes. Until then, no entity can confirm it’s covered by the exception.
State reporting requirements are explicitly not treated as substantially similar. An entity subject to state incident reporting should expect to file with the state and with CISA.
CIRCIA directs CISA to deconflict and harmonize with the 52 existing or proposed federal reporting requirements identified during the rulemaking. Harmonization was among the loudest themes in public comment, and how far the final rule carries it is an open question.
Two further exceptions are proposed, both narrow: one for certain DNS governance organizations, one for federal agencies already reporting under FISMA.
Enforcement, and the Protections That Come with Compliance
If CISA has reason to believe an entity experienced a reportable event and did not report it, it may issue a Request for Information. Failure to respond adequately can lead to a subpoena, issued no earlier than 72 hours after the RFI is served. Non-compliance with a subpoena may be referred to the Department of Justice for civil enforcement, and failure to comply may be punished as contempt. Separate referral paths exist for suspension and debarment, and for federal contract actions.
CISA may not take these enforcement actions against SLTT government entities. For municipal utilities and other government-operated systems, the enforcement posture as proposed is materially different from what a private operator faces.
The protections attaching to compliance are substantial. Reports and RFI responses, when marked appropriately, are treated as commercial, financial, and proprietary information. They are exempt from FOIA and from state and local disclosure laws. Applicable privileges, including trade secret protections, are preserved. Submitting a report creates no cause of action, and reports may not be entered as evidence, subjected to discovery, or used in a trial or hearing. Information obtained solely through a CIRCIA report generally cannot be used by federal or SLTT governments to regulate the submitting entity.
These protections do not extend to material produced under subpoena. Reporting on time and responding to an RFI carries a legal advantage that responding to a subpoena does not.
What to Work Through Now
None of this is binding until the final rule takes effect, and the specifics may shift. Each one takes longer than 72 hours to resolve, which is the argument for resolving them now.
Name who declares reasonable belief. The clock starts at a judgment call. Identify the role that makes it and the point at which it gets made.
Map the report contents to your sources. For each required element, identify where the answer would come from. The gaps in that mapping are your work list.
Check what your retention actually covers. Compare your current log and network data retention against a two-year preservation obligation that starts at reasonable belief and runs from the last report you file.
Find out whether your existing reporting might qualify. If you already report to NERC, TSA, the Coast Guard, or another federal regulator, note it now and watch for CISA’s determinations on the exception in the final rule.
Look at your third-party dependencies. The fourth prong of the incident definition covers unauthorized access facilitated by compromise of a cloud provider, managed service provider, hosting provider, or supply chain. Knowing which providers reach into your environment is part of knowing what you would have to report.
Draft a report against a hypothetical incident. Conduct a tabletop exercise, and make sure everyone is in the room if they’re part of the decision-making process. Take a plausible scenario, walk it through the content requirements, and record where you run out of answers. The exercise takes an afternoon and produces a specific gap list.
Revisit this when the rule publishes. Everything above is proposed, and the feedback CISA collected this summer lands in the final text.
The Record Has to Exist Before the Clock Starts
The obligations described here amount to a requirement to describe what happened in your environment, in some detail, on a short clock, and to hold the underlying material for two years afterward.
That description is much easier to produce where the relevant record already exists than where it has to be assembled afterward. The rule doesn’t prescribe how a covered entity gets there, which leaves the approach open. The deadlines set the pace of a response, and then the preservation obligation outlasts it by two years.
We’ll follow up with an update when the final rule publishes. In the meantime, if you want a hand working out what your current retention would actually produce against that obligation, reach out any time.
Become a Subscriber
EMBEROT WILL NEVER SELL, RENT, LOAN, OR DISTRIBUTE YOUR EMAIL ADDRESS TO ANY THIRD PARTY. THAT’S JUST PLAIN RUDE.
