Sophos News

Sophos Guidance on CIRCIA

Note: this information is relevant to US based organizations; click the image above to download the report.

In March 2022, President Biden signed the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) into law in the United States. Its enactment requires the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to develop and implement regulations requiring covered entities to report covered cyber incidents and ransomware payments to CISA, within 24 months of passing the law. The new law grants CISA with its first-ever enforcement powers.

CISA is expected to deliver a Notice of Proposed Rulemaking (NPRM) in early 2024 that will highlight the proposed reporting requirements, which are expected to be available for feedback before final publication in 2025. For updated guidance and feedback opportunities, organizations can visit https://www.cisa.gov/CIRCIA.

Who will be affected by this legislation?

The legislation implements regulations on United States “Covered Entities” in the critical infrastructure sector, as defined by Presidential Policy Directive 211. Covered entities are organizations within industry sectors considered to be “critical infrastructure,” listed in the table below. The sectors and their Sector Specific Agencies (SSAs) include, but are not limited to:

It is worth noting that Education is considered a subsector of the Government Facilities Sector,2 and the Education Facilities Subsector encompasses prekindergarten through 12th grade, as well as post-secondary public, private, and proprietary education facilities.

What are the requirements of the legislation?

Reporting is not required until CISA’s Final Rule implementing CIRCIA’s reporting requirements goes into effect, which is expected in 2025. Until then, organizations are strongly encouraged to voluntarily share cyber incident information with CISA, and they can be reached 24/7 at report@cisa.gov, or (888) 282-08703, or their online portal at https://www.cisa.gov/report. More information regarding the final legislation and voluntary reporting can be found here4.

However, once the Final Rule goes into effect, it will likely require “Covered Entities” to:

If a “Covered Entity” is a victim of a cyber incident and makes a ransomware payment prior to the 72-hour reporting requirement, they may likely be allowed to submit one single report, however, final reporting procedures are still to be determined.

What constitutes a covered cyber incident?

The final definition is yet to be proposed; however it will likely include at a minimum:

The final legislation will also likely account for the sophistication or novelty of tactics used to perpetrate a cyber incident, as well as:

What must the contents of a report include?

The final required reporting content may vary, and will be available after publication, but as a best practice in incident response management, Covered Entities should be prepared to report:

  1. Incident date and time
  2. Incident location
  3. Type of observed activity
  4. Detailed narrative of the event
  5. Number of people or systems affected
  6. Company/Organization name
  7. Point of Contact details
  8. Severity of event
  9. Critical Infrastructure Sector if known
  10. Anyone else that was informed

Other information that may be required could include:

Which third parties can report on the affected party’s behalf?

Entities deemed critical infrastructure that are required to report a cyber incident or ransom payment may be allowed to use a third party to submit the report on their behalf. The final guidance on how to use a third party will be available with the final regulations, but it is expected that the list of third parties will likely include:

What happens if an affected entity fails to comply with reporting requirements?

If an impacted organization misses the 72-hour deadline, a subpoena may be issued by the Director of CISA to compel disclosure of information deemed necessary. The final regulations will fully define enforcement methods and what can be expected.

What protections do reporting parties have?

CIRCIA reports are expected to be considered the commercial, financial, and proprietary information of the covered entity and are likely exempt from disclosure under section 552(b)(3) of title 5, United States Code (commonly known as the ‘Freedom of Information Act’), as well as any provision of State, Tribal, or local freedom of information law, open government law, open meetings law, open records law, sunshine law, or similar law requiring disclosure of information or records. Such an exemption is likely to require the reporting entity to assert its rights in writing under this section.

1 https://www.cisa.gov/sites/default/files/2023-01/ppd-21-critical-infrastructure-and-resilience-508_0.pdf

2 https://www.dhs.gov/xlibrary/assets/nppd/nppd-ip-education-facilities-snapshot-2011.pdf

3 https://www.cisa.gov/sites/default/files/2022-11/Sharing_Cyber_Event_Information_Fact_Sheet_FINAL_v4.pdf

4 https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/cyber-incident-reporting-criticalinfrastructure-act-2022-circia

This document does not constitute legal advice nor does it reflect the views of Sophos or its employees. Companies should consult their own counsel for legal guidance on any laws and regulations.