Explore the key aspects of the Cyber Incident Reporting for Critical Infrastructure Act of 2022 and its proposed rulemaking, including covered entities and substantial cyber incidents.

The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) introduces significant changes to how cyber incidents are reported within critical infrastructure sectors. This act, through its Notice of Proposed Rulemaking (NPRM), outlines the requirements for covered entities to report substantial cyber incidents.
Understanding these requirements is crucial for organizations operating within critical infrastructure.
The CIRCIA NPRM defines a covered cyber incident as a substantial cyber incident experienced by a covered entity. This definition is central to the reporting requirements and helps determine which incidents must be reported.
The act aims to enhance the security and resilience of critical infrastructure by ensuring timely reporting of significant cyber incidents.
Identifying Covered Entities
Under the proposed rulemaking, a covered entity is any organization that meets one or more of the 16 sector-based criteria listed in proposed 6 CFR § 226.2.
These criteria are designed to identify entities that operate within critical infrastructure sectors. The Small Business Administration’s specifications for small businesses are also considered in determining covered entities.
To qualify as a covered entity, an organization must be part of a critical infrastructure sector. This includes sectors such as energy, transportation, healthcare, and financial services. The proposed rulemaking ensures that entities within these sectors are held accountable for reporting substantial cyber incidents. This accountability is essential for maintaining the security and reliability of critical infrastructure.
Understanding Substantial Cyber Incidents
A substantial cyber incident is defined as a significant cyber incident that impacts a covered entity. The CIRCIA NPRM provides examples of qualifying incidents and incidents that are unlikely to qualify. Understanding what constitutes a substantial cyber incident is crucial for covered entities to comply with the reporting requirements.
Examples of qualifying incidents include large-scale data breaches, ransomware attacks, and disruptions to critical services. These incidents have the potential to cause significant harm to critical infrastructure and must be reported promptly. On the other hand, minor incidents that do not significantly impact operations are unlikely to qualify as substantial cyber incidents.
Reporting Requirements and Compliance
Covered entities are required to report substantial cyber incidents to the appropriate authorities as outlined in the CIRCIA NPRM. This reporting process ensures that relevant stakeholders are aware of significant cyber incidents and can take necessary actions to mitigate risks. Compliance with these reporting requirements is essential for maintaining the security of critical infrastructure.
The proposed rulemaking also outlines the timeline for reporting substantial cyber incidents. Covered entities must report incidents within a specified timeframe to ensure timely response and mitigation. Failure to comply with these reporting requirements can result in penalties and other consequences. Understanding the reporting process and timeline is crucial for covered entities to ensure compliance.

