Federal cybersecurity laws in the United States are not a single statute but a stack of them, and which ones apply to you depends on what you do. Federal agencies and their contractors answer to FISMA. Critical infrastructure operators will soon report incidents under CIRCIA. Publicly traded companies disclose material incidents to the SEC. Defense contractors must meet NIST security controls and, increasingly, third-party CMMC certification. Healthcare organizations follow the HIPAA Security Rule, and non-bank financial firms follow the FTC Safeguards Rule. State breach notification laws sit on top of all of it.
FISMA: Federal Agencies and Their Contractors
The Federal Information Security Modernization Act of 2014 requires every federal executive branch agency to run an agency-wide information security program covering the data it collects, stores, and transmits.1National Institute of Standards and Technology. Federal Information Security Modernization Act FISMA The 2014 version replaced the original 2002 law to move agencies away from periodic checkbox audits toward continuous, real-time security.
Under FISMA, agencies must categorize their information systems by risk, apply security controls matched to that risk, conduct regular risk assessments, and perform annual security reviews. Agency heads and program officials are personally responsible for keeping risks at acceptable levels.1National Institute of Standards and Technology. Federal Information Security Modernization Act FISMA Continuous monitoring is central: agencies track system security on an ongoing basis rather than waiting for the next audit.
FISMA reaches beyond federal buildings. State agencies administering federal programs and private businesses holding government contracts also have to meet its security baseline. The Office of Management and Budget holds final oversight authority; the Department of Homeland Security, through CISA, develops and administers the security policies civilian agencies follow.1National Institute of Standards and Technology. Federal Information Security Modernization Act FISMA DHS also issues Binding Operational Directives, compulsory orders requiring federal agencies to act against specific known threats or vulnerabilities.2Federal CIO Council. DHS Binding Operational Directive (BOD)
CIRCIA: Incident Reporting for Critical Infrastructure
The Cyber Incident Reporting for Critical Infrastructure Act of 2022 will be the first broad federal mandate requiring private-sector critical infrastructure operators to report cyberattacks and ransomware payments to the government. The statute directs CISA to write regulations requiring covered entities to report significant cyber incidents within 72 hours and ransom payments within 24 hours.3Cybersecurity & Infrastructure Security Agency. Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA)
Here’s the part that trips people up: the reporting obligations are not enforceable yet. CISA issued a proposed rule but has pushed final publication to mid-2026, and the requirements may take additional time to go into effect after that. If you operate in a critical infrastructure sector, watch the rulemaking closely, because once the final rule lands, the deadlines will be tight.
Who Will Be Covered
CIRCIA applies within the 16 critical infrastructure sectors identified by Presidential Policy Directive 21, including energy, financial services, communications, healthcare, transportation, water, and information technology.4The White House (Archives). Presidential Policy Directive – Critical Infrastructure Security and Resilience Not every organization in those sectors will qualify as a covered entity. The final rule will establish size-based and sector-based criteria, likely drawing on Small Business Administration size standards to exclude smaller operations.3Cybersecurity & Infrastructure Security Agency. Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA)
The Deadlines and What to Preserve
Once the rules take effect, a covered entity must report a significant cyber incident to CISA within 72 hours of reasonably believing the incident occurred, and any ransom payment within 24 hours of disbursement.5Office of the Law Revision Counsel. 6 US Code 681b – Required Reporting of Certain Cyber Incidents Expect to preserve logs, communications, and other forensic data connected to any reported incident. CISA has authority to pursue administrative enforcement, including civil proceedings, against entities that fail to report.3Cybersecurity & Infrastructure Security Agency. Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA)
SEC Rules for Public Companies
Public companies have their own cybersecurity reporting regime, in force since late 2023. It runs independently of CIRCIA and applies based on securities registration, not critical infrastructure status.
Form 8-K Incident Disclosure
When a public company determines it has experienced a material cybersecurity incident, it must file a Form 8-K within four business days of that determination.6Securities and Exchange Commission. Form 8-K – Current Report The clock starts when the company decides the incident is material, not when the breach happened. If the full picture isn’t available at filing time, the company files what it knows and amends within four business days of learning more.
Annual Governance Disclosure
The SEC also added Item 106 to Regulation S-K, which requires domestic registrants to describe their cybersecurity risk management processes, strategy, and governance in their annual Form 10-K. Companies must explain how the board oversees cybersecurity risk and management’s role in assessing it. Foreign private issuers have a parallel requirement on Form 20-F.7U.S. Securities and Exchange Commission. Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure All registrants must tag their cybersecurity disclosures in Inline XBRL for fiscal years ending on or after December 15, 2024.
Defense Contractors: NIST 800-171, CMMC, and the False Claims Act
Companies handling Controlled Unclassified Information for the Department of Defense face some of the strictest federal cybersecurity requirements. They must implement the security controls in NIST Special Publication 800-171, covering access controls, incident response, audit logging, encryption, and more.8National Institute of Standards and Technology. NIST SP 800-171 Rev 3 – Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations Revision 3, finalized in May 2024, is the current version.
CMMC Certification Levels
The Cybersecurity Maturity Model Certification program adds verification on top of NIST 800-171. Rather than trusting contractors to self-report, CMMC requires assessments at three levels:9eCFR. 32 CFR Part 170 – Cybersecurity Maturity Model Certification (CMMC) Program
- Level 1 covers basic safeguarding of federal contract information and uses annual contractor self-assessment.
- Level 2 covers the full set of NIST SP 800-171 requirements for Controlled Unclassified Information. Depending on the sensitivity of the contract, DoD may accept self-assessment or require certification by an accredited third-party assessment organization.
- Level 3 covers the most sensitive programs and requires a government-led assessment by the Defense Industrial Base Cybersecurity Assessment Center.
The CMMC final rule was published on October 15, 2024. DoD is rolling out requirements in four phases over three years. Phase 1, which began in late 2025, focuses on Level 1 and Level 2 self-assessments in new solicitations.10DoD CIO. About CMMC Contractors who cannot demonstrate the required level will be ineligible for covered contract awards.
False Claims Act Exposure
The enforcement stick behind defense cybersecurity is the False Claims Act. A contractor that certifies compliance with cybersecurity requirements but doesn’t actually implement the controls can face civil fraud claims from the Department of Justice. Raytheon and related entities paid $8.4 million to resolve allegations that they failed to implement required cybersecurity controls, including not developing a system security plan for an internal system used on DoD contracts.11United States Department of Justice. Raytheon Companies and Nightwing Group to Pay $8.4M to Resolve False Claims Act Allegations Relating to Non-Compliance with Cybersecurity Requirements in Federal Contracts Current False Claims Act penalties run from roughly $14,000 to over $28,000 per false claim, and a single contract can involve many claims. Whistleblowers who report noncompliance share in any recovery.
HIPAA Security Rule for Healthcare
Any organization handling electronic protected health information, including hospitals, insurers, pharmacies, and their business associates, must comply with the HIPAA Security Rule. The rule requires three categories of safeguards: administrative (policies, training, risk analysis), physical (facility and workstation controls), and technical (access controls, encryption, audit logging).12HHS.gov. Summary of the HIPAA Security Rule The Department of Health and Human Services enforces the rule through the Office for Civil Rights, which can impose significant penalties when breaches trace back to inadequate safeguards.
FTC Safeguards Rule for Financial Institutions
Non-banking financial institutions, including mortgage brokers, auto dealers that arrange financing, tax preparers, and payday lenders, must comply with the FTC Safeguards Rule. The updated rule requires a written information security program that designates a qualified individual to run it, uses written risk assessments, applies access controls and encryption, deploys multi-factor authentication for anyone accessing customer data, and includes annual penetration testing plus vulnerability assessments every six months.13Federal Trade Commission. FTC Safeguards Rule – What Your Business Needs to Know Companies must also securely dispose of customer information within two years of the last use, unless a legitimate business or legal need requires retention.
Voluntary Threat Information Sharing
The Cybersecurity Information Sharing Act of 2015 gives companies a legal framework to voluntarily share cyber threat intelligence with each other and with the government without triggering antitrust, regulatory, or public records exposure. Under 6 U.S.C. ยง 1503, private entities are authorized to monitor their own information systems for cybersecurity purposes and to share cyber threat indicators and defensive measures with other private entities or the federal government.14Office of the Law Revision Counsel. 6 USC 1503 – Authorizations for Preventing, Detecting, Analyzing, and Mitigating Cybersecurity Threats
Companies that participate get liability protection, including immunity from antitrust claims that might otherwise arise from coordinating with competitors. Shared information is generally exempt from Freedom of Information Act disclosure, so competitors and the public cannot use FOIA to obtain threat data a company shared with the government.15FOIA.gov. Freedom of Information Act – Frequently Asked Questions In return, companies must strip out personally identifiable information not directly relevant to the threat before sharing. CISA runs the Automated Indicator Sharing program as the primary technical channel for this exchange.16Cybersecurity & Infrastructure Security Agency. How Automated Indicator Sharing (AIS) Works
State Laws Still Apply
Federal cybersecurity statutes generally do not preempt state law. Every state has its own data breach notification requirements, and those obligations run alongside federal reporting mandates rather than replacing them. A company that suffers a breach may need to report to CISA under CIRCIA, disclose to the SEC on Form 8-K, notify affected individuals under state breach notification laws, and report to state attorneys general, all on different timelines with different content requirements.
Efforts to create a single federal breach notification standard that would override state laws have repeatedly stalled in Congress. State attorneys general have opposed federal preemption, arguing state laws often give consumers stronger protections than the federal alternatives proposed. If you operate across multiple states, compliance planning has to account for the strictest applicable state requirement in addition to every relevant federal obligation.
Reporting a Cybercrime
Regulatory reporting is separate from law enforcement reporting. If you or your business fall victim to cybercrime, file a complaint with the FBI’s Internet Crime Complaint Center (IC3). IC3 accepts reports on business email compromise, ransomware, investment fraud, identity theft, phishing, romance scams, and other internet-related offenses.17Internet Crime Complaint Center (IC3). IC3 Brochure Filing with IC3 is available whether or not you have any mandatory reporting obligation under CIRCIA or SEC rules.