Ransomware payment reporting requirements under CIRCIA give covered critical infrastructure organizations 24 hours from the moment they disburse a ransom to report the payment to CISA, and 72 hours from discovery of a substantial cyber incident to report the incident itself. Both clocks come from the Cyber Incident Reporting for Critical Infrastructure Act of 2022, but neither is enforceable yet. CISA published its proposed rule on April 4, 2024, and the federal regulatory agenda projects a final rule in May 2026.1Reginfo.gov. View Rule 1670-AA04 Once the final rule takes effect, the deadlines start running with little lead time, so covered organizations should treat the proposed rule as the operating blueprint now.
Whether the Rule Applies to Your Organization
CIRCIA reporting duties reach only “covered entities.” Being in one of the 16 critical infrastructure sectors designated under Presidential Policy Directive 21 — chemical, communications, energy, financial services, healthcare, water, and the rest — is the entry point, not the whole test. Under the proposed rule, an organization in one of those sectors also has to satisfy at least one of two qualifying criteria.2Federal Register. Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements
The first is size. If the organization exceeds the Small Business Administration size standard for its industry classification, it’s covered. The second is sector-specific and applies regardless of size. Examples the proposed rule captures this way include owners of chemical facilities subject to the Chemical Facility Anti-Terrorism Standards, Defense Department contractors already required to report cyber incidents under DFARS, emergency services providers serving a population of 50,000 or more, communications providers such as ISPs, broadcasters, and cable operators, manufacturers of primary metals, machinery, electrical equipment, or transportation equipment, and operators within the bulk electric system. If your organization is small but sits inside one of these sector-specific hooks, the size test is irrelevant.
If your status is unclear, evaluate it before an incident forces the question. Uncertainty about coverage will not shield an entity from enforcement once the final rule takes effect.
The Two Reporting Deadlines
CIRCIA sets two distinct clocks that can run together during the same event.
The ransom payment clock is 24 hours. It starts when the funds leave the entity’s control, not when the attacker confirms receipt or delivers a decryption key.3Office of the Law Revision Counsel. 6 USC 681b – Required Reporting of Certain Cyber Incidents The incident clock is 72 hours from the point the entity reasonably believes a covered cyber incident has occurred.4Cybersecurity & Infrastructure Security Agency. Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) A ransomware attack that both compromises systems and results in a payment triggers both. In practice, if the payment happens inside the 72-hour incident window, the payment report will fall due first.
The 72-hour deadline attaches only to “substantial” incidents. The proposed rule defines those as incidents causing significant loss of confidentiality, integrity, or availability of an information system; serious impact on the safety or resiliency of operational systems; disruption of business or service delivery; or unauthorized access enabled through a compromised cloud provider, managed service provider, or supply chain.2Federal Register. Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements An extortion threat with no actual system compromise does not qualify.
Reporting doesn’t stop with the initial filing. Whenever substantial new or different information surfaces, the entity must submit a supplemental report, and that obligation continues until the incident is fully mitigated and resolved.5Office of the Law Revision Counsel. 6 USC 681b – Required Reporting of Certain Cyber Incidents If an organization files an incident report and later pays the ransom, that payment itself is a supplemental trigger. CISA expects initial reports filed under the tight deadlines to be incomplete; supplements are how the record catches up with the forensics.
What Goes Into a Ransom Payment Report
The proposed rule calls for granular detail about both the extortion event and the money movement.2Federal Register. Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements At minimum, a payment report must include:
- The date the payment was made
- The amount and type of assets used, whether cryptocurrency, wire transfer, or another form
- The full payment demand, including the specific currency or asset type the attacker requested
- Payment instructions provided by the attacker, including wallet addresses, transaction hashes, and any identifying information about the recipient
- The outcome: whether the attacker delivered a working decryption tool, returned exfiltrated data, or disappeared
- Involvement of any third-party incident response firm or negotiation service
The underlying incident details ride along with the payment report. That means the attack vector (phishing email, exploited vulnerability, compromised vendor), the ransomware variant if forensics can identify it, indicators of compromise such as suspicious traffic or malicious files, and the impact on operations and services. Contemporaneous logs kept from initial detection through negotiation and payment make assembling a report inside 24 hours realistic rather than aspirational.
How To Submit
CISA’s incident reporting portal is the primary channel. The agency already runs a web-based form for voluntary reporting that captures the categories CIRCIA will require, and that portal (or an updated version) will be the mandatory submission channel once the final rule takes effect.6Cybersecurity & Infrastructure Security Agency. Voluntary Cyber Incident Reporting After submission the system generates a confirmation with a unique tracking number. Save it. That number is your proof of timely compliance. CISA typically sends an automated acknowledgment to the listed point of contact, and analysts sometimes follow up for technical clarification or to share threat intelligence.
Using a Third Party
Covered entities don’t have to file themselves. The statute allows an organization to designate an incident response firm, insurance carrier, managed service provider, or law firm to submit on its behalf, and the third party must attest that the covered entity expressly authorized the filing.2Federal Register. Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements Authorization can be verbal or written. Legal responsibility does not shift with the filing. A late or incomplete submission by the third party is the covered entity’s problem.
Records You Have To Keep After Filing
Filing doesn’t close the file. The proposed rule requires covered entities to preserve all data and records relevant to the reported incident or payment for at least two years from the date of the most recent report, including supplemental filings.2Federal Register. Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements The scope is broad: communications with the attacker, indicators of compromise, network logs, forensic images, information about exfiltrated data, financial records tied to the payment, and internal or third-party forensic reports.
One limit worth knowing. Organizations aren’t required to create records they wouldn’t otherwise maintain. The obligation attaches to data the entity already has or would generate through normal incident response. Preserved data has to stay readily accessible and protected against unauthorized access or destruction, so that a later lawful request from CISA or another federal agency can be honored.
What Happens If You Don’t Report
CIRCIA gives CISA a structured escalation path. It starts with a Request for Information. If the Director has reason to believe a covered entity experienced a reportable incident or made a ransom payment without filing, CISA can issue an RFI requiring a response within a set deadline.7Regulations.gov. Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements
An inadequate response within 72 hours can be escalated to a subpoena. Ignoring the subpoena opens the door to a Department of Justice referral and a civil enforcement action in federal district court, where noncompliance can be treated as contempt.8Cybersecurity and Infrastructure Security Agency. CIRCIA NPRM Overview
The exposure runs beyond court. CISA must refer noncompliant entities that may warrant suspension and debarment to the DHS Suspension and Debarment Official. For federal contractors, referrals can also go to contracting officials or the Attorney General. For any company whose revenue depends on federal contracts, that debarment risk is often the sharpest teeth in the statute. When deciding whether to exercise enforcement authority, CISA is required to consider how complex the incident-determination question was and the entity’s prior interactions with the agency. State, local, tribal, and territorial government entities remain subject to the reporting requirements but are excluded from these enforcement provisions.7Regulations.gov. Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements
Protections That Come With Filing
CIRCIA pairs the reporting duty with meaningful legal protections. Information submitted under the statute is exempt from disclosure under the Freedom of Information Act and equivalent state and local open-records laws.9Office of the Law Revision Counsel. 6 USC 681e – Information Shared With or Provided to the Federal Government Competitors, journalists, and the public cannot pry your report loose through a records request.
Federal, state, local, and tribal governments are barred from using information obtained solely through CIRCIA reporting to bring a regulatory enforcement action against the reporting entity, unless that government has an arrangement letting CIRCIA reports satisfy its own reporting requirements. Reports and materials created solely to prepare them are also inadmissible in any trial, hearing, or regulatory proceeding. That protection reaches documents drafted specifically for the filing. It doesn’t shield pre-existing records that the report happens to reference.
Filing does not waive attorney-client privilege, work-product protection, or trade secret protections, and CISA reads that provision broadly to cover any state or federal privilege that might apply.2Federal Register. Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements Without it, organizations would have a real reason to worry that disclosing incident details to a federal agency could waive privilege in later civil litigation.
When an Existing Sector Report Can Substitute
Many critical infrastructure organizations already report cyber incidents to sector regulators. Banks report to financial regulators. Defense contractors report to DoD. Energy companies report to DoE. CIRCIA includes a substantially-similar-reporting exception so those entities don’t have to file the same facts twice.
The exception applies only when five conditions are all satisfied. The other report must contain functionally equivalent information, be filed on a timeline that lets CISA receive it inside the CIRCIA deadline, and the receiving agency must have a formal information-sharing agreement with CISA plus a working mechanism to actually transmit the report in time.2Federal Register. Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements If the other agency collects less detail than CIRCIA requires, or its deadline is longer, the exception does not apply and the entity must file separately with CISA. Assume you owe CISA a report until you can confirm every condition is met.