The REPORT Act sets the reporting requirements online platforms must follow when they encounter child sexual exploitation on their services. Signed into law on May 7, 2024 as Public Law 118-59, it amended 18 U.S.C. § 2258A to broaden which offenses trigger a mandatory CyberTipline report, raise fines for noncompliance to as much as $850,000 for a first offense, and extend the evidence preservation window from 90 days to a full year. If you run compliance, trust and safety, or legal for a service that transmits or stores user content, the sections below walk through what the statute now requires.
Which Platforms Are Covered
The statute applies to any “provider” of an electronic communication service or remote computing service. In practice that sweeps in internet service providers, social media platforms, email and messaging services, cloud storage providers, and any other service that transmits or stores user content electronically.
Size is not an exemption. A small messaging app and a platform with hundreds of millions of users owe the same duty to report. Size only affects the penalty tier if a provider fails to comply.
What Triggers the Duty to Report
The obligation activates when a provider gains actual knowledge of facts or circumstances indicating an apparent violation of specific federal child exploitation statutes. Those statutes cover the production, distribution, receipt, and possession of child sexual abuse material. The REPORT Act added two more triggers that were not explicitly on the list before May 2024: child sex trafficking, and the coercion or enticement of a minor into illegal sexual activity.
Actual knowledge is a real limit. Constructive knowledge does not count, and the statute is explicit that providers are not required to monitor users, scan communications, or proactively search for illegal material. The duty only fires once the provider actually becomes aware.
Once aware, the provider must act “as soon as reasonably possible.” The statute sets no fixed deadline in hours or days. You cannot sit on a discovery for weeks, but the language accommodates the time it takes to pull together a complete report.
The statute also distinguishes between apparent violations and planned or imminent ones. Apparent violations, where facts suggest a crime has occurred or is occurring, trigger a mandatory report. Planned or imminent violations, where facts suggest a crime may be about to happen, are permissive; a provider may report them but is not legally required to.
What to Include in a CyberTipline Report
The statute lists categories of information that a provider may include, and uses the phrase “at the sole discretion of the provider” when describing report contents. The items below are not strictly mandatory, but the more complete the report, the more useful it is to investigators:
- Identifying information about the suspect, including email addresses, IP addresses, payment information, and any self-reported details like name or username.
- Timestamps and history: when the content was uploaded, transmitted, or discovered by the provider, including time zone data.
- Geographic indicators, such as IP address, verified physical address, or at minimum an area code or zip code associated with the account.
- The visual depictions themselves.
- The full message or transmission containing the material, including attached files or transmission data.
Hash values are especially useful because they let law enforcement and other providers identify copies of the same known illegal file across platforms. Under 18 U.S.C. § 2258C, NCMEC can share hash values back to providers so they can detect previously identified material. Participation in that hash-sharing program is voluntary, and receiving hashes from NCMEC does not by itself create an obligation to use them.
How to Submit the Report
Reports go through the NCMEC CyberTipline, the centralized intake point for provider reports nationwide. The electronic portal uses standardized fields to categorize the type of exploitation, the urgency, and the supporting evidence. After submission, the system generates a confirmation receipt that documents that the provider met its reporting duty.
Keep your own internal records of every submission. If a regulator or court later questions whether the company reported in a timely manner, that internal documentation is the evidence of compliance.
Preserving the Evidence for One Year
The single largest practical change under the REPORT Act was extending the preservation window from 90 days to one full year from the date the report is submitted to the CyberTipline. Investigations into exploitation networks often take months, and evidence that vanished at 90 days had been derailing prosecutions.
The preservation duty is not limited to the exact material described in the report. It also covers any visual depictions, data, or digital files that are reasonably accessible and could add context about the reported material or the person involved. Preserved materials must be stored securely, with employee access limited to staff who need it to comply with the preservation requirement.
The one-year window is a floor, not a ceiling. Providers may voluntarily preserve longer. The statute does not require providers to delete material once the year ends, and it does not require them to wait for law enforcement authorization before deleting it.
Who You Can and Can’t Tell
Once a report is filed, the statute sharply limits who the provider may share the underlying information with. Permitted recipients are federal, state, local, or tribal law enforcement agencies involved in investigating child exploitation crimes, qualifying foreign law enforcement agencies, NCMEC itself, and recipients required by legal process such as a subpoena or court order.
The user whose account triggered the report is not on that list. The statute effectively prohibits tipping off a reported user, because a notification could prompt them to destroy evidence, flee, or continue harming a child under different account credentials. Trust and safety teams need to understand this limit; an accidental notification can compromise an investigation.
Liability Protection for Good-Faith Reports
Under 18 U.S.C. § 2258B, no civil claim or criminal charge may be brought against a provider, a domain name registrar, or their employees arising from carrying out reporting or preservation duties under the statute. That protection extends to storing and handling the reported material itself, which matters because a provider necessarily possesses illegal content while working the report.
The immunity has limits. It does not cover intentional misconduct, actions taken with actual malice, reckless disregard of a substantial risk of causing physical injury, or use of the reporting process for a purpose unrelated to statutory duties. To keep the protection, providers must also minimize the number of employees with access to the reported material and must permanently destroy any visual depictions when a law enforcement agency requests destruction.
The REPORT Act added two further protections. Vendors that contract with NCMEC to store and transfer reported material now have liability coverage if they meet certain cybersecurity requirements. And minors who self-report images depicting themselves to the CyberTipline are shielded from liability for doing so.
Penalties for Failing to Report
Fines rose sharply under the REPORT Act. Prior law capped an initial failure to report at $150,000, with $300,000 for repeat violations. The current penalties are tiered by platform size and by whether it is a first or subsequent violation:
- Initial knowing and willful failure: up to $850,000 for providers with 100 million or more monthly active users, or up to $600,000 for providers with fewer than 100 million monthly active users.
- Subsequent knowing and willful failures: up to $1,000,000 for larger providers, or up to $850,000 for smaller providers.
The “knowingly and willfully” language does real work. A provider that genuinely did not know about the content cannot be fined. A provider that knew but failed to report because of a bureaucratic breakdown still faces regulatory exposure, but the penalty bar is higher than for a deliberate refusal. The statute does not define these terms internally, so courts would apply their ordinary federal criminal law meanings: “knowingly” as awareness of the facts, and “willfully” as a deliberate choice to ignore the legal duty.
No Duty to Monitor Users
An explicit carve-out in the statute is often misunderstood. Nothing in 18 U.S.C. § 2258A requires a provider to monitor any user or subscriber, monitor the content of any communication, or proactively search, screen, or scan for child exploitation material. The reporting duty activates only when a provider gains actual knowledge through its existing operations.
If a company does use detection tools, whether voluntarily or under a separate legal framework, and those tools surface apparent violations, the actual knowledge standard is met and the reporting clock starts. Choosing to scan means choosing to know.
AI-Generated Content
The reporting obligation covers violations of 18 U.S.C. § 2252A, which includes computer-generated images “virtually indistinguishable” from a real minor engaged in sexually explicit conduct. AI-generated content meeting that standard falls within the mandatory reporting framework.
The reporting duty does not extend to violations of 18 U.S.C. § 1466A, which covers obscene visual representations of child abuse that do not depict an identifiable real minor. AI-generated cartoons, illustrations, or clearly synthetic content that does not resemble a real child’s abuse falls outside the mandatory reporting trigger, even though such material may still violate federal obscenity law.