Skip to main content
Privacy and Cybersecurity Update

Congress Passes Cyber Incident Reporting for Critical Infrastructure Act of 2022

March 21, 2022

The U.S. Congress has passed a significant new cybersecurity law that will require critical infrastructure entities to report material cybersecurity incidents and ransomware payments to the Cybersecurity and Infrastructure Security Agency (CISA) within 72 and 24 hours, respectively. The reporting requirements will cover multiple sectors of the economy, including chemical industry entities, commercial facilities, communications sector entities, critical manufacturing, dams, financial services entities, food and agriculture sector entities, healthcare entities, information technology, energy, and transportation. CISA must promulgate a proposed implementing regulation within 24 months from final enactment date of March 15, 2022, and a final regulation no later than 18 months thereafter. The effective date of the act’s reporting requirements will be set by the final rule.

Background. Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) is intended to provide the federal government with a better understanding of the nation’s cyberthreats and facilitate a coordinated national response to ransomware attacks. The FBI currently provides an avenue for voluntarily sharing information about cyber incidents and estimates that only a quarter of cyber incidents are actually reported to the FBI. Separately, current Department of Homeland Security (DHS) Transportation Security Administration (TSA) directives impose cybersecurity and reporting requirements for designated transportation operators and pipelines. Existing directives require select transportation and pipeline entities to report to CISA, within 24 hours, those cyber events that have the potential to disrupt operations. CIRCIA now provides that federal agencies may enter into agreements regarding the sufficiency of any such existing, substantially similar reporting obligations. When such agreements are in place, the reporting entity is exempt from new reporting requirements imposed by CIRCIA.

弁護士広告—Sidley Austin LLP はグローバルな法律事務所です。当事務所の所在地および連絡先情報は、www.sidley.com/en/locations/offices に掲載されています。

Sidley は、本情報をクライアントおよび関係者の皆様へのサービスとして、教育目的のみに提供しています。本情報は、法的助言として解釈または依拠されるべきものではなく、また弁護士と依頼者の関係を生じさせるものでもありません。読者は、専門家の助言を求めることなく本情報に基づいて行動すべきではありません。Sidley および Sidley Austin とは、www.sidley.com/disclaimer に記載のとおり、Sidley Austin LLP およびその関連パートナーシップを指します。

© Sidley Austin LLP

お問い合わせ

この Sidley Update に関してご質問がある場合は、通常ご担当されている Sidley の弁護士、またはご連絡ください。

関連公式ブログ