Skip to main content
Privacy and Cybersecurity Update

Congress Passes Cyber Incident Reporting for Critical Infrastructure Act of 2022

March 21, 2022

The U.S. Congress has passed a significant new cybersecurity law that will require critical infrastructure entities to report material cybersecurity incidents and ransomware payments to the Cybersecurity and Infrastructure Security Agency (CISA) within 72 and 24 hours, respectively. The reporting requirements will cover multiple sectors of the economy, including chemical industry entities, commercial facilities, communications sector entities, critical manufacturing, dams, financial services entities, food and agriculture sector entities, healthcare entities, information technology, energy, and transportation. CISA must promulgate a proposed implementing regulation within 24 months from final enactment date of March 15, 2022, and a final regulation no later than 18 months thereafter. The effective date of the act’s reporting requirements will be set by the final rule.

Background. Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) is intended to provide the federal government with a better understanding of the nation’s cyberthreats and facilitate a coordinated national response to ransomware attacks. The FBI currently provides an avenue for voluntarily sharing information about cyber incidents and estimates that only a quarter of cyber incidents are actually reported to the FBI. Separately, current Department of Homeland Security (DHS) Transportation Security Administration (TSA) directives impose cybersecurity and reporting requirements for designated transportation operators and pipelines. Existing directives require select transportation and pipeline entities to report to CISA, within 24 hours, those cyber events that have the potential to disrupt operations. CIRCIA now provides that federal agencies may enter into agreements regarding the sufficiency of any such existing, substantially similar reporting obligations. When such agreements are in place, the reporting entity is exempt from new reporting requirements imposed by CIRCIA.

律师广告—Sidley Austin LLP 是一家全球性律师事务所。我们的地址及联系方式可在 www.sidley.com/en/locations/offices 查阅。

Sidley 提供本信息仅作为向客户及其他友好人士提供的服务,且仅供教育目的使用。本信息不应被解释或依赖为法律意见,亦不构成律师与客户关系。读者在未寻求专业顾问意见之前,不应依据本信息采取任何行动。Sidley 和 Sidley Austin 指 Sidley Austin LLP 及其关联合伙实体,详见 www.sidley.com/disclaimer

© Sidley Austin LLP

联系我们

如果您对本次 Sidley 更新有任何疑问,请联系您平时合作的 Sidley 律师,或

Related Blogs