United States

CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act)

22 controls. 2 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

22 controls 2 frameworks share controls with it United States verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
CIRCIA-2240Definitions: Covered Entity, Covered Cyber Incident, Ransom Payment1
CIRCIA-2241Cyber Incident Review and Threat Indicator Sharing1
CIRCIA-2242a172-Hour Covered Cyber Incident Report2
CIRCIA-2242a224-Hour Ransom Payment Report2
CIRCIA-2242a3Supplemental Reports2
CIRCIA-2242a4Preservation of Data Relevant to the Incident1
CIRCIA-2242a5Reporting Exceptions: Substantially Similar Reporting and DNS0
CIRCIA-2242c4Required Contents of a Covered Cyber Incident Report1
CIRCIA-2242c5Required Contents of a Ransom Payment Report1
CIRCIA-2242dThird-Party Report Submission0
CIRCIA-2242eAwareness of Reporting Obligations1
CIRCIA-2243Voluntary Reporting of Other Cyber Incidents0
CIRCIA-2244bResponse to a CISA Request for Information1
CIRCIA-2244cSubpoena and Civil Enforcement for Noncompliance1
CIRCIA-2244dReferral to the Attorney General0
CIRCIA-2244fExclusion of State, Local, Tribal and Territorial Governments0
CIRCIA-2245aAuthorized Use, Retention and Digital Security of Reports1
CIRCIA-2245a5Prohibition on Use of Reported Information in Regulatory Actions0
CIRCIA-2245bProtections for Reporting Entities (FOIA, Privilege, Proprietary)0
CIRCIA-2245cLiability Protections and Evidentiary Restrictions0
CIRCIA-2246Cyber Incident Reporting Council Harmonization0
CIRCIA-2247Federal Sharing of Incident Reports0

Tell me when CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act) files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What this page is

A control-level reference for CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act), drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition