{
  "node_id": "us-circia-cyber-incident-reporting-act-2022",
  "title": "Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA)",
  "domain": "Cybersecurity",
  "version": "1.1.0",
  "last_updated": "2026-07-03",
  "bluf": "The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) mandates that covered entities in critical infrastructure sectors report covered cyber incidents to the Cybersecurity and Infrastructure Security Agency (CISA) within 72 hours of reasonable belief that an incident has occurred, and report any ransomware payments within 24 hours of making the payment, as required by Section 2242 of the Homeland Security Act of 2002, added by CIRCIA and codified at 6 U.S.C. 681b.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "ai_overlay_2026"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-cybersecurity-framework-2-0",
    "cisa-cross-sector-cybersecurity-goals",
    "cisa-ms-isac-ransomware-guide",
    "nis2-incident-reporting-article-23",
    "iso-27001-2022"
  ],
  "primary_citations_count": 8
}