Is it allowed under U.S. federal law for many critical infrastructure owners to avoid reporting cyber incidents that materially affect services?

Last updated on October 4, 2025

NO — The Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) and related CISA rules and guidance create new reporting duties for operators of critical infrastructure and certain covered entities. The law requires covered entities to report qualifying cyber incidents and ransomware payments to CISA within specific timeframes once the implementing rules are in place. This changed the landscape from purely voluntary reporting to mandatory reporting for many organisations in scope, so affected operators cannot simply decline to report qualifying incidents to federal authorities.

 

https://www.cisa.gov/topics/cyber-threats-and-advisories/information-sharing/cyber-incident-reporting-critical-infrastructure-act-2022-circia

2022-03 (CIRCIA)

Scroll to Top