Scope - What This Guide Covers
This guide focuses on the dual-track federal cyber incident reporting framework: the voluntary sharing provisions under the Cybersecurity Information Sharing Act of 2015 (CISA 2015), extended through September 30, 2026, and the mandatory reporting requirements under the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), with final regulations expected by May 2026.
You'll find requirement breakdowns, implementation guidance for both frameworks, and a quick reference table. This isn't about choosing between voluntary or mandatory reporting. You're managing both simultaneously, and your program needs to accommodate overlapping timelines and distinct obligations.
Key Concepts and Definitions
CISA 2015 Voluntary Sharing: You can share cyber threat indicators and defensive measures with the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency (CISA). In return, you receive antitrust immunity, Freedom of Information Act protections, and liability shields for information shared in good faith.
CIRCIA Mandatory Reporting: Covered entities must report substantial cyber incidents within 72 hours and ransom payments within 24 hours. This isn't optional. The statute sets these deadlines; CISA's regulations will define who reports, what constitutes a covered incident, and how to submit.
Covered Entity: CIRCIA's regulations will clarify this term. Expect definitions tied to critical infrastructure sectors, potentially including cloud service providers and managed service providers in the reporting chain.
Substantially Similar Events: A concept CISA plans to address in rulemaking. If you've already reported an incident under another federal requirement, will CIRCIA accept that submission? This harmonization question matters for organizations juggling multiple reporting obligations.
Requirements Breakdown
CISA 2015 (Voluntary, Through September 30, 2026)
What you can share: Cyber threat indicators (evidence of security threats like malicious code signatures, IP addresses, or attack patterns) and defensive measures (actions to detect or prevent threats).
Legal protections:
- Antitrust immunity for sharing within industry groups
- FOIA exemptions (shared information won't be disclosed publicly)
- Liability protection (you can't be sued for sharing in good faith)
Limitations: The information you share can't be used for regulatory enforcement against you, except in cases involving imminent threats of death or serious bodily harm.
Sunset risk: Congress has extended this law twice with short-term renewals. Don't build long-term threat intelligence programs assuming these protections will persist beyond September 2026.
CIRCIA (Mandatory, Regulations Expected May 2026)
Statutory deadlines:
- 72 hours to report a covered cyber incident
- 24 hours to report a ransom payment
Open questions:
- Which organizations qualify as covered entities
- How "covered cyber incident" will be defined
- Whether cloud and managed service providers must report on behalf of customers
- How CIRCIA harmonizes with existing federal and state reporting requirements
- What constitutes a "substantially similar" event already reported elsewhere
Implementation Guidance
Prepare Your Voluntary Sharing Program
If you're using CISA 2015 protections, document your sharing procedures. When you submit threat indicators, include a clear statement that you're sharing under CISA 2015 and expect the statutory protections. Don't assume CISA's portal will automatically apply the right legal framework to your submission.
Review what you're sharing. The protections don't cover business information unrelated to cybersecurity threats. If you're sharing customer data or proprietary business details beyond what's necessary to describe the threat, you're outside the law's safe harbor.
Build Your CIRCIA Readiness Now
You don't know yet whether you're a covered entity, but you can prepare the infrastructure:
Detection capabilities: Your security operations center needs to identify incidents that might meet CIRCIA's threshold within hours, not days. If you're relying on monthly vulnerability scans and quarterly reviews, you can't hit a 72-hour reporting window.
Decision trees: Draft incident classification criteria now. When the regulations publish definitions of "covered cyber incident," you'll map them to your existing severity tiers. Your on-call responders shouldn't be interpreting regulatory language at 2 a.m. during an active incident.
Reporting templates: Create draft submission forms with fields for incident timeline, affected systems, data types involved, and containment actions. You'll revise these when CISA publishes the reporting portal specifications, but starting from a template beats starting from scratch under deadline pressure.
Ransom payment procedures: If you're in a sector where ransomware is a realistic threat, document who has authority to approve a payment and how you'll notify CISA within 24 hours. This isn't endorsing payment; it's acknowledging that if your leadership makes that decision, you need a reporting mechanism ready.
Engage in the Rulemaking Process
CISA scheduled seven virtual town halls between March 9 and April 2, 2026. Register at www.cisa.gov/circia. The first five sessions are sector-specific; the final two are open to all organizations.
Bring specific concerns:
- If you're already reporting under sector-specific rules (like North American Electric Reliability Corporation Critical Infrastructure Protection standards for utilities), ask how CIRCIA will harmonize with existing obligations
- If you're a managed service provider, ask whether you report on behalf of clients or they report independently
- If you operate across multiple sectors, ask which sector definition applies when your organization spans categories
Your comments during rulemaking can shape the final rule's scope and burden. CISA can't change the statutory deadlines, but it has discretion on definitions, thresholds, and harmonization approaches.
Common Pitfalls
Assuming voluntary sharing satisfies mandatory reporting: CISA 2015 and CIRCIA serve different purposes. Voluntary threat intelligence sharing doesn't fulfill a mandatory incident report, even if you're describing the same event.
Waiting for final regulations to prepare: By the time CISA publishes final rules in May 2026, you'll have weeks to comply, not months. Build your incident detection and reporting infrastructure now.
Treating September 2026 as a distant deadline: If Congress doesn't renew CISA 2015 again, your voluntary sharing program loses its legal protections on October 1, 2026. Review any information-sharing agreements with industry groups or ISACs that rely on CISA 2015's liability shields.
Ignoring cloud provider responsibilities: If CIRCIA regulations require cloud or managed service providers to report incidents affecting your infrastructure, you need contractual clarity on who reports what. Don't discover this gap during an incident.
Over-reporting to stay safe: When CIRCIA's definitions publish, resist the urge to report every security event out of caution. Flooding CISA with low-severity reports dilutes the value of the system and burdens your team with unnecessary documentation.
Quick Reference Table
| Framework | Type | Deadline | Scope | Status |
|---|---|---|---|---|
| CISA 2015 | Voluntary | None (share when ready) | Cyber threat indicators, defensive measures | Extended through Sept 30, 2026 |
| CIRCIA | Mandatory | 72 hours (incidents), 24 hours (ransom) | Covered cyber incidents (definition pending) | Regulations expected May 2026 |
| Town Halls | Stakeholder input | March 9 - April 2, 2026 | Scope, definitions, harmonization | Registration open at cisa.gov/circia |
Next action: Mark your calendar for the CIRCIA town hall relevant to your sector. Register now; these sessions fill quickly. If you miss the sector-specific session, attend one of the general sessions on March 31 or April 2, 2026.
Your reporting program needs to handle both frameworks simultaneously. Build the infrastructure now, engage in rulemaking, and prepare for a compliance landscape where voluntary and mandatory reporting coexist with different rules, different deadlines, and different legal implications.





