Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
CIRCIA and CISA 2015: Your Reporting Strategy ReferenceRegulations & Laws
5 min readFor GRC Leaders

CIRCIA and CISA 2015: Your Reporting Strategy Reference

Scope - What This Guide Covers

This guide focuses on the dual-track federal cyber incident reporting framework: the voluntary sharing provisions under the Cybersecurity Information Sharing Act of 2015 (CISA 2015), extended through September 30, 2026, and the mandatory reporting requirements under the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), with final regulations expected by May 2026.

You'll find requirement breakdowns, implementation guidance for both frameworks, and a quick reference table. This isn't about choosing between voluntary or mandatory reporting. You're managing both simultaneously, and your program needs to accommodate overlapping timelines and distinct obligations.

Key Concepts and Definitions

CISA 2015 Voluntary Sharing: You can share cyber threat indicators and defensive measures with the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency (CISA). In return, you receive antitrust immunity, Freedom of Information Act protections, and liability shields for information shared in good faith.

CIRCIA Mandatory Reporting: Covered entities must report substantial cyber incidents within 72 hours and ransom payments within 24 hours. This isn't optional. The statute sets these deadlines; CISA's regulations will define who reports, what constitutes a covered incident, and how to submit.

Covered Entity: CIRCIA's regulations will clarify this term. Expect definitions tied to critical infrastructure sectors, potentially including cloud service providers and managed service providers in the reporting chain.

Substantially Similar Events: A concept CISA plans to address in rulemaking. If you've already reported an incident under another federal requirement, will CIRCIA accept that submission? This harmonization question matters for organizations juggling multiple reporting obligations.

Requirements Breakdown

CISA 2015 (Voluntary, Through September 30, 2026)

What you can share: Cyber threat indicators (evidence of security threats like malicious code signatures, IP addresses, or attack patterns) and defensive measures (actions to detect or prevent threats).

Legal protections:

  • Antitrust immunity for sharing within industry groups
  • FOIA exemptions (shared information won't be disclosed publicly)
  • Liability protection (you can't be sued for sharing in good faith)

Limitations: The information you share can't be used for regulatory enforcement against you, except in cases involving imminent threats of death or serious bodily harm.

Sunset risk: Congress has extended this law twice with short-term renewals. Don't build long-term threat intelligence programs assuming these protections will persist beyond September 2026.

CIRCIA (Mandatory, Regulations Expected May 2026)

Statutory deadlines:

  • 72 hours to report a covered cyber incident
  • 24 hours to report a ransom payment

Open questions:

  • Which organizations qualify as covered entities
  • How "covered cyber incident" will be defined
  • Whether cloud and managed service providers must report on behalf of customers
  • How CIRCIA harmonizes with existing federal and state reporting requirements
  • What constitutes a "substantially similar" event already reported elsewhere

Implementation Guidance

Prepare Your Voluntary Sharing Program

If you're using CISA 2015 protections, document your sharing procedures. When you submit threat indicators, include a clear statement that you're sharing under CISA 2015 and expect the statutory protections. Don't assume CISA's portal will automatically apply the right legal framework to your submission.

Review what you're sharing. The protections don't cover business information unrelated to cybersecurity threats. If you're sharing customer data or proprietary business details beyond what's necessary to describe the threat, you're outside the law's safe harbor.

Build Your CIRCIA Readiness Now

You don't know yet whether you're a covered entity, but you can prepare the infrastructure:

Detection capabilities: Your security operations center needs to identify incidents that might meet CIRCIA's threshold within hours, not days. If you're relying on monthly vulnerability scans and quarterly reviews, you can't hit a 72-hour reporting window.

Decision trees: Draft incident classification criteria now. When the regulations publish definitions of "covered cyber incident," you'll map them to your existing severity tiers. Your on-call responders shouldn't be interpreting regulatory language at 2 a.m. during an active incident.

Reporting templates: Create draft submission forms with fields for incident timeline, affected systems, data types involved, and containment actions. You'll revise these when CISA publishes the reporting portal specifications, but starting from a template beats starting from scratch under deadline pressure.

Ransom payment procedures: If you're in a sector where ransomware is a realistic threat, document who has authority to approve a payment and how you'll notify CISA within 24 hours. This isn't endorsing payment; it's acknowledging that if your leadership makes that decision, you need a reporting mechanism ready.

Engage in the Rulemaking Process

CISA scheduled seven virtual town halls between March 9 and April 2, 2026. Register at www.cisa.gov/circia. The first five sessions are sector-specific; the final two are open to all organizations.

Bring specific concerns:

Your comments during rulemaking can shape the final rule's scope and burden. CISA can't change the statutory deadlines, but it has discretion on definitions, thresholds, and harmonization approaches.

Common Pitfalls

Assuming voluntary sharing satisfies mandatory reporting: CISA 2015 and CIRCIA serve different purposes. Voluntary threat intelligence sharing doesn't fulfill a mandatory incident report, even if you're describing the same event.

Waiting for final regulations to prepare: By the time CISA publishes final rules in May 2026, you'll have weeks to comply, not months. Build your incident detection and reporting infrastructure now.

Treating September 2026 as a distant deadline: If Congress doesn't renew CISA 2015 again, your voluntary sharing program loses its legal protections on October 1, 2026. Review any information-sharing agreements with industry groups or ISACs that rely on CISA 2015's liability shields.

Ignoring cloud provider responsibilities: If CIRCIA regulations require cloud or managed service providers to report incidents affecting your infrastructure, you need contractual clarity on who reports what. Don't discover this gap during an incident.

Over-reporting to stay safe: When CIRCIA's definitions publish, resist the urge to report every security event out of caution. Flooding CISA with low-severity reports dilutes the value of the system and burdens your team with unnecessary documentation.

Quick Reference Table

Framework Type Deadline Scope Status
CISA 2015 Voluntary None (share when ready) Cyber threat indicators, defensive measures Extended through Sept 30, 2026
CIRCIA Mandatory 72 hours (incidents), 24 hours (ransom) Covered cyber incidents (definition pending) Regulations expected May 2026
Town Halls Stakeholder input March 9 - April 2, 2026 Scope, definitions, harmonization Registration open at cisa.gov/circia

Next action: Mark your calendar for the CIRCIA town hall relevant to your sector. Register now; these sessions fill quickly. If you miss the sector-specific session, attend one of the general sessions on March 31 or April 2, 2026.

Your reporting program needs to handle both frameworks simultaneously. Build the infrastructure now, engage in rulemaking, and prepare for a compliance landscape where voluntary and mandatory reporting coexist with different rules, different deadlines, and different legal implications.

Digital advertisement promoting the whitepaper “The State of Application Security in Modern Software,” showing the cover f the whitepaper and text highlighting AppSec risks, AI code threats, API vulnerabilities, and a button to download the whitepaper.

You Might Also Like