CIRCIA

Covered Cyber Incident reporting for critical infrastructure operators

The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) sets reporting deadlines of 72 hours after a covered entity reasonably believes a covered cyber incident has occurred, and 24 hours after a ransom payment. Reporting duties depend on coverage and application of CISA's implementing rule. Check CISA's CIRCIA guidance for the applicable rule and filing requirements.

Asqav signs submitted agent-action records with ML-DSA-65 (FIPS 204). Producers can use circia_covered_cyber_incident in incident_class to record their incident classification. The tag preserves the producer's assessment; it does not determine legal coverage. Audit Pack export collects recorded receipts for a requested time window, with their available anchors.

The receipt format is described in the IETF Internet-Draft draft-marques-asqav-compliance-receipts. Its CIRCIA mapping describes evidence fields; it is not a CISA reporting format or proof that a filing meets the implementing rule.

Requirements

Element Requirement Asqav binding
Incident classification Assess covered-entity and covered-incident status under the applicable implementing rule. Producers tag records with incident_class: ["circia_covered_cyber_incident"]. Sign-time vocabulary validation checks the token, not the legal classification.
72-hour CISA notice Where the reporting duty applies, report within 72 hours after reasonable belief that a covered cyber incident occurred. A checked time anchor constrains when the committed record bytes existed. Incident and discovery times supplied by the producer remain assertions; an anchor does not establish when the producer first reasonably believed an incident occurred.
Chain-of-custody Preserve the incident records and supporting evidence required by the applicable rule. Per-agent chain links and available RFC 3161 or OpenTimestamps proofs support integrity checks. Audit Pack export packages the recorded window and a signed manifest. Checking a link requires its predecessor; the records alone do not prove that the incident occurred or that the window is complete.
Retention Determine the required retention period from the applicable rule and any preservation request. CIRCIA mode applies a product retention floor of 731 days, with longer applicable floors taking precedence. This is a product setting, not a statement of the implementing rule's required retention period. Preserve exported signed bytes and verification material for checks after hosted retention ends.

This page maps receipt capabilities to CIRCIA evidence preparation. It does not establish that reporting duties have taken effect for a particular entity or incident. See CISA for applicability and submission requirements, and the docs for the receipt vocabulary.