CIRCIA
Covered Cyber Incident reporting for critical infrastructure operators
The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) sets reporting deadlines of 72 hours after a covered entity reasonably believes a covered cyber incident has occurred, and 24 hours after a ransom payment. Reporting duties depend on coverage and application of CISA's implementing rule. Check CISA's CIRCIA guidance for the applicable rule and filing requirements.
Asqav signs submitted agent-action records with ML-DSA-65 (FIPS 204). Producers can use circia_covered_cyber_incident in incident_class to record their incident classification. The tag preserves the producer's assessment; it does not determine legal coverage. Audit Pack export collects recorded receipts for a requested time window, with their available anchors.
The receipt format is described in the IETF Internet-Draft draft-marques-asqav-compliance-receipts. Its CIRCIA mapping describes evidence fields; it is not a CISA reporting format or proof that a filing meets the implementing rule.
Requirements
| Element | Requirement | Asqav binding |
|---|---|---|
| Incident classification | Assess covered-entity and covered-incident status under the applicable implementing rule. | Producers tag records with incident_class: ["circia_covered_cyber_incident"]. Sign-time vocabulary validation checks the token, not the legal classification. |
| 72-hour CISA notice | Where the reporting duty applies, report within 72 hours after reasonable belief that a covered cyber incident occurred. | A checked time anchor constrains when the committed record bytes existed. Incident and discovery times supplied by the producer remain assertions; an anchor does not establish when the producer first reasonably believed an incident occurred. |
| Chain-of-custody | Preserve the incident records and supporting evidence required by the applicable rule. | Per-agent chain links and available RFC 3161 or OpenTimestamps proofs support integrity checks. Audit Pack export packages the recorded window and a signed manifest. Checking a link requires its predecessor; the records alone do not prove that the incident occurred or that the window is complete. |
| Retention | Determine the required retention period from the applicable rule and any preservation request. | CIRCIA mode applies a product retention floor of 731 days, with longer applicable floors taking precedence. This is a product setting, not a statement of the implementing rule's required retention period. Preserve exported signed bytes and verification material for checks after hosted retention ends. |
This page maps receipt capabilities to CIRCIA evidence preparation. It does not establish that reporting duties have taken effect for a particular entity or incident. See CISA for applicability and submission requirements, and the docs for the receipt vocabulary.