On September 12, 2022, the U.S. Cybersecurity and Infrastructure Security Agency (“CISA”) published a Request for Information, seeking public comment on how to structure implementing regulations for reporting requirements under the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (“CIRCIA”).  Written comments are requested on or before November 14, 2022 and may be submitted through the Federal eRulemaking Portal: http://www.regulations.gov.

Overview of CIRCIA.  CIRCIA was signed into law on March 15, 2022 and establishes two cyber incident reporting requirements for covered critical infrastructure entities:

  1. A 24-hour requirement to report any ransomware payments to CISA; and
  2. A 72-hour requirement to report all covered cyber incidents to CISA.

These requirements will take effect upon the issuance of implementing regulations from the Director of CISA.  The Act directs CISA to issue a Notice of Proposed Rulemaking (“NPRM”) within 24 months of the date of enactment to implement the Act’s requirements, and to issue a final rule within 18 months of issuing the NPRM.

Request for Information.  CISA is seeking public comment through its Request for Information on potential aspects of the proposed regulation prior to publication of the NPRM.  According to the Request for Information, CISA is particularly interested in public input regarding:

  • Definitions, criteria, and the scope of regulatory coverage, including the scope of covered entities and covered incidents;
  • Report contents and submission procedures, including when timing requirements for various reporting requirements will begin to run;
  • Other incident reporting requirements and security vulnerability information sharing; and
  • Additional policies, procedures, and requirements.

Looking Ahead.  As noted, written comments are requested on or before November 14, 2022. Submissions received after that date may not be considered.  Comments may be submitted through the Federal eRulemaking Portal: http://www.regulations.gov.

CISA will also be hosting public listening sessions throughout the comment period as an additional means for interested parties to provide input. 

Print:
Email this postTweet this postLike this postShare this post on LinkedIn
Photo of Ashden Fein Ashden Fein

Ashden Fein is co-chair of Covington’s Data Privacy and Cybersecurity Practice. He advises clients on cybersecurity and national security matters, including crisis management and incident response, risk management and governance, government and internal investigations, and regulatory compliance. Ashden also serves as lead counsel…

Ashden Fein is co-chair of Covington’s Data Privacy and Cybersecurity Practice. He advises clients on cybersecurity and national security matters, including crisis management and incident response, risk management and governance, government and internal investigations, and regulatory compliance. Ashden also serves as lead counsel in criminal, civil, and internal investigations involving cybersecurity, insider risk, and U.S. national security issues.

Ashden regularly counsels clients on preparing for and responding to cyber-based attacks, assessing security controls and practices for the protection of data and systems, developing and implementing cybersecurity risk management and governance programs, and complying with federal and state regulatory requirements. Ashden frequently supports clients as the lead investigator and crisis manager for global cyber and data security incidents, including data breaches involving personal data, advanced persistent threats targeting intellectual property across industries, state-sponsored theft of sensitive U.S. government information, extortion and ransomware, and destructive attacks.

Ashden also assists clients from across industries with leading internal investigations and responding to government inquiries related to U.S. national security and insider risks. He frequently represents government contractors in False Claims Act matters involving cybersecurity and national security. Additionally, he advises aerospace, defense, and intelligence contractors on security compliance under U.S. national security laws and regulations including, among others, the National Industrial Security Program (NISPOM), U.S. government cybersecurity regulations, FedRAMP, and requirements related to supply chain security.

Before joining Covington, Ashden served on active duty in the U.S. Army as a Military Intelligence officer and prosecutor specializing in cybercrime and national security investigations and prosecutions — to include serving as the lead trial lawyer in the prosecution of Private Chelsea (Bradley) Manning for the unlawful disclosure of classified information to Wikileaks. Ashden is a retired U.S. Army officer.

Photo of Micaela McMurrough Micaela McMurrough

Micaela McMurrough serves as co-chair of Covington’s global and multi-disciplinary Technology Group, as co-chair of the Artificial Intelligence and Internet of Things (IoT) initiative. In her practice, she has represented clients in high-stakes antitrust, patent, trade secrets, contract, and securities litigation, and other…

Micaela McMurrough serves as co-chair of Covington’s global and multi-disciplinary Technology Group, as co-chair of the Artificial Intelligence and Internet of Things (IoT) initiative. In her practice, she has represented clients in high-stakes antitrust, patent, trade secrets, contract, and securities litigation, and other complex commercial litigation matters, and she regularly represents and advises domestic and international clients on cybersecurity and data privacy issues, including cybersecurity investigations and cyber incident response. Micaela has advised clients on data breaches and other network intrusions, conducted cybersecurity investigations, and advised clients regarding evolving cybersecurity regulations and cybersecurity norms in the context of international law.

In 2016, Micaela was selected as one of thirteen Madison Policy Forum Military-Business Cybersecurity Fellows. She regularly engages with government, military, and business leaders in the cybersecurity industry in an effort to develop national strategies for complex cyber issues and policy challenges. Micaela previously served as a United States Presidential Leadership Scholar, principally responsible for launching a program to familiarize federal judges with various aspects of the U.S. national security structure and national intelligence community.

Prior to her legal career, Micaela served in the Military Intelligence Branch of the United States Army. She served as Intelligence Officer of a 1,200-member maneuver unit conducting combat operations in Afghanistan and was awarded the Bronze Star.

Photo of Matthew Harden Matthew Harden

Matthew Harden is a cybersecurity and litigation associate in Covington’s New York office. He advises clients on cybersecurity and national security matters, including cybersecurity incident response, crisis management, enterprise risk management and governance, internal investigations, and regulatory compliance.

Matthew helps clients prepare for…

Matthew Harden is a cybersecurity and litigation associate in Covington’s New York office. He advises clients on cybersecurity and national security matters, including cybersecurity incident response, crisis management, enterprise risk management and governance, internal investigations, and regulatory compliance.

Matthew helps clients prepare for and respond to cybersecurity incidents and data security events. He advises on cybersecurity investigations, counsels on incident response strategy, and helps clients assess legal, regulatory, and litigation risks arising from data breaches, network intrusions, ransomware, insider threats, digital threats, and other cyber matters.

Matthew counsels clients on cybersecurity and information security governance. He assists with drafting, designing, and assessing enterprise cybersecurity policies, information security programs, incident response plans, and related procedures. His work includes advising on cybersecurity and privacy compliance obligations, emerging cybersecurity regulations, and legal risks associated with artificial intelligence (AI), Internet of Things (IoT) technologies, and connected products.

As part of his litigation and investigations practice, Matthew draws on his cybersecurity experience to advise clients in high-stakes disputes, internal investigations, and regulatory matters. He represents government contractors in False Claims Act matters involving cybersecurity and national security. He also maintains an active pro bono practice focused on veterans’ rights.

Matthew serves as a Judge Advocate in the U.S. Coast Guard Reserve.