Compare with different regulatory event:

Description

Signed Cyber Incident Reporting for Critical Infrastructure Act of 2022

On 15 March 2022, the United States President signed into law the Cyber Incident Reporting for Critical Infrastructure Act of 2022. The Act was incorporated in the Consolidated Appropriations Act of 2022 and was previously part of the Strengthening American Cybersecurity Act of 2022. The Act establishes a Cyber Incident Review Office in the Cybersecurity and Infrastructure Security Agency (CISA) and requires critical infrastructure controllers and civilian federal agencies to report any significant cyberattack to the CISA within 72 hours. Ransomware attacks to critical infrastructure must be reported within 24 hours.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
cross-cutting
Implementation Level
national
Government Branch
executive
Government Body
central government

Complete timeline of this policy change

Hide details
2022-02-08
under deliberation

The Strengthening American Cybersecurity Act of 2022 (S. 3600) is introduced in the US Senate. The …

2022-03-01
under deliberation

The "Strengthening American Cybersecurity Act of 2022" (S. 3600) is adopted by the US Senate and pa…

2022-03-15
in force

On 15 March 2022, the United States President signed into law the Cyber Incident Reporting for Crit…