CIRCIA 72/24 Reporting Readiness Pack
Know in ten minutes whether CIRCIA covers you, decide in one call whether an incident is reportable, and have the report drafted inside the first day — the two-gate covered-entity worksheet, the four-prong decision tree, the 72/24 clock runbook, and a report pre-fill with a JSON Schema twin for your SOAR. Built on the NPRM, with a free update when the final rule publishes.
What this actually gives you
- CISA estimates roughly 300,000 covered entities across the 16 sectors, and most do not think of themselves as critical infrastructure — water utilities, clinics, food and agriculture, regional transport, mid-size manufacturers and their MSPs.
- The hard part is not the report. It is knowing whether you owe one at 2 a.m. while the incident is still running — a two-gate covered-entity test, then four prongs and the exclusions.
- 72 hours for a substantial incident, 24 hours for a ransom payment, with a report pre-fill so Section A is complete before anything happens.
- Built on the NPRM and honest about it: everything still open is marked “verify final” rather than presented as settled, and the updated edition is free when the final rule publishes.
CIRCIA is the first US federal law to require all critical-infrastructure entities to report significant cyber incidents to CISA on a clock — 72 hours for a substantial incident, 24 hours for a ransom payment — with civil enforcement behind it. CISA estimates roughly 300,000 covered entities across the 16 sectors, and most of them do not think of themselves as critical infrastructure. Water utilities, clinics, food and agriculture, regional transport, mid-size manufacturers and the MSPs that serve them are all in scope.
The hard part is not the report. It is knowing whether you owe one, at 2 a.m., while the incident is still running. That determination is what this pack automates.
01 Covered-Entity Determination Worksheet (XLSX) — the two-gate test: the SBA size standard for your sector, then the 28 sector-based criteria. Returns COVERED / WATCH / NOT COVERED per legal entity, with a roster for groups. WATCH fires when you are within 20% of the size gate, because that is the threshold CISA has signalled it may raise.
02 Is It Reportable? (DOCX + printable PDF + Markdown) — incident, then exclusions, then the four prongs, then the reasonable-belief test, then the ransom branch. One page, printable, designed to be walked in a single call rather than read.
03 72/24 Clock Runbook (DOCX) — who owns the determination, the T-0 to T+72 timeline, the supplemental-report standard, submission mechanics, and the evidence-preservation and legal-hold steps that satisfy the two-year retention requirement.
04 CIRCIA Report Pre-Fill (DOCX + report-schema.json) — every field the proposed rule requires for incident, ransom, joint and supplemental reports, so Section A is already filled before anything happens. The JSON Schema twin drops into a SOAR or ticketing system so the fields are collected as your responders work.
05 Harmonization Matrix (XLSX) — 16 regimes and their clocks side by side. The 'Your clocks' sheet computes every deadline from a single T-0, which is the only way to sequence CIRCIA against SEC 8-K, state breach law and your sector regulator without missing one.
06 Ransom Payment 24-Hour Checklist (DOCX) — the three gates before, at and within 24 hours of a payment: OFAC screening, insurer consent, counsel, and the contract clause that has to already be in your negotiator agreement.
07 Tabletop Injects (DOCX) — hospital ransomware with a payment decision, a water OT intrusion, an MSP-borne manufacturer wipe, with after-action metrics.
08 Practitioner Guide (PDF) — what is fixed in statute versus proposed in the rule, coverage, the prongs, the clocks, enforcement, multi-regime sequencing, a 30-day plan and an FAQ.
Built on the NPRM, and honest about it. The reporting duties come from 6 U.S.C. §681; the coverage detail comes from CISA's proposed 6 CFR Part 226. Everything still open is marked 'verify final' in the files rather than presented as settled. When the final rule publishes you get the updated edition free, and the changelog will list every change — re-download always serves the current version.
Pairs with the Incident Response Runbook Library for the response itself, and the EU Cyber Resilience Act Workbook if you also ship product into the EU.
A practitioner's toolset, not legal advice. CIRCIA submissions carry 18 U.S.C. §1001 exposure — have counsel review before you file.
Also available in 3 bundles
This product is sold on its own and as part of a set. If you need more than this one, the set is cheaper than buying the parts.
The Regime Clocks
Four regulators, four clocks, one incident — the First 72 Hours Command Kit plus the CIRCIA, SEC 8-K and NYDFS Part 500 kits. The problem is sequencing: the confidential federal report precedes the public 8-K, and only the SEC clock waits for a materiality determination. 19% off buying them separately.
Defense Supplier Pack
The CMMC self-assessment and SPRS score you are certifying to, the provider holding your admin rights, and the federal incident clock underneath both. What a DIB contractor is actually accountable for while Phase 2 is suspended. 19% off buying separately.
Critical Infrastructure Complete
The plant, the regulators above it, the federal reporting duty, the drill and the board layer — five products covering an operator end to end, from the vendor VPN that should already be off to the evidence log a director keeps. 25% off buying separately.
What's included
- Complete Library (.zip) — all formats included — fully editable
- Instant download after purchase
- Free updates — re-download when we release new versions
- Practitioner License: unlimited client use (vCISO / MSP)
More from the CISO Marketplace ecosystem
Choose your license:
- Secure checkout via Stripe
- All major cards accepted
- 30-day satisfaction guarantee