Legis Daily

Cyber Incident Reporting for Critical Infrastructure Act of 2021

USA117th CongressHR-5440| House 
| Updated: 10/1/2021
Yvette D. Clarke

Yvette D. Clarke

Democratic Representative

New York

Cosponsors (3)
John Katko (Republican)Andrew R. Garbarino (Republican)Bennie G. Thompson (Democratic)

Homeland Security Committee, Cybersecurity and Infrastructure Protection Subcommittee

  • Introduced
  • In Committee
  • On Floor
  • Passed Chamber
  • Enacted
C yber Incident Reporting for Critical Infrastructure Act of 2021 This bill requires reporting and other actions to address cybersecurity incidents, including ransomware attacks. Entities that own or operate critical infrastructure must report cybersecurity incidents (e.g., ransomware attacks) within specified time frames while other entities may voluntarily report incidents. The Cybersecurity and Infrastructure Security Agency (CISA) must (1) carry out rulemaking to implement the reporting requirements, and (2) establish an office to receive and analyze such reports. To the extent practicable, CISA must align its rules with existing requirements related to the reporting of cybersecurity incidents. The bill limits the use and disclosure of reported information. The information may be shared (subject to protections and restrictions) with federal agencies or to address cybersecurity threats. However, shared information may not be used as a basis for certain regulatory enforcement. Additionally, an entity may not be liable for submitting required reports. Further, reports are not subject to laws governing release of federal or other governmental records. The bill authorizes CISA to take specified action (e.g., issuing subpoenas) if an entity fails to submit a required report. CISA may share subpoenaed information with a regulator or the Department of Justice for regulatory enforcement or criminal prosecution.
View Full Text

Suggested Questions

Get AI-generated questions to help you understand this bill better

Timeline
Sep 30, 2021
Introduced in House
Sep 30, 2021
Referred to the House Committee on Homeland Security.
Oct 1, 2021
Referred to the Subcommittee on Cybersecurity, Infrastructure Protection, and Innovation.
  • September 30, 2021
    Introduced in House


  • September 30, 2021
    Referred to the House Committee on Homeland Security.


  • October 1, 2021
    Referred to the Subcommittee on Cybersecurity, Infrastructure Protection, and Innovation.

Science, Technology, Communications

Related Bills

  • HR 117-4350: National Defense Authorization Act for Fiscal Year 2022

Cyber Incident Reporting for Critical Infrastructure Act of 2021

USA117th CongressHR-5440| House 
| Updated: 10/1/2021
C yber Incident Reporting for Critical Infrastructure Act of 2021 This bill requires reporting and other actions to address cybersecurity incidents, including ransomware attacks. Entities that own or operate critical infrastructure must report cybersecurity incidents (e.g., ransomware attacks) within specified time frames while other entities may voluntarily report incidents. The Cybersecurity and Infrastructure Security Agency (CISA) must (1) carry out rulemaking to implement the reporting requirements, and (2) establish an office to receive and analyze such reports. To the extent practicable, CISA must align its rules with existing requirements related to the reporting of cybersecurity incidents. The bill limits the use and disclosure of reported information. The information may be shared (subject to protections and restrictions) with federal agencies or to address cybersecurity threats. However, shared information may not be used as a basis for certain regulatory enforcement. Additionally, an entity may not be liable for submitting required reports. Further, reports are not subject to laws governing release of federal or other governmental records. The bill authorizes CISA to take specified action (e.g., issuing subpoenas) if an entity fails to submit a required report. CISA may share subpoenaed information with a regulator or the Department of Justice for regulatory enforcement or criminal prosecution.
View Full Text

Suggested Questions

Get AI-generated questions to help you understand this bill better

Timeline
Sep 30, 2021
Introduced in House
Sep 30, 2021
Referred to the House Committee on Homeland Security.
Oct 1, 2021
Referred to the Subcommittee on Cybersecurity, Infrastructure Protection, and Innovation.
  • September 30, 2021
    Introduced in House


  • September 30, 2021
    Referred to the House Committee on Homeland Security.


  • October 1, 2021
    Referred to the Subcommittee on Cybersecurity, Infrastructure Protection, and Innovation.
Yvette D. Clarke

Yvette D. Clarke

Democratic Representative

New York

Cosponsors (3)
John Katko (Republican)Andrew R. Garbarino (Republican)Bennie G. Thompson (Democratic)

Homeland Security Committee, Cybersecurity and Infrastructure Protection Subcommittee

Science, Technology, Communications

Related Bills

  • HR 117-4350: National Defense Authorization Act for Fiscal Year 2022
  • Introduced
  • In Committee
  • On Floor
  • Passed Chamber
  • Enacted