Skip to main content
Image coming soon

CIRCIA Cyber Incident Reporting Evidence & Implementation Kit

$249.00
Adding to cart… The item has been added
CIRCIA · Cyber Incident Reporting for Critical Infrastructure · Evidence & Implementation Kit
Meet CIRCIA's reporting duties, without decoding covered-entity scope and the deadlines yourself.
Every CIRCIA obligation handed to you as an adopt-ready control, from the covered-entity scope and the 72-hour incident report through the 24-hour ransom payment report and report contents to data preservation, with the evidence CISA and auditors examine.
Report-ready in a weekend, not a quarter.

Here is the honest situation. CIRCIA requires covered entities in the sixteen critical infrastructure sectors to report a covered cyber incident to CISA within 72 hours and any ransom payment within 24 hours, with detailed report contents, supplemental reports as the incident develops, and preservation of the relevant data and records. The report protections, the substantially-similar-reporting exception and the CISA enforcement powers all have to be understood in advance, because the clock starts the moment you reasonably believe an incident occurred. Building the detection, escalation and reporting playbook to meet those timelines, and evidencing it, is real work, and an entity that misses the 72-hour or 24-hour window is exactly where covered entities fall short.

This Kit removes the guesswork. It is every CIRCIA obligation written as an adopt-ready control you personalize in a weekend, with the evidence CISA and auditors examine.

What you get, the moment you buy

29
Obligations as adopt-ready controls. Every CIRCIA obligation, from the covered-entity scope and the 72-hour incident report through the 24-hour ransom payment report, the report contents, supplemental reports and data preservation, written so you personalize and apply it.
29
Evidence-they-examine checklists. For each control, exactly what CISA and auditors examine, plus where covered entities fall short, so you close the gap first.
1
Incident Reporting Control Matrix, pre-built. Every obligation in a working spreadsheet, ready to record status, owner and evidence location.
1
Gap & Readiness Assessment. Score each obligation and the workbook returns your readiness as a single percentage, and exactly what to fix next.

Grounded in the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) and the CISA implementing rule, with the covered-entity scope, the 72-hour covered cyber incident report, the 24-hour ransom payment report, the report contents, data preservation and the report protections called out. Editable Word and Excel files.

The clock starts before you have all the facts
CIRCIA's 72-hour window runs from when you reasonably believe a covered incident occurred, not when the investigation finishes, and a ransom payment must be reported within 24 hours regardless. An entity that waits for certainty misses the deadline. This Kit builds the detection, escalation and reporting playbook that hits the timelines, with the evidence.

What one control looks like

This is determining covered-entity status across the critical infrastructure sectors, where CIRCIA begins. All 29 are built to this depth.

CIRCIA-1 Determine covered entity status by sector COVERED ENTITY
Put this control in place

Assess and document whether [your organization name] operates within one of the sixteen critical infrastructure sectors and meets the sector-based criteria or size-based thresholds set out in the CISA implementing rule, recording the sector, the specific criterion triggered, and the analysis supporting the conclusion so scope decisions are defensible and repeatable.

Practitioner note.

Reassess covered entity status whenever the business acquires new lines, sectors, or crosses a size threshold.

Evidence CISA and auditors examine
  • Documented sector determination memorandum
  • Mapping of operations to the sixteen critical infrastructure sectors
  • Size and revenue threshold calculation worksheet
  • Sign-off by legal or compliance leadership
Common finding they raise: Organizations assume they are out of scope without documenting the sector and size analysis that supports the conclusion.

Why this is not another template pack

  • The evidence is the point. A report you cannot show you filed on time is a compliance failure. This tells you what CISA and auditors examine and where entities fall short, for every obligation.
  • The deadlines and contents built in. The 72-hour incident report, the 24-hour ransom report, the required contents and supplemental reports are written into the controls, the substance CIRCIA requires.
  • Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
  • It compounds. CIRCIA aligns with the NIST CSF incident response and other sector reporting regimes, so this work feeds your wider incident response program.

Who buys this

Covered entities across the critical infrastructure sectors, and the security, legal and incident response leads who own reporting. Whether it is a first readiness pass or a playbook refresh, you save weeks and walk in with the scope, deadlines and evidence structured.

By the end of the weekend you will have
✓  An adopt-ready control for all 29 obligations
✓  A completed incident reporting control matrix
✓  The evidence CISA and auditors examine
✓  Your 72-hour and 24-hour reporting playbook in place
✓  A readiness percentage and a fix list
✓  The missed-deadline risk designed out

Common questions

Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.

Is this legal advice? No. It is an implementation toolkit grounded in CIRCIA and the CISA rule. For a specific matter consult counsel; this gets your controls and playbook in order fast.

What are the two deadlines? 72 hours to report a covered cyber incident, and 24 hours to report a ransom payment. Both are built as controls.

Does it cover the report protections? Yes. The liability protections, privilege, non-use and the substantially-similar-reporting exception are their own control group.

What if it is not for me? A 30-day money-back guarantee.

Do not wait for certainty and miss the reporting window.
Every CIRCIA obligation is fast to adopt with the Kit. It is instant, and it is guaranteed.
Add it to your cart and be report-ready this weekend.

Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com