Skip to main content
HR 5440 117th Congress House Science, Technology, Communications

Cyber Incident Reporting for Critical Infrastructure Act of 2021

Introduced: September 30, 2021 Introduced by: Clarke, Yvette D. Democratic · New York See on congress.gov
This bill died when the 117th Congress ended
It never became law before the 117th Congress (2021–2022) adjourned, and bills don't carry over to the next Congress. It would have to be reintroduced. You can still save it for reference, but it won't receive updates.
 Everywhere this bill has been 3 steps
Introduced
In committee
Reported out
Passed House
Passed Senate
To President
Became law
Oct 1, 2021
Referred to the Subcommittee on Cybersecurity, Infrastructure Protection, and Innovation.
Sep 30, 2021
Referred to the House Committee on Homeland Security.
Sep 30, 2021
Introduced in House
 Ask about this bill AI · grounded in the bill text

Have a question about what this bill does? Ask in plain English; the answer is drawn from the bill's actual text and official record, and it'll tell you when something isn't in the text rather than guess.

AI answers can be imperfect; always confirm against the full bill text.

 Plain-English summary Congressional Research Service

Cyber Incident Reporting for Critical Infrastructure Act of 2021

This bill requires reporting and other actions to address cybersecurity incidents, including ransomware attacks.

Entities that own or operate critical infrastructure must report cybersecurity incidents (e.g., ransomware attacks) within specified time frames while other entities may voluntarily report incidents. The Cybersecurity and Infrastructure Security Agency (CISA) must (1) carry out rulemaking to implement the reporting requirements, and (2) establish an office to receive and analyze such reports. To the extent practicable, CISA must align its rules with existing requirements related to the reporting of cybersecurity incidents.

The bill limits the use and disclosure of reported information. The information may be shared (subject to protections and restrictions) with federal agencies or to address cybersecurity threats. However, shared information may not be used as a basis for certain regulatory enforcement. Additionally, an entity may not be liable for submitting required reports. Further, reports are not subject to laws governing release of federal or other governmental records.

The bill authorizes CISA to take specified action (e.g., issuing subpoenas) if an entity fails to submit a required report. CISA may share subpoenaed information with a regulator or the Department of Justice for regulatory enforcement or criminal prosecution.

What's happening now October 1, 2021

Referred to the Subcommittee on Cybersecurity, Infrastructure Protection, and Innovation.

 Related & companion bills 1
 Bill text 1 version

Source documents hosted by congress.gov.

 Committees of jurisdiction 2
Cite this page click to expand
APA
U.S. Congress. (2026). H.R. 5440: Cyber Incident Reporting for Critical Infrastructure Act of 2021. 117th Congress. Open America. https://openamerica.io/bill/117-HR-5440/
MLA
"H.R. 5440: Cyber Incident Reporting for Critical Infrastructure Act of 2021." 117th Congress, 2026, Open America, https://openamerica.io/bill/117-HR-5440/.
Bluebook (legal)
H.R. 5440, 117th Cong. (2026), https://openamerica.io/bill/117-HR-5440/.
Markdown link
[H.R. 5440: Cyber Incident Reporting for Critical Infrastructure Act of 2021](https://openamerica.io/bill/117-HR-5440/)
Report a problem