Skip to main content
S 2875 117th Congress Senate Science, Technology, Communications Advanced technology and technological innovations Business records Civil actions and liability Computer security and identity theft Computers and information technology Congressional oversight Currency Digital media Fraud offenses and financial crimes Government information and archives Government studies and investigations Intergovernmental relations Right of privacy State and local government operations Terrorism

Cyber Incident Reporting Act of 2021

Introduced: September 28, 2021 Introduced by: Peters, Gary C. Democratic · Michigan See on congress.gov
 Everywhere this bill has been 5 steps
Introduced
In committee
Reported out
Passed House
Passed Senate
To President
Became law
Dec 13, 2022
Placed on Senate Legislative Calendar under General Orders. Calendar No. 633.
Dec 13, 2022
Committee on Homeland Security and Governmental Affairs. Reported by Senator Peters with an amendment in the nature of a substitute. With written report No. 117-249.
Oct 6, 2021
Committee on Homeland Security and Governmental Affairs. Ordered to be reported with an amendment in the nature of a substitute favorably.
Sep 28, 2021
Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
Sep 28, 2021
Introduced in Senate
 Plain-English summary Congressional Research Service

Cyber Incident Reporting Act of 2021

This bill requires reporting and other actions to address cybersecurity incidents, including ransomware attacks.

Entities that own or operate critical infrastructure must report cyber incidents and ransom payments within specified time frames while other entities may voluntarily report incidents. The Cybersecurity and Infrastructure Security Agency (CISA) must establish an office to receive and analyze such reports.

The bill limits the use and disclosure of reported information. The information may be shared (subject to protections) with federal agencies or to address cybersecurity threats. However, shared information may not be used as a basis for certain regulatory enforcement. Additionally, an entity may not be liable for submitting required reports. Further, reports do not constitute waivers of applicable protections against disclosure (e.g., attorney-client privilege) and are not subject to laws governing release of federal records.

The bill authorizes CISA to take specified action (e.g., issuing subpoenas) if an entity fails to submit a required report. CISA may share subpoenaed information with a regulator or the Department of Justice for regulatory enforcement or criminal prosecution.

A federal agency must share any information it receives about cyber attacks with CISA.

The bill also establishes (1) an interagency council to standardize federal reporting of cybersecurity threats, (2) a task force on ransomware attacks, and (3) a pilot program to identify information systems vulnerable to ransomware attacks.

What's happening now December 13, 2022

Placed on Senate Legislative Calendar under General Orders. Calendar No. 633.

 Committees of jurisdiction 1