---
kind: "section"
citation: "6 U.S.C. § 681b"
title: "6"
title_heading: "Domestic Security"
number: "681b"
heading: "Required reporting of certain cyber incidents"
release: "119-102"
date: "2026-07-12"
url: "https://uscodex.org/usc/6/681b"
units:
  - "Chapter 1 — Homeland Security Organization"
  - "Subchapter XVIII — Cybersecurity and Infrastructure Security Agency"
  - "Part D — Cyber Incident Reporting"
---

# §681b. Required reporting of certain cyber incidents

- (a) **In general—**
  - (1) **Covered cyber incident reports—**
    - (A) **In general—** A [covered entity](/usc/6/681.md?p=4) that experiences a [covered cyber incident](/usc/6/681.md?p=3) shall report the [covered cyber incident](/usc/6/681.md?p=3) to the [Agency](/usc/6/650.md?p=1) not later than 72 hours after the [covered entity](/usc/6/681.md?p=4) reasonably believes that the [covered cyber incident](/usc/6/681.md?p=3) has occurred.
    - (B) **Limitation—** The [Director](/usc/6/650.md?p=10) may not require reporting under [subparagraph (A)](#a-1-A) any earlier than 72 hours after the [covered entity](/usc/6/681.md?p=4) reasonably believes that a [covered cyber incident](/usc/6/681.md?p=3) has occurred.
  - (2) **Ransom payment reports—**
    - (A) **In general—** A [covered entity](/usc/6/681.md?p=4) that makes a [ransom payment](/usc/6/681.md?p=8) as the result of a [ransomware attack](/usc/6/650.md?p=22) against the [covered entity](/usc/6/681.md?p=4) shall report the payment to the [Agency](/usc/6/650.md?p=1) not later than 24 hours after the [ransom payment](/usc/6/681.md?p=8) has been made.
    - (B) **Application—** The requirements under [subparagraph (A)](#a-2-A) shall apply even if the [ransomware attack](/usc/6/650.md?p=22) is not a [covered cyber incident](/usc/6/681.md?p=3) subject to the reporting requirements under [paragraph (1)](#a-1).
  - (3) **Supplemental reports—** A [covered entity](/usc/6/681.md?p=4) shall promptly submit to the [Agency](/usc/6/650.md?p=1) an update or supplement to a previously submitted [covered cyber incident](/usc/6/681.md?p=3) report if substantial new or different information becomes available or if the [covered entity](/usc/6/681.md?p=4) makes a [ransom payment](/usc/6/681.md?p=8) after submitting a [covered cyber incident](/usc/6/681.md?p=3) report required under [paragraph (1)](#a-1), until such date that such [covered entity](/usc/6/681.md?p=4) notifies the [Agency](/usc/6/650.md?p=1) that the [covered cyber incident](/usc/6/681.md?p=3) at issue has concluded and has been fully mitigated and resolved.
  - (4) **Preservation of information—** Any [covered entity](/usc/6/681.md?p=4) subject to requirements of paragraph [(1)](#a-1), [(2)](#a-2), or [(3)](#a-3) shall preserve data relevant to the [covered cyber incident](/usc/6/681.md?p=3) or [ransom payment](/usc/6/681.md?p=8) in accordance with procedures established in the final rule issued pursuant to [subsection (b)](#b).
  - (5) **Exceptions—**
    - (A) **Reporting of covered cyber incident with ransom payment—** If a [covered entity](/usc/6/681.md?p=4) is the victim of a [covered cyber incident](/usc/6/681.md?p=3) and makes a [ransom payment](/usc/6/681.md?p=8) prior to the 72 hour requirement under [paragraph (1)](#a-1), such that the reporting requirements under paragraphs [(1)](#a-1) and [(2)](#a-2) both apply, the [covered entity](/usc/6/681.md?p=4) may submit a single report to satisfy the requirements of both paragraphs in accordance with procedures established in the final rule issued pursuant to [subsection (b)](#b).
    - (B) **Substantially similar reported information—**
      - (i) **In general—** Subject to the limitation described in [clause (ii)](#a-5-B-ii), where the [Agency](/usc/6/650.md?p=1) has an agreement in place that satisfies the requirements of [section 681g(a) of this title](/usc/6/681g.md?p=a), the requirements under paragraphs [(1)](#a-1), [(2)](#a-2), and [(3)](#a-3) shall not apply to a [covered entity](/usc/6/681.md?p=4) required by law, regulation, or contract to report substantially similar information to another [Federal agency](/usc/6/677a.md?p=4) within a substantially similar timeframe.
      - (ii) **Limitation—** The exemption in [clause (i)](#a-5-B-i) shall take effect with respect to a [covered entity](/usc/6/681.md?p=4) once an [agency](/usc/6/650.md?p=1) agreement and [sharing](/usc/6/650.md?p=26) mechanism is in place between the [Agency](/usc/6/650.md?p=1) and the respective [Federal agency](/usc/6/677a.md?p=4), pursuant to [section 681g(a) of this title](/usc/6/681g.md?p=a).
      - (iii) **Rules of construction—** Nothing in this paragraph shall be construed to—
        - (I) exempt a [covered entity](/usc/6/681.md?p=4) from the reporting requirements under [paragraph (3)](#a-3) unless the supplemental report also meets the requirements of clauses (i) and (ii) of this paragraph;[^1]
        - (II) prevent the [Agency](/usc/6/650.md?p=1) from contacting an [entity](/usc/6/301c.md?p=2) submitting information to another [Federal agency](/usc/6/677a.md?p=4) that is provided to the [Agency](/usc/6/650.md?p=1) pursuant to [section 681g of this title](/usc/6/681g.md); or
        - (III) prevent an [entity](/usc/6/301c.md?p=2) from communicating with the [Agency](/usc/6/650.md?p=1).
    - (C) **Domain name system—** The requirements under paragraphs [(1)](#a-1), [(2)](#a-2) and [(3)](#a-3) shall not apply to a [covered entity](/usc/6/681.md?p=4) or the [functions](/usc/6/101.md?p=9) of a [covered entity](/usc/6/681.md?p=4) that the [Director](/usc/6/650.md?p=10) determines constitute [critical infrastructure](/usc/6/101.md?p=4) owned, operated, or governed by multi-stakeholder organizations that develop, implement, and enforce policies concerning the Domain Name System, such as the Internet Corporation for Assigned Names and Numbers or the Internet Assigned Numbers Authority.
  - (6) **Manner, timing, and form of reports—** Reports made under paragraphs [(1)](#a-1), [(2)](#a-2), and [(3)](#a-3) shall be made in the manner and form, and within the time period in the case of reports made under [paragraph (3)](#a-3), prescribed in the final rule issued pursuant to [subsection (b)](#b).
  - (7) **Effective date—** Paragraphs [(1)](#a-1) through [(4)](#a-4) shall take effect on the dates prescribed in the final rule issued pursuant to [subsection (b)](#b).
- (b) **Rulemaking—**
  - (1) **Notice of proposed rulemaking—** Not later than 24 months after March 15, 2022, the [Director](/usc/6/650.md?p=10), in consultation with [Sector Risk Management Agencies](/usc/6/650.md?p=23), the [Department](/usc/6/641.md?p=1) of Justice, and other [Federal agencies](/usc/6/677a.md?p=4), shall publish in the Federal Register a notice of proposed rulemaking to implement [subsection (a)](#a).
  - (2) **Final rule—** Not later than 18 months after publication of the notice of proposed rulemaking under [paragraph (1)](#b-1), the [Director](/usc/6/650.md?p=10) shall issue a final rule to implement [subsection (a)](#a).
  - (3) **Subsequent rulemakings—**
    - (A) **In general—** The [Director](/usc/6/650.md?p=10) is authorized to issue regulations to amend or revise the final rule issued pursuant to [paragraph (2)](#b-2).
    - (B) **Procedures—** Any subsequent rules issued under [subparagraph (A)](#b-3-A) shall comply with the requirements under [chapter 5](/usc/5/chptI/ch5.md) of title 5, including the issuance of a notice of proposed rulemaking under [section 553](/usc/6/553.md) of such title.
- (c) **Elements—** The final rule issued pursuant to [subsection (b)](#b) shall be composed of the following elements:
  - (1) A clear description of the types of [entities](/usc/6/301c.md?p=2) that constitute [covered entities](/usc/6/681.md?p=4), based on—
    - (A) the consequences that disruption to or compromise of such an [entity](/usc/6/301c.md?p=2) could cause to national security, economic security, or public health and safety;
    - (B) the likelihood that such an [entity](/usc/6/301c.md?p=2) may be targeted by a malicious cyber actor, including a foreign country; and
    - (C) the extent to which damage, disruption, or unauthorized access to such an [entity](/usc/6/301c.md?p=2), including the accessing of sensitive cybersecurity vulnerability information or penetration testing tools or techniques, will likely enable the disruption of the reliable operation of [critical infrastructure](/usc/6/101.md?p=4).
  - (2) A clear description of the types of substantial [cyber incidents](/usc/6/681.md?p=5) that constitute [covered cyber incidents](/usc/6/681.md?p=3), which shall—
    - (A) at a minimum, require the occurrence of—
      - (i) a [cyber incident](/usc/6/681.md?p=5) that leads to substantial [loss](/usc/6/444.md?p=5) of confidentiality, integrity, or availability of such [information system](/usc/6/650.md?p=14) or network, or a serious impact on the safety and resiliency of operational systems and processes;
      - (ii) a disruption of business or industrial operations, including due to a denial of service attack, [ransomware attack](/usc/6/650.md?p=22), or exploitation of a zero day vulnerability, against[^2]
        - (I) an [information system](/usc/6/650.md?p=14) or network; or
        - (II) an operational technology system or process; or
      - (iii) unauthorized access or disruption of business or industrial operations due to [loss](/usc/6/444.md?p=5) of service facilitated through, or caused by, a compromise of a [cloud service provider](/usc/6/650.md?p=3), [managed service provider](/usc/6/650.md?p=18), or other third-party data hosting provider or by a [supply chain compromise](/usc/6/650.md?p=28);
    - (B) consider—
      - (i) the sophistication or novelty of the tactics used to perpetrate such a [cyber incident](/usc/6/681.md?p=5), as well as the type, volume, and sensitivity of the data at issue;
      - (ii) the number of individuals directly or indirectly affected or potentially affected by such a [cyber incident](/usc/6/681.md?p=5); and
      - (iii) potential impacts on industrial control systems, such as supervisory control and data acquisition systems, distributed control systems, and programmable logic controllers; and
    - (C) exclude—
      - (i) any event where the [cyber incident](/usc/6/681.md?p=5) is perpetrated in good faith by an [entity](/usc/6/301c.md?p=2) in response to a specific request by the owner or operator of the [information system](/usc/6/650.md?p=14); and
      - (ii) the threat of disruption as extortion, as described in [section 681(14)(A)](/usc/6/681.md)[^3] of this title.
  - (3) A requirement that, if a [covered cyber incident](/usc/6/681.md?p=3) or a [ransom payment](/usc/6/681.md?p=8) occurs following an exempted threat described in [paragraph (2)(C)(ii)](#c-2-C-ii), the [covered entity](/usc/6/681.md?p=4) shall comply with the requirements in this part in reporting the [covered cyber incident](/usc/6/681.md?p=3) or [ransom payment](/usc/6/681.md?p=8).
  - (4) A clear description of the specific required contents of a report pursuant to [subsection (a)(1)](#a-1), which shall include the following information, to the extent applicable and available, with respect to a [covered cyber incident](/usc/6/681.md?p=3):
    - (A) A description of the [covered cyber incident](/usc/6/681.md?p=3), including—
      - (i) identification and a description of the function of the affected [information systems](/usc/6/650.md?p=14), networks, or devices that were, or are reasonably believed to have been, affected by such [cyber incident](/usc/6/681.md?p=5);
      - (ii) a description of the unauthorized access with substantial [loss](/usc/6/444.md?p=5) of confidentiality, integrity, or availability of the affected [information system](/usc/6/650.md?p=14) or network or disruption of business or industrial operations;
      - (iii) the estimated date range of such [incident](/usc/6/650.md?p=12); and
      - (iv) the impact to the operations of the [covered entity](/usc/6/681.md?p=4).
    - (B) Where applicable, a description of the vulnerabilities exploited and the security defenses that were in place, as well as the tactics, techniques, and procedures used to perpetrate the [covered cyber incident](/usc/6/681.md?p=3).
    - (C) Where applicable, any identifying or contact information related to each actor reasonably believed to be responsible for such [cyber incident](/usc/6/681.md?p=5).
    - (D) Where applicable, identification of the category or categories of information that were, or are reasonably believed to have been, accessed or acquired by an unauthorized person.
    - (E) The name and other information that clearly identifies the [covered entity](/usc/6/681.md?p=4) impacted by the [covered cyber incident](/usc/6/681.md?p=3), including, as applicable, the [State](/usc/6/101.md?p=17) of incorporation or formation of the [covered entity](/usc/6/681.md?p=4), trade names, legal names, or other identifiers.
    - (F) Contact information, such as telephone number or electronic mail address, that the [Agency](/usc/6/650.md?p=1) may use to contact the [covered entity](/usc/6/681.md?p=4) or an authorized agent of such [covered entity](/usc/6/681.md?p=4), or, where applicable, the service provider of such [covered entity](/usc/6/681.md?p=4) acting with the express permission of, and at the direction of, the [covered entity](/usc/6/681.md?p=4) to assist with compliance with the requirements of this part.
  - (5) A clear description of the specific required contents of a report pursuant to [subsection (a)(2)](#a-2), which shall be the following information, to the extent applicable and available, with respect to a [ransom payment](/usc/6/681.md?p=8):
    - (A) A description of the [ransomware attack](/usc/6/650.md?p=22), including the estimated date range of the attack.
    - (B) Where applicable, a description of the vulnerabilities, tactics, techniques, and procedures used to perpetrate the [ransomware attack](/usc/6/650.md?p=22).
    - (C) Where applicable, any identifying or contact information related to the actor or actors reasonably believed to be responsible for the [ransomware attack](/usc/6/650.md?p=22).
    - (D) The name and other information that clearly identifies the [covered entity](/usc/6/681.md?p=4) that made the [ransom payment](/usc/6/681.md?p=8) or on whose behalf the payment was made.
    - (E) Contact information, such as telephone number or electronic mail address, that the [Agency](/usc/6/650.md?p=1) may use to contact the [covered entity](/usc/6/681.md?p=4) that made the [ransom payment](/usc/6/681.md?p=8) or an authorized agent of such [covered entity](/usc/6/681.md?p=4), or, where applicable, the service provider of such [covered entity](/usc/6/681.md?p=4) acting with the express permission of, and at the direction of, that [covered entity](/usc/6/681.md?p=4) to assist with compliance with the requirements of this part.
    - (F) The date of the [ransom payment](/usc/6/681.md?p=8).
    - (G) The [ransom payment](/usc/6/681.md?p=8) demand, including the type of [virtual currency](/usc/6/681.md?p=10) or other commodity requested, if applicable.
    - (H) The [ransom payment](/usc/6/681.md?p=8) instructions, including information regarding where to send the payment, such as the [virtual currency address](/usc/6/681.md?p=11) or physical address the [funds](/usc/6/677a.md?p=5) were requested to be sent to, if applicable.
    - (I) The amount of the [ransom payment](/usc/6/681.md?p=8).
  - (6) A clear description of the types of data required to be preserved pursuant to [subsection (a)(4)](#a-4), the period of time for which the data is required to be preserved, and allowable uses, processes, and procedures.
  - (7) Deadlines and criteria for submitting supplemental reports to the [Agency](/usc/6/650.md?p=1) required under [subsection (a)(3)](#a-3), which shall—
    - (A) be established by the [Director](/usc/6/650.md?p=10) in consultation with the [Council](/usc/6/681.md?p=2);
    - (B) consider any existing regulatory reporting requirements similar in scope, purpose, and timing to the reporting requirements to which such a [covered entity](/usc/6/681.md?p=4) may also be subject, and make efforts to harmonize the timing and contents of any such reports to the maximum extent practicable;
    - (C) balance the need for situational awareness with the ability of the [covered entity](/usc/6/681.md?p=4) to conduct [cyber incident](/usc/6/681.md?p=5) response and investigations; and
    - (D) provide a clear description of what constitutes substantial new or different information.
  - (8) Procedures for—
    - (A) [entities](/usc/6/301c.md?p=2), including third parties pursuant to [subsection (d)(1)](#d-1), to submit reports required by paragraphs [(1)](#a-1), [(2)](#a-2), and [(3)](#a-3) of subsection (a), including the manner and form thereof, which shall include, at a minimum, a concise, user-friendly web-based form;
    - (B) the [Agency](/usc/6/650.md?p=1) to carry out—
      - (i) the enforcement provisions of [section 681d of this title](/usc/6/681d.md), including with respect to the issuance, service, withdrawal, referral process, and enforcement of subpoenas, appeals and due process procedures;
      - (ii) other available enforcement mechanisms including acquisition, suspension and debarment procedures; and
      - (iii) other aspects of noncompliance;
    - (C) implementing the exceptions provided in [subsection (a)(5)](#a-5); and
    - (D) protecting privacy and civil liberties consistent with processes adopted pursuant to [section 1504(b) of this title](/usc/6/1504.md?p=b) and anonymizing and safeguarding, or no longer retaining, information received and disclosed through [covered cyber incident](/usc/6/681.md?p=3) reports and [ransom payment](/usc/6/681.md?p=8) reports that is known to be personal information of a specific individual or information that identifies a specific individual that is not directly related to a [cybersecurity threat](/usc/6/650.md?p=8-A).
  - (9) Other procedural measures directly necessary to implement [subsection (a)](#a).
- (d) **Third party report submission and ransom payment—**
  - (1) **Report submission—** A [covered entity](/usc/6/681.md?p=4) that is required to submit a [covered cyber incident](/usc/6/681.md?p=3) report or a [ransom payment](/usc/6/681.md?p=8) report may use a third party, such as an [incident](/usc/6/650.md?p=12) response company, insurance provider, service provider, [Information Sharing and Analysis Organization](/usc/6/650.md?p=13), or law firm, to submit the required report under [subsection (a)](#a).
  - (2) **Ransom payment—** If a [covered entity](/usc/6/681.md?p=4) impacted by a [ransomware attack](/usc/6/650.md?p=22) uses a third party to make a [ransom payment](/usc/6/681.md?p=8), the third party shall not be required to submit a [ransom payment](/usc/6/681.md?p=8) report for itself under [subsection (a)(2)](#a-2).
  - (3) **Duty to report—** Third-party reporting under this subparagraph[^4] does not relieve a [covered entity](/usc/6/681.md?p=4) from the duty to comply with the requirements for [covered cyber incident](/usc/6/681.md?p=3) report or [ransom payment](/usc/6/681.md?p=8) report submission.
  - (4) **Responsibility to advise—** Any third party used by a [covered entity](/usc/6/681.md?p=4) that knowingly makes a [ransom payment](/usc/6/681.md?p=8) on behalf of a [covered entity](/usc/6/681.md?p=4) impacted by a [ransomware attack](/usc/6/650.md?p=22) shall advise the impacted [covered entity](/usc/6/681.md?p=4) of the responsibilities of the impacted [covered entity](/usc/6/681.md?p=4) regarding reporting [ransom payments](/usc/6/681.md?p=8) under this section.
- (e) **Outreach to covered entities—**
  - (1) **In general—** The [Agency](/usc/6/650.md?p=1) shall conduct an outreach and education campaign to inform likely [covered entities](/usc/6/681.md?p=4), [entities](/usc/6/301c.md?p=2) that offer or advertise as a service to customers to make or facilitate [ransom payments](/usc/6/681.md?p=8) on behalf of [covered entities](/usc/6/681.md?p=4) impacted by [ransomware attacks](/usc/6/650.md?p=22) and other appropriate [entities](/usc/6/301c.md?p=2) of the requirements of paragraphs [(1)](#a-1), [(2)](#a-2), and [(3)](#a-3) of subsection (a).
  - (2) **Elements—** The outreach and education campaign under [paragraph (1)](#e-1) shall include the following:
    - (A) An overview of the final rule issued pursuant to [subsection (b)](#b).
    - (B) An overview of mechanisms to submit to the [Agency](/usc/6/650.md?p=1) [covered cyber incident](/usc/6/681.md?p=3) reports, [ransom payment](/usc/6/681.md?p=8) reports, and information relating to the disclosure, retention, and use of [covered cyber incident](/usc/6/681.md?p=3) reports and [ransom payment](/usc/6/681.md?p=8) reports under this section.
    - (C) An overview of the protections afforded to [covered entities](/usc/6/681.md?p=4) for complying with the requirements under paragraphs [(1)](#a-1), [(2)](#a-2), and [(3)](#a-3) of subsection (a).
    - (D) An overview of the steps taken under [section 681d of this title](/usc/6/681d.md) when a [covered entity](/usc/6/681.md?p=4) is not in compliance with the reporting requirements under [subsection (a)](#a).
    - (E) Specific outreach to cybersecurity vendors, [cyber incident](/usc/6/681.md?p=5) response providers, cybersecurity insurance [entities](/usc/6/301c.md?p=2), and other [entities](/usc/6/301c.md?p=2) that may support [covered entities](/usc/6/681.md?p=4).
    - (F) An overview of the privacy and civil liberties requirements in this part.
  - (3) **Coordination—** In conducting the outreach and education campaign required under [paragraph (1)](#e-1), the [Agency](/usc/6/650.md?p=1) may coordinate with—
    - (A) the [Critical Infrastructure](/usc/6/101.md?p=4) Partnership Advisory [Council](/usc/6/681.md?p=2) established under [section 451 of this title](/usc/6/451.md);
    - (B) [Information Sharing and Analysis Organizations](/usc/6/650.md?p=13);
    - (C) trade associations;
    - (D) information [sharing](/usc/6/650.md?p=26) and analysis [centers](/usc/6/681.md?p=1);
    - (E) sector coordinating [councils](/usc/6/681.md?p=2); and
    - (F) any other [entity](/usc/6/301c.md?p=2) as determined appropriate by the [Director](/usc/6/650.md?p=10).
- (f) **Exemption—** Sections [3506(c)](/usc/44/3506.md?p=c), [3507](/usc/44/3507.md), [3508](/usc/44/3508.md), and [3509](/usc/44/3509.md) of title 44 shall not apply to any action to carry out this section.
- (g) **Rule of construction—** Nothing in this section shall affect the authorities of the Federal Government to implement the requirements of Executive Order 14028 (86 Fed. Reg. 26633; relating to improving the nation’s cybersecurity), including changes to the Federal Acquisition Regulations and remedies to include suspension and debarment.
- (h) **Savings provision—** Nothing in this section shall be construed to supersede or to abrogate, modify, or otherwise limit the authority that is vested in any officer or any [agency](/usc/6/650.md?p=1) of the [United States](/usc/6/101.md?p=19-A) Government to regulate or take action with respect to the cybersecurity of an [entity](/usc/6/301c.md?p=2).

## Footnotes

[^1]: So in original. Probably should be “subparagraph”.
[^2]: So in original. Probably should be followed by a dash.
[^3]: See References in Text note below.
[^4]: So in original. Probably should be “subsection”.

## Source credit

(Pub. L. 107–296, title XXII, § 2242, as added Pub. L. 117–103, div. Y, § 103(a)(2), Mar. 15, 2022, 136 Stat. 1042.)

## Notes

### Editorial Notes

### References in Text

Section 681(14)(A) of this title, referred to in subsec. (c)(2)(C)(ii), was repealed by section 7143(b)(2)(N)(v) of Pub. L. 117–263. See section 650(22)(A) of this title. References to terms defined in this chapter deemed to be references to those terms as defined in section 650 of this title, see section 7143(f)(2) of Pub. L. 117–263, set out as a Rule of Construction note under section 650 of this title.

Executive Order 14028, referred to in subsec. (g), is Ex. Ord. No. 14028, May 12, 2021, 86 F.R. 26633, which is set out as a note under section 3551 of Title 44, Public Printing and Documents.
