The Cyber Incident Reporting for Critical Infrastructure Act of 2022 regulations are expected to be finalized this fall. If your organization qualifies as critical infrastructure, you'll face new mandatory cyber incident reporting requirements. The challenge? Many organizations aren't sure whether they're included.
This isn't a question you can postpone until the final rule is released. Determining your status now gives you time to build reporting processes, train your team, and establish vendor protocols. Waiting means scrambling when the clock starts.
What You Need Before Starting
Before assessing your organization's status, gather these materials:
Internal documentation:
- Current business descriptions for all operating units
- List of products and services you provide
- Customer profiles (government vs. commercial, sector breakdown)
- Any existing regulatory filings that describe your business activities
Reference materials:
- Presidential Policy Directive 21 (defines the 16 critical infrastructure sectors)
- Your industry's sector-specific agency guidance, if available
- Current CISA critical infrastructure definitions
Key stakeholders:
- Someone from each business unit who understands day-to-day operations
- Your regulatory compliance lead
- Legal counsel familiar with your corporate structure
- IT security team lead
You don't need a cybersecurity framework assessment yet. This is a scoping exercise, not a technical audit.
Step-by-Step Implementation
Step 1: Map Your Activities to the 16 Sectors
Organizations must determine if they operate within one of 16 critical infrastructure sectors. Start by reviewing Presidential Policy Directive 21's sector definitions. Don't rely on your industry label. A "technology company" might provide chemical manufacturing software. A "consulting firm" might operate power grid monitoring systems.
Create a spreadsheet with three columns: Business Activity, Sector Match (if any), and Confidence Level (high/medium/low). List every distinct thing your organization does. Be specific. "We provide IT services" is too broad. "We manage patient data systems for hospitals" is specific enough to evaluate.
Common sectors that catch organizations by surprise:
- Healthcare and Public Health: You don't need to be a hospital. Medical device manufacturers, pharmacy benefit managers, and health data processors often qualify.
- Information Technology: This covers managed service providers, cloud infrastructure operators, and software that supports other critical sectors.
- Financial Services: Payment processors, insurance companies, and firms handling securities transactions typically fall here.
- Communications: Internet service providers, telecommunications carriers, and broadcast networks.
Step 2: Assess Dependency Relationships
Critical infrastructure isn't just about what you do. It's about who depends on you. Ask:
- Do other critical infrastructure entities rely on your services to operate?
- Would your operational disruption cascade into another sector?
- Are you in the supply chain for critical infrastructure operations?
A manufacturer supplying specialized components to water treatment facilities might qualify even if manufacturing itself isn't their primary sector match. Document these dependency relationships. They matter during regulatory interpretation.
Step 3: Evaluate Ownership and Control Structures
Your corporate structure affects scope determination. Map out:
- Parent-subsidiary relationships
- Joint ventures and partnerships
- Facilities you operate but don't own
- Services you provide under contract to government entities
If you operate critical infrastructure assets on behalf of another organization, you might have reporting obligations even if you're not the asset owner. Conversely, owning a small stake in a critical infrastructure entity doesn't automatically bring you into scope.
Step 4: Consult Your Sector-Specific Agency
Each critical infrastructure sector has a designated federal agency. If you think you might qualify:
- Identify your sector-specific agency (CISA maintains the current list)
- Review any guidance they've published about scope and definitions
- Consider requesting an informal opinion if your status is unclear
Don't skip this step because you're worried about drawing attention. Regulators prefer organizations that ask questions over those that guess wrong and fail to comply.
Step 5: Document Your Determination
Write down your conclusion and the reasoning behind it. Include:
- Which sectors you considered and why
- Specific business activities that do or don't match sector definitions
- Any dependency relationships you identified
- Stakeholders you consulted
- Date of determination
This documentation serves two purposes. First, it shows good faith effort if regulators later question your determination. Second, it creates a baseline for reassessment when your business changes.
Validation: How to Verify It Works
You've made a determination. Now test it:
Peer review: Have someone unfamiliar with your analysis review your sector mapping. Can they follow your logic? Do they reach the same conclusion?
Scenario testing: Pick a hypothetical cyber incident (ransomware attack, data breach, system outage). Walk through what you'd need to report and to whom under the new regulations. If you can't answer these questions, revisit your scoping analysis.
Boundary cases: Identify your most ambiguous business activities. If those activities grew significantly, would your determination change? If you can't answer clearly, you need more precision in your analysis.
External validation: If you're part of an industry association, compare notes with peers. Are similar organizations reaching similar conclusions? Significant divergence suggests you might be missing something.
Maintenance and Ongoing Tasks
Your critical infrastructure status isn't static. Set up quarterly reviews that check:
Business changes:
- New products or services launched
- Acquisitions or divestitures
- New customer relationships, especially government contracts
- Changes in what your technology supports
Regulatory updates:
- Revised sector definitions from CISA or sector-specific agencies
- New guidance documents or FAQs
- Enforcement actions that clarify scope questions
Annual formal reassessment: Once a year, repeat the full scoping analysis. Assign this to a specific person with a specific deadline. Don't let it become something everyone assumes someone else is handling.
If your determination changes from "not in scope" to "in scope," you'll need to build incident reporting capabilities quickly. That means establishing monitoring systems, defining what constitutes a reportable incident, creating reporting templates, and training your security team. Starting this work after you're already obligated puts you at immediate compliance risk.
Organizations that struggle most with new regulations are those that treat scoping as a one-time checkbox exercise. The ones that succeed build it into their regular compliance rhythm. Make your determination now, but plan to keep making it.



