Am I a CIRCIA Covered Entity? Scoping Critical-Infrastructure Reach Across 16 Sectors

The question that decides whether CIRCIA applies to you is not “do we report incidents” but “are we a covered entity” — and firms answer it too fast, usually with the wrong half of the test.

Most of the CIRCIA commentary jumps straight to the reporting mechanics — the 72-hour clock, the 24-hour ransom-payment clock, the web form. Useful, but premature. None of it matters until you have settled the prior question: is the firm a covered entity at all, and if so, which parts of it are in scope. That is a scoping exercise, and it is where the misreadings happen. CISA’s own regulatory analysis put the population at more than 300,000 entities, which tells you the drafters did not intend a narrow net. This is the companion to the reporting piece: before you build the muscle, work out whether you are on the pitch.

The test has two parts, and firms only read one

Under the proposed rule, an entity is a covered entity if it operates in one of the sixteen critical-infrastructure sectors and it either exceeds the applicable small-business size standard or meets one of the enumerated sector-based criteria. Read that structure carefully, because the word that catches people is “or”. A firm that comfortably sits below the size threshold — a genuine small business by the Small Business Administration’s own standard — is still a covered entity if it meets a sector-based criterion. Being small does not get you out. It only gets you out of the size limb of the test.

Free · 4 minutes

Do you know where AI is already being used in your business — and what it can see?

Fourteen questions on shadow AI, data exposure, oversight, and governance debt — the gap between how fast AI is arriving and how much control you have over it. Banded finding on screen, full sheet by email.

So the exercise is not “are we big enough to be caught”. It is: are we in a sector, and if so, do we clear the size standard, and separately, do we meet any sector-based criterion. Any one of the latter two is sufficient. Firms that scope themselves out on size alone have answered a third of the question and stopped.

Sector first — and “we’re not critical infrastructure” is rarely true

The sixteen sectors are the ones CISA already recognises: Chemical; Commercial Facilities; Communications; Critical Manufacturing; Dams; Defense Industrial Base; Emergency Services; Energy; Financial Services; Food and Agriculture; Government Facilities; Healthcare and Public Health; Information Technology; Nuclear Reactors, Materials and Waste; Transportation Systems; and Water and Wastewater Systems.

The instinct in the room is to look down that list, not see your industry label, and conclude you are out. That instinct is usually wrong, for two reasons. The Information Technology sector is defined by function, not by whether you call yourself a technology company — a managed service provider, a SaaS platform serving enterprise clients, a maker of operational-technology hardware or identity and access-management software can all sit inside it. And the Communications sector reaches any provider of communications services by wire or radio to the public, business or government. Between IT and Communications alone, a great many firms that would never describe themselves as critical infrastructure are inside the first limb of the test before size is even considered.

Then size, or a sector-based criterion that ignores it

The size limb uses the SBA small-business size standard for your NAICS code. These vary — broadly, somewhere between 100 and 1,500 employees, or roughly $2.25 million to $47 million in annual revenue, depending on the industry. Exceed the standard for your code and you are in on size, full stop.

The sector-based criteria are the part that catches the small and the specialised. They are function-specific, and worth reading against your own activities rather than in the abstract. On the proposed rule, examples include: financial-services entities already required (or that their primary federal regulator intends to require) to report cyber incidents to that regulator; energy entities subject to the NERC Critical Infrastructure Protection standards or that file DOE form OE-417; Defense Industrial Base contractors and subcontractors subject to the DFARS incident-reporting clause at 48 C.F.R. 252.204-7012; hospitals with 100 or more beds and critical-access hospitals; community water systems and publicly owned treatment works serving more than 3,300 people; and IT entities that develop certain software or provide IT services to the federal government. Meet one of these and your size is irrelevant to the outcome.

The traps that quietly widen the net

Three widen scope beyond the naive reading. First, the constituent-part problem: the proposed rule applies to the whole entity if any part of it meets a criterion. A single business line performing a critical-infrastructure function can pull the entire legal entity into scope, which makes the scoping question one for group structure, not just the obviously-regulated division.

Second, you can be dragged in as somebody else’s supplier. If you provide managed services, cloud or software into a covered sector, the sector-based criteria for IT are built to capture exactly that role — the same pull-through logic that European firms will recognise from DORA’s critical third-party designation, where what you supply, not what you are, decides the obligation. Third, the reportable event itself reaches supply-chain compromise: a substantial cyber incident includes unauthorised access arising from a breach at a vendor, managed service provider or cloud platform, so scope and trigger both run through your dependencies.

Scope it now, but scope it as provisional

An honest caveat: this is still a proposed rule. CISA published the notice in April 2024, funding lapses delayed the work, and the final rule is now expected around September 2026, with the reporting obligations commencing after it takes effect rather than on the day it is published. Definitions, thresholds and the sector-based criteria can move between proposal and final text. So do the scoping exercise now, but treat any close call as likely to tighten against you, and re-run it when the final rule lands. This is the discipline of reading a definition on its own terms rather than on your preferred reading of it — the same discipline I have written about for the phrase “critical or important function” in a different regime.

The output you want is a short, evidenced memorandum: which sectors the firm touches, the NAICS codes and size standards that apply, each sector-based criterion tested against a named activity, and a documented conclusion for each legal entity. That memorandum is what lets you decide, deliberately, whether to stand up the reporting capability now or hold. Once you know you are in scope, the reporting build — the 72-hour and 24-hour muscle — becomes a project with a start date rather than a surprise.

The firms that get caught out will not be the ones plainly outside the sixteen sectors. They will be the ones that scoped themselves out on size, never read the sector-based criterion that did not care how small they were, and found out which limb of the test governed only when the clock had already started.

Free interactive tool

Website compliance checklist

What your site has to do, based on what it actually does

Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.

Free interactive tool

Interactive deadline calculator

Check which regulations apply to you and when

Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.

Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.

Most technology problems are not technology problems. They are control problems.

The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.

Full Governance by Sixteen Pillars

Govern your business. Prove your compliance.

A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.

See what's coming