CIRCIA: Why CPA and Law Firms Need to Prepare Now
- Samuel Kader
- Jul 14
- 4 min read

Cyber incident reporting is about to become much more urgent.
The Cyber Incident Reporting for Critical Infrastructure Act of 2022, known as CIRCIA, directs the Cybersecurity and Infrastructure Security Agency to establish mandatory reporting requirements for covered organizations.
Once the final rule is implemented, covered entities will generally be required to report qualifying cyber incidents to CISA within 72 hours and ransomware payments within 24 hours. As of July 2026, CISA is still working toward the final rule. The requirements are not yet in effect, but CPA and law firms should not mistake that for permission to wait.
The time to prepare is now.
CIRCIA Changes the Incident Response Timeline
Seventy-two hours may sound like enough time to report a cyber incident. During an active attack, it is not.
Before an organization can report accurately, it must determine what happened, which systems were affected, whether sensitive information was accessed and whether clients or operations are at risk.
It may also need to coordinate with cybersecurity professionals, legal counsel, cyber insurance providers, law enforcement and other regulators. A firm that begins figuring out these responsibilities after discovering an attack may already be behind.
Will CIRCIA Apply to Every CPA or Law Firm?
Not necessarily. The exact definition of a covered entity will depend on the final rule. The proposed framework focuses on organizations operating within the nation’s critical infrastructure sectors and uses size-based and sector-specific criteria to determine coverage.
However, CPA and law firms should not automatically assume CIRCIA does not affect them.
A firm may directly fall within the final coverage criteria based on its size, services or operations. It may also work with clients in financial services, healthcare, energy, communications, government and other critical sectors.
Those clients may expect their professional service providers to identify and communicate cyber incidents quickly. Contracts, cyber insurance policies and vendor requirements may also create responsibilities even when the firm itself is not directly required to report to CISA.
The question is not only, “Are we covered?”
Firms must also ask, “Could an incident involving our systems affect a covered client, and could we provide the information they need within hours?”
Why CPA Firms Should Pay Attention
CPA firms hold tax records, payroll information, banking details, Social Security numbers and other information that criminals can use for fraud, extortion and identity theft.
They also connect with client accounting platforms, financial systems and cloud applications. A compromised device or account may therefore create consequences far beyond the firm’s own network.
If a cyber incident affects a client operating within critical infrastructure, the CPA firm may need to quickly establish what information was accessed, when the compromise occurred and whether the client’s data was involved.
Without centralized logging, documented escalation procedures and an established incident response team, answering those questions can take far too long.
Why Law Firms Should Pay Attention
Law firms possess privileged communications, litigation strategies, intellectual property, financial records and sensitive information belonging to clients across nearly every industry. An intrusion involving a law firm can affect active litigation, business transactions, regulatory matters and clients that may have their own reporting obligations.
Firms must be prepared to determine which clients and matters were affected, preserve evidence and coordinate legal, technical and client communications without unnecessary delay.
Waiting until an attack occurs to decide who has authority to act can create confusion at the worst possible moment.
CIRCIA Is More Than a Reporting Requirement
CIRCIA is often described as a reporting law, but meeting a short deadline requires much more than completing a form.
Organizations need the ability to detect an incident quickly, investigate it, preserve evidence and escalate it to the right decision-makers. They must also understand how CIRCIA may interact with state breach-notification laws, client contracts, cyber insurance requirements and professional obligations.
In other words, CIRCIA is also an incident readiness requirement.
What CPA and Law Firms Should Do Now
Determine your potential exposure. Review whether your firm or any clients you support could fall within CIRCIA’s final definition of a covered entity.
Update your incident response plan. Clearly document who must be contacted, who has decision-making authority and how legal, technical, insurance and client communications will be coordinated.
Map your reporting obligations. Identify the federal, state, contractual and insurance requirements that could be triggered by an incident.
Improve detection and evidence preservation. Confirm that security logs are being collected, protected and retained long enough to support an investigation.
Review third-party responsibilities. Make sure your vendors and IT providers have clear incident notification and escalation requirements.
Test the plan. Conduct a tabletop exercise to uncover unclear responsibilities, missing information and communication gaps before a real incident occurs.
Preparation Cannot Wait
The final CIRCIA rule will provide greater clarity about exactly which organizations and incidents are covered. Firms should monitor those developments closely, but they do not need to wait to improve their readiness.
The capabilities required by CIRCIA are the same capabilities every CPA and law firm needs during a serious cyber incident: rapid detection, clear escalation, reliable evidence and coordinated communication.
Once an incident begins, there may not be enough time to build those capabilities.
Preparation needs to happen now.
About Shield IT Networks
Shield IT Networks helps CPA firms, law firms and other professional service organizations strengthen their cybersecurity, reduce risk and prepare for evolving regulatory and client requirements.
Our Cyber Readiness Assessment identifies vulnerabilities, security gaps and incident response weaknesses before they become costly problems.
Schedule your Cyber Readiness Assessment today to understand where your firm stands and what needs to be addressed before the next cyber incident occurs.

