Us Code § 681g - Federal sharing of incident reports

Full text of Us Code United States Code § 681g — Federal sharing of incident reports, with citation guidance and answers to common questions.

§ 681g. Federal sharing of incident reports

(a) Cyber incident reporting sharing

(1) In general

Notwithstanding any other provision of law or regulation, any Federal agency, including any independent establishment (as defined in section 104 of title 5), that receives a report from an entity of a cyber incident, including a ransomware attack, shall provide the report to the Agency as soon as possible, but not later than 24 hours after receiving the report, unless a shorter period is required by an agreement made between the Department of Homeland Security (including the Cybersecurity and Infrastructure Security Agency) and the recipient Federal agency. The Director shall share and coordinate each report pursuant to section 681a(b) of this title, as added by section 103 of this division.

(2) Rule of construction

The requirements described in paragraph (1) and section 681e(d) of this title, as added by section 103 of this division, may not be construed to be a violation of any provision of law or policy that would otherwise prohibit disclosure or provision of information within the executive branch.

(3) Protection of information

The Director shall comply with any obligations of the recipient Federal agency described in paragraph (1) to protect information, including with respect to privacy, confidentiality, or information security, if those obligations would impose greater protection requirements than this division or the amendments made by this division.

(4) Effective date

This subsection shall take effect on the effective date of the final rule issued pursuant to section 681b(b) of this title, as added by section 103 of this division.

(5) Agency agreements

(A) In general

The Agency and any Federal agency, including any independent establishment (as defined in section 104 of title 5), that receives incident reports from entities, including due to ransomware attacks, shall, as appropriate, enter into a documented agreement to establish policies, processes, procedures, and mechanisms to ensure reports are shared with the Agency pursuant to paragraph (1).

(B) Availability

To the maximum extent practicable, each documented agreement required under subparagraph (A) shall be made publicly available.

(C) Requirement

The documented agreements required by subparagraph (A) shall require reports be shared from Federal agencies with the Agency in such time as to meet the overall timeline for covered entity reporting of covered cyber incidents and ransom payments established in section 681b of this title, as added by section 103 of this division.

(b) Harmonizing reporting requirements

The Secretary of Homeland Security, acting through the Director, shall, in consultation with the Cyber Incident Reporting Council described in section 681f of this title, as added by section 103 of this division, to the maximum extent practicable—

(1) periodically review existing regulatory requirements, including the information required in such reports, to report incidents and ensure that any such reporting requirements and procedures avoid conflicting, duplicative, or burdensome requirements; and

(2) coordinate with appropriate Federal partners and regulatory authorities that receive reports relating to incidents to identify opportunities to streamline reporting processes, and where feasible, facilitate interagency agreements between such authorities to permit the sharing of such reports, consistent with applicable law and policy, without impacting the ability of the Agency to gain timely situational awareness of a covered cyber incident or ransom payment.

(Pub. L. 117–103, div. Y, §104, Mar. 15, 2022, 136 Stat. 1054.)


Editorial Notes

References in Text

Section 103 of this division, referred to in text, is section 103 of div. Y of Pub. L. 117–103, which enacted this part and amended section 659 of this title.

Codification

Section was enacted as part of the Cyber Incident Reporting for Critical Infrastructure Act of 2022, and also as part of the Consolidated Appropriations Act, 2022, and not as part of the Homeland Security Act of 2002 which comprises this chapter.


Statutory Notes and Related Subsidiaries

Definitions

For definitions of terms used in this section, see section 102 of div. Y of Pub. L. 117–103, which is set out as a note under section 665j of this title.

CHAPTER 2—NATIONAL EMERGENCY MANAGEMENT

Sec.
701.
Definitions.

        

SUBCHAPTER I—PERSONNEL PROVISIONS

Part A—Federal Emergency Management Agency Personnel

711.
Surge Capacity Force.

        

Part B—Emergency Management Capabilities

721.
Evacuation preparedness technical assistance.
722.
Urban Search and Rescue Response System.
723.
Metropolitan Medical Response Grant Program.
724.
Logistics.
725.
Prepositioned equipment program.
726.
Basic life supporting first aid and education.
727.
Improvements to information technology systems.
728.
Disclosure of certain information to law enforcement agencies.

        

SUBCHAPTER II—COMPREHENSIVE PREPAREDNESS SYSTEM

Part A—National Preparedness System

741.
Definitions.
742.
National preparedness.
743.
National preparedness goal.
744.
Establishment of national preparedness system.
745.
National planning scenarios.
746.
Target capabilities and preparedness priorities.
747.
Equipment and training standards.
748.
Training and exercises.
748a.
Prioritization of facilities.
749.
Comprehensive assessment system.
750.
Remedial action management program.
751.
Federal response capability inventory.
752.
Reporting requirements.
753.
Federal preparedness.
754.
Use of existing resources.

        

Part B—Additional Preparedness

761.
Emergency Management Assistance Compact grants.
762.
Emergency management performance grants program.
763.
Transfer of Noble Training Center.
763a.
Training for Federal Government, foreign governments, or private entities.
764.
National exercise simulation center.
765.
Real property transactions.

        

Part C—Miscellaneous Authorities

771.
National Disaster Recovery Strategy.
772.
National Disaster Housing Strategy.
773.
Individuals with disabilities guidelines.
774.
Reunification.
775.
National Emergency Family Registry and Locator System.
776.
Individuals and households pilot program.
777.
Public assistance pilot program.

        

Part D—Prevention of Fraud, Waste, and Abuse

791.
Advance contracting.
792.
Repealed.
793.
Oversight and accountability of Federal disaster expenditures.
794.
Limitation on length of certain noncompetitive contracts.
795.
Fraud, waste, and abuse controls.
796.
Registry of disaster response contractors.
797.
Fraud prevention training program.

        

Part E—Authorization of Appropriations

811.
Authorization of appropriations.

        

Part F—Global Catastrophic Risk Management

821.
Definitions.
822.
Assessment of global catastrophic risk.
823.
Report required.
824.
Enhanced catastrophic incident annex.
825.
Rules of construction.

        

About This Section

6 U.S.C. § 681g is part of Title 6 of the United States Code. The United States Code is the official codification of federal statutes maintained by the Office of the Law Revision Counsel of the U.S. House of Representatives. Congress amends the Code through new public laws, which are eventually incorporated into the relevant title.

This section may be cited in legal writing as 6 U.S.C. § 681g. For the most current official text, including any recent amendments, use the official source links below. Do not rely on this page as the sole authority for legal citation or litigation.

How to Read This Statute

Statutes are organized by title, chapter, section, and subsection. Pay attention to words like "shall," "may," "and," and "or," because they determine whether a requirement is mandatory or permissive and whether multiple conditions must all be met. Historical notes and amendments often appear at the end of a section.

Using This Page

This page is intended for research and educational use. Lawyers, students, journalists, and compliance professionals can use it as a starting point, but should always verify the current text through an official government source before relying on it for legal advice, filings, or compliance decisions.

Sources

Source: official Us Code text · Last verified 2026-08-27

Frequently Asked Questions About Us Code § 681g

What does United States Code § 681g cover?

Section 681g ("Federal sharing of incident reports") is part of the United States Code, the codified statutory law of Us Code. It sets out the legal rule or procedure described in the text above. Statutes are amended regularly, so always verify against the official source.

How do I cite Us Code § 681g?

A common citation format is "United States Code § 681g" (Us Code). Legal writing may require the code abbreviation, section number, and year or edition. Match the style required by your court, professor, or publisher.

Is this the official text of Us Code law?

No. This page is for research and education and may not include the most recent amendments. For official current law, check the Us Code official source linked on this page or consult a licensed Us Code attorney.

How does Us Code § 681g apply to my situation?

Statutes are interpreted in context, and application depends on your specific facts. Only a licensed attorney in Us Code can advise on how this section applies to you. Contact your state or local bar association for a referral.

Sources & Verification

Not legal advice. Verify against the official source and consult a licensed attorney in Us Code.