In January 2024, a ransomware group hit the Kansas City Area Transportation Authority and demanded $2 million. In August 2025, the Maryland Transit Administration got breached — the attackers claimed Social Security numbers, driver's license data, and home addresses of Maryland residents. The ransom demand: $3.4 million. Neither agency had a 72-hour federal reporting plan. Starting in 2026, that's not just a bad day — it's a federal compliance violation. CIRCIA is coming, and transit agencies are in the crosshairs .
CIRCIA Compliance for Transit Agencies: What the New Cyber Reporting Law Means for Your Bus Fleet
New federal rules require 72-hour breach reporting. Here's your compliance checklist, incident response plan, and software readiness guide — before enforcement hits.
72-Hour Reporting Window
16 Critical Sectors Covered
$4.4M Avg Breach Cost
What Is CIRCIA — and Why Should Bus Fleet Managers Care?
The Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) was signed into law in March 2022. CISA published its proposed rules in April 2024, and the final rule is expected in May 2026 — with enforcement likely beginning 12–18 months after that. Transit agencies fall under the Transportation Systems sector, one of 16 critical infrastructure sectors covered by the law.
Here's the part most fleet managers haven't heard yet: CIRCIA doesn't just apply to your IT department. It applies to any system that touches your operations — your CMMS, your telematics platform, your GPS tracking, your fuel card system, your dispatch software. If a ransomware attack locks your maintenance records or disrupts your route scheduling, that's a reportable incident.
72 Hours
Report any substantial cyber incident to CISA — including loss of system availability, data breaches, or disruption to operations
24 Hours
Report any ransomware payment to CISA — even if the payment isn't connected to a reportable incident
Ongoing
Submit supplemental reports as the incident develops — new data discovered, systems recovered, root cause identified
Get a CMMS with built-in audit trails and access logs — start free
It's Already Happening: Real Cyberattacks on Transit Agencies
This isn't theoretical. Transit agencies are getting hit right now — and the attacks are getting more expensive, more disruptive, and more targeted. Here's the recent track record:
Jan 2024
Kansas City Area Transportation Authority (KCATA)
Ransomware attack disrupted communications, paratransit scheduling, and call centers. Medusa group demanded $2 million. Customers couldn't schedule rides or reach support for days.
Sep 2024
Transport for London (TfL)
Cyberattack exposed financial and personal data of thousands of riders — including bank account details of approximately 5,000 passengers. All 30,000 employees had to reset passwords in person.
Dec 2024
Pittsburgh Regional Transit
Ransomware attack detected December 19 disrupted transit services and internal systems, creating significant operational challenges during holiday travel season.
Aug 2025
Maryland Transit Administration (MTA)
Rhysida ransomware group breached MTA systems, claimed Social Security numbers and driver's license data. Demand: $3.4 million in Bitcoin. Bus tracking and paratransit booking went offline.
The pattern is clear: attackers target transit agencies because they run legacy systems, handle sensitive rider data, and can't afford extended downtime — making them more likely to pay. The average data breach cost in the transportation sector is $4.4 million according to IBM's 2024 Cost of a Data Breach Report. Under CIRCIA, every one of these incidents would require a 72-hour report to CISA.
What Counts as a "Substantial Cyber Incident" for Your Fleet?
Not every phishing email triggers a CIRCIA report. But the threshold is lower than most fleet managers expect. Under the proposed rule, a "substantial cyber incident" includes any event that causes:
Loss of System Availability
Your CMMS goes offline. Dispatch can't assign routes. Drivers can't complete digital DVIRs. Maintenance records are inaccessible.
Data Confidentiality Breach
Employee records, CDL information, fuel card numbers, or rider data is accessed, exfiltrated, or encrypted by an unauthorized party.
Operational Disruption
GPS tracking goes dark. Telematics feeds stop. You can't verify which buses ran which routes or whether safety inspections were completed.
Third-Party Supply Chain Compromise
A vendor's software you rely on gets breached. Phishing campaigns impersonate your telematics or fleet management provider to steal credentials.
That last one is critical for fleet managers. In 2024, phishing campaigns specifically impersonated Samsara and other fleet management platforms to deliver malware to transportation companies. If your CMMS vendor gets compromised and your fleet data is exposed, you are the covered entity that has to report — not the vendor.
See how BusCMMS protects your fleet data with cloud-native security
Your CMMS Is Either Part of Your Defense — or Part of Your Attack Surface
BusCMMS is cloud-native with encrypted data at rest and in transit, role-based access controls, audit logging, and automatic backups. If a breach happens anywhere else in your stack, your maintenance data and compliance records stay intact and audit-ready.
The 72-Hour Compliance Checklist: What to Do When You're Breached
When the clock starts, 72 hours evaporates fast. If you don't have a pre-built incident response plan, you'll spend the first 48 hours figuring out what happened instead of reporting it. Here's the sequence that CIRCIA expects — adapted for transit operations.
0–6 Hrs
Detect & Contain
Isolate affected systems — disconnect compromised machines from the network
Activate your incident response team (internal + external cyber counsel)
Preserve forensic evidence — do NOT reboot or wipe affected machines
Verify backup integrity — can you recover critical fleet operations data?
6–24 Hrs
Assess & Document
Determine scope: which systems, data, and operations are impacted?
Classify incident: does it meet CIRCIA's "substantial" threshold?
If ransomware payment is made or considered — trigger the 24-hour clock
Document everything: timestamps, affected assets, data types, attack vector
24–72 Hrs
Report & Recover
File CIRCIA report via CISA's reporting portal with required fields
Notify state-level agencies per applicable state breach notification laws
Begin system restoration from verified clean backups
Plan supplemental reports as investigation reveals more detail
Get audit-ready access logs and encrypted backups built into your CMMS
Your CMMS Security Checklist: Is Your Fleet Software Helping or Hurting?
Under CIRCIA, your fleet management software is part of your critical infrastructure stack. If it gets compromised, you report. If it can't provide audit trails during an investigation, you have a documentation gap. Here's what your CMMS should have in 2026:
Encryption at Rest & In Transit
Maintenance records, driver info, and fleet data encrypted with TLS 1.3 and AES-256 — unreadable even if intercepted
Role-Based Access Controls (RBAC)
Drivers see inspections. Mechanics see work orders. Only admins see financials. Principle of least privilege enforced by default.
Complete Audit Trail Logging
Every login, data access, edit, and export is timestamped and attributed. This is what CISA investigators ask for first.
Automatic Cloud Backups
If ransomware encrypts your local machines, your fleet data survives in geographically redundant cloud storage. Recovery in hours, not weeks.
No Local-Only Data Storage
Cloud-native means no maintenance database living on a single shop PC that becomes a ransomware hostage. Your data doesn't depend on your hardware.
Red Flag: Desktop-Only CMMS
If your maintenance system runs on a single PC in the shop with no cloud backup, encryption, or access logging — it's the weakest link in your fleet's cyber defense. One ransomware hit and your records are gone.
Book a demo and see how BusCMMS checks every box on this list
Most transit agencies I work with haven't heard of CIRCIA yet. They know about DOT compliance, ADA requirements, and Title VI — but federal cyber reporting isn't on their radar. That's about to change, and the agencies that prepare now will be in far better shape than those who scramble after the first enforcement action.
The single best thing a transit agency can do before CIRCIA takes effect is to get its fleet operations data off of locally-stored systems and into a cloud-native platform with proper access controls and audit logging. That one step eliminates the two biggest risks: data loss from ransomware and the inability to document what happened during an investigation. A CMMS with complete audit trails isn't just a maintenance tool anymore — it's a compliance asset.
The agencies being targeted aren't Fortune 500 companies with dedicated SOC teams. They're 50-bus districts with a fleet manager who also handles HR, procurement, and parent complaints. CIRCIA compliance has to be built into the tools these teams already use — not layered on top as another thing to manage.
CIRCIA is not theoretical. The final rule is expected in May 2026, with enforcement likely beginning in late 2027 or early 2028. CISA estimates over 300,000 entities will be covered — and transit agencies managing bus fleets are squarely in scope. The attacks are already happening: Kansas City, Pittsburgh, Maryland, and London have all been hit in the past 18 months.
Compliance starts with three things: an incident response plan you can execute in 72 hours, fleet software that provides audit trails and encrypted data, and a team that knows what a "substantial incident" looks like before it happens. You don't need a cybersecurity department. You need tools that were built with security as a foundation, not an afterthought.
BusCMMS is cloud-native, encrypted, and audit-logged by design. Your maintenance data, inspection records, and fleet operations history are protected, backed up, and accessible for investigation — whether it's a DOT audit or a CISA inquiry. That's not a feature we added for CIRCIA. It's how the platform was built from day one.
Sign up free and get your fleet data into a CIRCIA-ready platform today
Don't Wait for the First Enforcement Action
Whether CIRCIA enforcement starts in 2027 or 2028, the transit agencies that prepare now will be compliant on day one. BusCMMS gives your fleet encrypted data storage, complete audit logging, role-based access, and cloud-native resilience — built for bus operations, secured for federal compliance.







