Duties and compliance
Covered providers must follow the reporting and preservation framework in federal law; the REPORT Act expanded both its reach and its consequences.
Core requirements
- Report qualifying apparent offensesWhen the statutory actual-knowledge threshold is met, covered providers must make a CyberTipline report as soon as reasonably possible.
- Include expanded offensesThe reportable categories now include apparent child sex trafficking involving a minor and online enticement, in addition to covered child sexual abuse material offenses.
- Preserve reported contentsProviders must preserve the reported contents for one year and may voluntarily preserve them longer for qualifying child-protection purposes.
- Use appropriate securityPreservation must be consistent with the most recent NIST Cybersecurity Framework or its successor.
Penalties for a provider’s reporting failure
For a first knowing and willful failure to report, the Act authorizes fines of up to $850,000 for providers with at least 100 million monthly active users and up to $600,000 for smaller providers. For later violations, the respective maximums rise to $1,000,000 and $850,000.
Use the controlling text
Coverage, exceptions, knowledge standards, definitions, remedies, and effective dates must be evaluated from the full statutory or legislative text. Agency guidance can explain requirements but does not replace the text.