Cybersecurity Regulations: Multiple Sectors Are Subject to Potentially Duplicative Reporting Requirements

Read full story on GAO Reports
Share
Cybersecurity Regulations: Multiple Sectors Are Subject to Potentially Duplicative Reporting Requirements
AI disclosure

Summary

What GAO Found GAO identified 117 cybersecurity regulations established by 37 federal agencies for private entities, spanning nine critical infrastructure sectors. Most of those regulations either contain the same kind of reporting requirement applicable to a sector or the same reporting requirement as at least one other regulation, which may lead to duplication. Specifically, 80 of the 117 regulations (about 70 percent) had at least 125 total reporting requirements (see figure), with some regulations requiring multiple types of reporting. Cybersecurity Regulations with Reporting Requirements, as of June 2026 These regulations included sector-specific and cross-sector reporting requirements for private sector entities that may be required to report similar or different cybersecurity information to multiple agencies. For example, a proposed rule from the Department of Homeland Security related to cybersecurity incident reporting by critical infrastructure sectors acknowledged that it may be potentially duplicative with one or more of the 15 existing financial sector regulations that also require such incident reporting. Additionally, cross-sector regulations may duplicate or conflict with regulations focused on a specific sector. For example, one from the Securities and Exchange Commission that requires publicly traded companies across different sectors to provide cybersecurity plans may duplicate or conflict with regulations focused on a specific sector. GAO has ongoing work to obtain additional industry perspectives on federal cybersecurity regulations, including where they perceive overlap and duplication within selected critical infrastructure sectors. Federal law and the April 2024 National Security Memorandum-22 established the Office of the National Cyber Director (ONCD) as the lead agency responsible for coordinating efforts to streamline, or harmonize, the development and adoption of consistent standards and regulations. ONCD and other federal agencies have initiated actions in recent years to harmonize cybersecurity regulations but have made limited progress. In March 2026, the White House issued a new national cyber strategy which established harmonization and reducing compliance burdens as a priority. According to the strategy, the administration intends to release implementation plans, which could help identify clear lead agency roles, responsibilities, and next steps while enhancing the cybersecurity of the nation’s critical infrastructure. Why GAO Did This Study Nearly all the nation’s critical infrastructure are supported by computer-based information systems, and it is vital that public and private sectors work together to protect them. Federal agencies have issued numerous regulations to help protect the nation’s critical infrastructure, which is mostly owned by the private sector. However, according to ONCD, when critical infrastructure sectors are subject to multiple cybersecurity regulations, the result can lead to conflicting guidance, inconsistencies, increased compliance costs and redundancies for regulated entities. Consistency is important to avoid overlap, duplication, or conflicting requirements. GAO was asked to review federal cybersecurity regulations to identify opportunities for harmonization. This report determines the extent to which federal cybersecurity regulations and requirements are potentially duplicative or conflicting for regulated private sector entities. GAO reviewed the Electronic Code of Federal Regulations to identify cybersecurity regulations and assess them for potentially duplicative and conflicting reporting requirements. GAO also reviewed available harmonization plans and analyses from ONCD and the Department of Homeland Security. GAO also interviewed relevant officials. We provided a draft of this report to ONCD for review and comment. ONCD did not provide comments on the report. For more information, contact David Hinchman at hinchmand@gao.gov.

Original reporting

Open original source

Related coverage

Read full article on GAO Reports

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.