GAO: Federal Cybersecurity Rules Create Potentially Duplicative Reporting Requirements Across Critical Sectors

Key Takeaways

  • The nation’s critical infrastructure is supported by IT systems—most of which are owned by the private sector. Federal agencies have issued many cybersecurity regulations for these systems.
  • The GAO found that 80 of the 117 regulations identified (about 70%) had the same kind of reporting requirement as another regulation. For example, the Securities and Exchange Commission requires publicly traded companies across different sectors to provide cybersecurity plans. However, this may duplicate or conflict with similar requirements in other regulations.
  • The administration intends to issue an implementation plan to streamline cybersecurity regulations.

What GAO Found

GAO identified 117 cybersecurity regulations established by 37 federal agencies for private entities, spanning nine critical infrastructure sectors. Most of those regulations either contain the same kind of reporting requirement applicable to a sector or the same reporting requirement as at least one other regulation, which may lead to duplication. Specifically, 80 of the 117 regulations (about 70 percent) had at least 125 total reporting requirements (see figure), with some regulations requiring multiple types of reporting.

These regulations included sector-specific and cross-sector reporting requirements for private sector entities that may be required to report similar or different cybersecurity information to multiple agencies. For example, a proposed rule from the Department of Homeland Security related to cybersecurity incident reporting by critical infrastructure sectors acknowledged that it may be potentially duplicative with one or more of the 15 existing financial sector regulations that also require such incident reporting. Additionally, cross-sector regulations may duplicate or conflict with regulations focused on a specific sector. For example, one from the Securities and Exchange Commission that requires publicly traded companies across different sectors to provide cybersecurity plans may duplicate or conflict with regulations focused on a specific sector. GAO has ongoing work to obtain additional industry perspectives on federal cybersecurity regulations, including where they perceive overlap and duplication within selected critical infrastructure sectors.

Federal law and the April 2024 National Security Memorandum-22 established the Office of the National Cyber Director (ONCD) as the lead agency responsible for coordinating efforts to streamline, or harmonize, the development and adoption of consistent standards and regulations. ONCD and other federal agencies have initiated actions in recent years to harmonize cybersecurity regulations but have made limited progress. In March 2026, the White House issued a new national cyber strategy which established harmonization and reducing compliance burdens as a priority. According to the strategy, the administration intends to release implementation plans, which could help identify clear lead agency roles, responsibilities, and next steps while enhancing the cybersecurity of the nation’s critical infrastructure.

Why GAO Did This Study

Nearly all the nation’s critical infrastructure are supported by computer-based information systems, and it is vital that public and private sectors work together to protect them. Federal agencies have issued numerous regulations to help protect the nation’s critical infrastructure, which is mostly owned by the private sector. However, according to ONCD, when critical infrastructure sectors are subject to multiple cybersecurity regulations, the result can lead to conflicting guidance, inconsistencies, increased compliance costs and redundancies for regulated entities. Consistency is important to avoid overlap, duplication, or conflicting requirements.

GAO was asked to review federal cybersecurity regulations to identify opportunities for harmonization. This report determines the extent to which federal cybersecurity regulations and requirements are potentially duplicative or conflicting for regulated private sector entities.

GAO reviewed the Electronic Code of Federal Regulations to identify cybersecurity regulations and assess them for potentially duplicative and conflicting reporting requirements. GAO also reviewed available harmonization plans and analyses from ONCD and the Department of Homeland Security. GAO also interviewed relevant officials.

GAO provided a draft of this report to ONCD for review and comment. ONCD did not provide comments on the report.

Read the full GAO report here.

The Government Technology & Services Coalition's Homeland Security Today (HSToday) is the premier news and information resource for the homeland security community, dedicated to elevating the discussions and insights that can support a safe and secure nation. A non-profit magazine and media platform, HSToday provides readers with the whole story, placing facts and comments in context to inform debate and drive realistic solutions to some of the nation’s most vexing security challenges.

Related Articles

Latest Articles