Roughly 70% of federal cybersecurity regulations contain redundant reporting requirements, according to the Government Accountability Office, potentially imposing an unnecessary burden on critical infrastructure providers without generating significant benefits for their government overseers.
Thirty-seven agencies have issued 117 cybersecurity rules covering nine infrastructure sectors, GAO said in a report published on Wednesday, and 80 of those rules cover the same ground, requiring reports on cybersecurity incidents, plans or audits. Across those 80 rules, the GAO found 125 distinct requirements.
“Many regulations required multiple types of reporting,” GAO analysts wrote in their report to leaders of the House and Senate homeland-security committees. “When multiple regulations have the same types of reporting requirements, particularly when the requirements affect entities within the same sector or across multiple sectors, those regulations have the potential to be duplicative or conflicting.”
The GAO identified 48 incident-reporting requirements from 27 agencies; 52 plan reporting requirements from 26 agencies; and 25 audit reporting requirements from 15 agencies.
In the incident-reporting realm, firms in the financial-services sector face the most significant potential regulatory overlap, where any given company might have to comply with one of 15 rules from the Treasury Department, the Federal Trade Commission, the Federal Deposit Insurance Corporation or other agencies.
When it comes to reporting on cybersecurity plans, federal contractors might have to share the same plan information with each of their agency customers separately. And in the highly diverse transportation sector, whose regulators have issued seven rules requiring plan reporting, “regulations affecting all sectors may duplicate or conflict with regulations focused on a specific sector,” according to the GAO.
In terms of regulations requiring companies to provide the results of third-party audits or assessments, the GAO warned that companies “may be required to provide duplicative compliance data or conduct multiple compliance audits that could vary in scope, depth, and methodology to comply with multiple regulations.”
The GAO report on regulatory overlap comes as the Cybersecurity and Infrastructure Security Agency is finalizing a rule required by the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) that is expected to apply significant incident-reporting requirements to a vast cross-sector swath of critical infrastructure.
Without regulatory harmonization, CIRCIA will make the redundancy problem worse, the GAO said, particularly in sectors like financial services that are already heavily regulated. Beyond redundancy, CIRCIA could also create contradictions, analysts wrote: “The potential exists for CIRCIA to have varying requirements for when financial services sector entities are to report cybersecurity incidents, including what to report and how soon sector entities are expected to notify federal agencies.”
The GAO said it was collecting infrastructure operators’ feedback on the federal regulatory thicket and planned to issue a report with their perspectives in the fall.
Stalled harmonization efforts
Both the Biden and Trump administrations have promised to rationalize the regulatory environment by eliminating duplicative rules and modernizing regulatory text, but the GAO found that agencies have not made significant progress on that front.
The interagency Cybersecurity Forum for Independent and Executive Branch Regulators has been dormant since late 2024, the Department of Homeland Security has not provided any evidence that it is implementing its own Cyber Incident Reporting Council’s recommendations and the Trump administration has dragged its feet on issuing a plan to implement President Donald Trump’s national cybersecurity strategy.
“In addition to establishing implementation plans, it will be important for [the Office of the National Cyber Director (ONCD)] and other involved agencies to prioritize and follow-through on previously initiated efforts to harmonize cybersecurity regulations,” GAO analysts wrote. “Doing so will help achieve the goal of reducing potentially burdensome requirements on the private sector while enhancing the cybersecurity of the nation’s critical infrastructure.”
The GAO shared its report with ONCD to solicit feedback and comments, but the office declined to comment.