A recent report by the U.S. Government Accountability Office (GAO) shows that about 70% of federal cybersecurity regulations contain redundant reporting requirements, which may impose unnecessary burdens on critical infrastructure operators without yielding significant benefits for their government regulators.

In a report released Wednesday, the GAO stated that 37 agencies have issued 117 cybersecurity rules covering nine infrastructure sectors, with 80 of these rules addressing the same content and requiring submissions of cybersecurity incident, plan, or audit reports. Among these 80 rules, the GAO identified 125 distinct specific requirements.

"Many regulations require multiple types of reports," GAO analysts wrote in the report submitted to leaders of the House and Senate Homeland Security Committees. "When multiple regulations have the same type of reporting requirement, especially when these requirements affect entities in the same sector or across sectors, these regulations may be duplicative or conflicting." The full report is available at:Full GAO Report

Specifically, the GAO identified 48 incident reporting requirements from 27 agencies, 52 plan reporting requirements from 26 agencies, and 25 audit reporting requirements from 15 agencies.

In the area of incident reporting, companies in the financial services industry face the most significant potential regulatory overlap. Any single company may be subject to one or more of 15 rules from the Department of the Treasury, the Federal Trade Commission, the Federal Deposit Insurance Corporation, or other agencies.

Regarding cybersecurity plan reporting, federal contractors may need to submit the same plan information separately to each agency client. In the highly diversified transportation sector, regulators have issued seven rules requiring plan reports. The GAO noted that "regulations affecting all industries may duplicate or conflict with sector-specific regulations."

For regulations requiring companies to provide third-party audit or assessment results, the GAO warned that companies "may be required to provide duplicative compliance data or undergo multiple compliance audits, the scope, depth, and methodology of which may vary by regulation."

This GAO report on regulatory overlap comes as the Cybersecurity and Infrastructure Security Agency (CISA) is finalizing a rule required by the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), which is expected to impose significant incident reporting requirements across a broad range of critical infrastructure sectors. Related coverage is available at:CISA Rulemaking Updates

The GAO stated that without regulatory coordination, CIRCIA will worsen redundancy issues, especially in already heavily regulated industries such as finance. Beyond redundancy, CIRCIA could also create conflicts. The analysts wrote: "CIRCIA may impose different requirements on financial services entities regarding when to report cybersecurity incidents, what to report, and the timeframe for notifying federal agencies." Background:Industry Feedback and GAO Panel Discussions

The GAO said it is collecting feedback from infrastructure operators on the federal regulatory "thicket" and plans to release a report containing their views in the fall. See the feedback collection at:Infrastructure Operator Feedback

Coordination Efforts Stalled

Both the Biden and Trump administrations have pledged to streamline the regulatory environment by eliminating duplicative rules and modernizing regulatory text, but the GAO found that agencies have made no significant progress in this regard. See the pledges at:Biden Administration PledgeandTrump Administration Pledge

The interagency "Cybersecurity Forum for Independent and Executive Branch Regulators" has been dormant since late 2024. The Department of Homeland Security has provided no evidence that it is implementing the recommendations of the Cyber Incident Reporting Council, and the Trump administration has been slow to release a plan to implement President Donald Trump's national cybersecurity strategy.

"In addition to developing an implementation plan," GAO analysts wrote, "the Office of the National Cyber Director (ONCD) and other relevant agencies should prioritize and continue to advance previously initiated cybersecurity regulatory coordination efforts. Doing so would help achieve the goal of reducing potential burdens on the private sector while enhancing the cybersecurity of the nation's critical infrastructure." See recommendations at:ONCD Recommendations

The GAO shared its report with ONCD for comments and feedback, but the office declined to comment.