NEWS
GAO Finds 70 Percent of Cyber Rules Overlap as CIRCIA Nears
GAO tallies 117 federal cyber rules with 80 overlapping on incidents, plans and audits; stalled harmonization leaves operators exposed as CIRCIA finalizes.
Roughly 70 percent of federal cybersecurity regulations already force private operators to file the same kinds of reports more than once. The Government Accountability Office tallied 117 rules from 37 agencies covering nine critical infrastructure sectors and found 80 of them share incident, plan or audit requirements, producing at least 125 separate obligations. The July 22 report lands weeks before CISA is expected to finalize the long-delayed CIRCIA rule that will add still more reporting.
Operators who own most of the country’s power grids, banks, hospitals and transport networks now face the bill for years of unfinished streamlining work. Multiple administrations promised to clean up the overlap. Most of those efforts stalled or paused. CIRCIA is set to test whether the pattern breaks.
The 117-Rule Map Across Nine Sectors
GAO searched the Electronic Code of Federal Regulations as of June 2026 and identified 117 established cybersecurity regulations plus two proposed ones. Eighty of the 117 (about 70 percent) require private entities to report cybersecurity incidents, cybersecurity plans or other technical information, or the results of reviews, audits or assessments. Some rules demand more than one type, which is why the total reaches 125 distinct requirements.
The breakdown is concrete:
| Reporting Type | Number of Regulations | Agencies Involved |
|---|---|---|
| Cybersecurity incidents | 48 | 27 |
| Plans or technical information | 52 | 26 |
| Reviews, audits or assessments | 25 | 15 |
Cross-sector rules sit alongside sector-specific ones. A single company can therefore answer to several agencies for the same underlying event or control. GAO noted that definitions of a reportable incident, reporting clocks, required content and submission methods already differ. That is the ground CIRCIA will enter.
The full inventory, grouped by sector, sits in the full 36-page GAO analysis PDF. The product page summarizing the GAO-26-108606 findings on 117 regulations confirms ONCD received a draft and declined to comment.
Financial Services Carries the Heaviest Load
In incident reporting, financial-services firms face the thickest stack. GAO counted 15 separate regulations that can apply depending on the entity’s charter and activities. The list includes rules from the Treasury Department, Federal Trade Commission, Federal Deposit Insurance Corporation, Securities and Exchange Commission, Federal Reserve Board, Office of the Comptroller of the Currency, National Credit Union Administration and Commodity Futures Trading Commission.
A single bank or broker-dealer may already file under more than one of those regimes. CIRCIA will cover many of the same entities once finalized. CISA has said it wants to explore reciprocity so that a report to one agency can satisfy others, but the mechanism is not yet locked. Differences in what counts as a covered incident, how fast notice must go out, and what details belong in the first submission can force parallel workstreams.
The same pattern appears in other sectors. Transportation systems operators can face up to seven plan-reporting rules. Federal contractors often send the same security-plan package to each agency customer separately. The diversion is real: industry participants told GAO in earlier panels that hours spent assembling multi-agency packages cut into time for actual incident response and hardening.
That pressure sits on top of broader technology shifts inside finance. Many firms already run complex delivery models, including the kind of specialized centers described in coverage of financial sector technology delivery centers. Adding more reporting clocks multiplies the coordination cost.
Plans and Audits Multiply the Paper
Incident reports get the headlines. Plan and audit requirements create the steady grind. Fifty-two regulations demand cybersecurity plans or other technical documentation. Twenty-five require submission of third-party audits or self-assessments that can vary in scope and methodology.
A contractor serving multiple federal agencies may hand over nearly identical plan material or assessment results to each one. GAO warned that companies “may be required to provide duplicative compliance data or conduct multiple compliance audits that could vary in scope, depth, and methodology.” The result is repeated effort without corresponding new insight for the government side.
- IT-sector contractors often re-submit security plans to each agency customer under FAR-linked clauses.
- Transportation entities juggle mode-specific plan rules that can also collide with SEC cross-sector plan requirements for public companies.
- Audit scopes differ enough that a single third-party assessment rarely satisfies every regulator at once.
This is not new to compliance teams. What is new is the near-term arrival of a large cross-sector mandate on top of the existing pile.
Harmonization Efforts That Stalled
Federal law and National Security Memorandum-22 gave the Office of the National Cyber Director the lead role in coordinating streamlining. DHS was told to produce a national infrastructure risk-management plan with a harmonization component by April 2025. Multiple concrete steps followed, then slowed.
- 2022-2023: CIRCIA created the Cyber Incident Reporting Council. DHS issued a September 2023 report with eight recommendations on model definitions, timelines and triggers. As of May 2026 DHS had not reported progress on those recommendations.
- 2022-2024: The Cybersecurity Forum for Independent and Executive Branch Regulators, relaunched under FCC leadership, explored consistency. FCC officials told GAO it has not been active since late 2024.
- 2023-2024: ONCD ran a request for information on regulatory harmonization and published a summary. Industry responses repeatedly flagged burden and inconsistency.
- March 2025: An executive order paused certain NSM-22 activities while the new administration reviewed critical-infrastructure policy. That review remained open as of June 2026.
- March 2026: The White House released a new national cyber strategy that lists harmonization and reduced compliance burdens as priorities. As of July 2026 the promised implementation plans had not appeared.
GAO’s assessment is blunt: “many past federal efforts have experienced delays and made limited progress.” ONCD did not answer GAO’s information requests in September 2025 or June 2026 and offered no comments on the draft report. Industry panels convened by GAO in 2025 and early 2026 described the same limited movement.
When multiple regulations have the same types of reporting requirements, particularly when the requirements affect entities within the same sector or across multiple sectors, those regulations have the potential to be duplicative or conflicting.
That line from the GAO analysts captures the core finding that prior streamlining work never fully resolved.
CIRCIA Arrives on Crowded Ground
Congress passed the Cyber Incident Reporting for Critical Infrastructure Act in 2022. CISA’s notice of proposed rulemaking drew heavy industry comment on scope, definitions and the absence of clear reciprocity. Funding lapses and internal delays pushed the original statutory timeline. Town halls originally planned for spring 2026 were canceled then rescheduled for mid-June. CISA now points to a September 2026 final-rule target on the regulatory agenda.
The agency’s own CISA CIRCIA rulemaking status page states that covered-entity reporting will not begin until the final rule’s effective date and that CISA continues to work on the text. Officials have said they want the rule to maximize visibility while minimizing unnecessary burden. The GAO report flags the risk in the opposite direction: without harmonization, CIRCIA can create new contradictions on timing, content and thresholds, especially in financial services.
House Homeland Security Committee Republicans, whose chairman requested the GAO study alongside Senate ranking member Gary Peters, publicly noted that seven out of ten federal cyber reporting rules are already duplicated and that CIRCIA’s final implementation “must succeed in harmonizing” the landscape. That is the political frame now attached to the rule.
Operators are not waiting for perfect clarity. Many have already mapped every existing federal and state clock. The open question is whether the final CIRCIA text includes workable single-report pathways or simply becomes the 16th (or higher) requirement for the most regulated firms.
What Operators Face This Fall
GAO is collecting additional operator feedback and plans a follow-on report for fall 2026. That timing will coincide with whatever CIRCIA final text emerges. In the meantime the practical checklist is straightforward:
- Inventory every applicable federal reporting rule by incident, plan and audit category, including the 15 financial-services incident streams where relevant.
- Note definition and clock differences so that a single internal event can generate multiple external packages without last-minute scrambling.
- Track CISA reciprocity language in the final rule and any companion guidance that would let one submission satisfy overlapping regimes.
- Watch for the administration’s cyber-strategy implementation plans, which GAO says are needed to assign clear lead roles and revive earlier recommendations.
The private sector owns the majority of critical infrastructure. It also absorbs most of the compliance cost when rules multiply without cleanup. The GAO numbers quantify the existing overlap. CIRCIA will decide whether that overlap shrinks or grows in the next reporting cycle.
Frequently Asked Questions
How many federal agencies issue cybersecurity regulations with reporting requirements?
GAO identified 37 agencies that have issued the 117 regulations under review. Of those, 27 agencies account for the 48 incident-reporting rules, 26 for the 52 plan rules, and 15 for the 25 audit rules. Some agencies appear in more than one category.
When is the CIRCIA final rule expected and what does it require?
CISA’s current regulatory-agenda target is September 2026. Once effective, covered entities will have to report covered cyber incidents within 72 hours and ransom payments within 24 hours to CISA. The exact scope of “covered entity” and the final definitions will appear in the published rule; voluntary reporting continues until then.
Did the GAO recommend specific legislative fixes?
The July 2026 report itself focuses on documenting the overlap and the limited progress of executive-branch efforts. It urges ONCD and other agencies to prioritize and finish previously started harmonization work and to issue the strategy implementation plans. Separate congressional discussions and earlier GAO products have floated stronger mandates, but this report stops short of new statutory language.
Which critical infrastructure sectors show the most overlap?
Financial services stand out for incident reporting with up to 15 applicable rules. Transportation shows heavy plan-reporting density (as many as seven rules). Cross-sector rules such as the SEC’s cybersecurity-plan requirements for public companies can collide with any sector-specific regime. IT contractors face repeated plan and audit submissions across agency customers.
Has the Cybersecurity Forum for Independent and Executive Branch Regulators been revived?
According to FCC officials quoted by GAO, the forum has not been active since late 2024. No public announcement of a restart appeared in the materials GAO reviewed through mid-2026.
-
AI4 weeks agoFable 5 and Mythos 5 Return as US Lifts Anthropic Export Controls
-
AI2 months agoSpaceX’s Google Deal Turns a Rocket Company Into a Cloud Landlord
-
GAMING1 month agoCD Projekt Red Co-CEO: Redemption Arc Isn’t Done, Witcher 4 in 2027
-
AI1 month agoOracle Cuts 21,000 Jobs in a Year, Cites AI in 10-K Filing
-
CRYPTO2 months agoXPL Rallies 30% Ahead of Plasma One Card Tier Launch
-
APPS2 months agoDGO App Brings Rs 549 Mobile Pass for FIFA World Cup 2026 in Nepal
-
AI2 months agoMoonshot AI Targets $30 Billion in China’s Fastest AI Funding Sprint
-
NEWS2 months agoGoogle Search Profiles Build a Follow Graph Inside Discover
