Skip to main content

Cybersecurity Regulations: Multiple Sectors Are Subject to Potentially Duplicative Reporting Requirements

GAO-26-108606 Published: Jul 22, 2026. Publicly Released: Jul 22, 2026.
Jump To:

Fast Facts

The nation’s critical infrastructure is supported by IT systems—most of which are owned by the private sector. Federal agencies have issued many cybersecurity regulations for these systems.

We found that 80 of the 117 regulations we identified (about 70%) had the same kind of reporting requirement as another regulation. For example, the Securities and Exchange Commission requires publicly traded companies across different sectors to provide cybersecurity plans. However, this may duplicate or conflict with similar requirements in other regulations.

The administration intends to issue an implementation plan to streamline cybersecurity regulations.

A gavel laying on top of a computer circuit board

Skip to Highlights

Highlights

What GAO Found

GAO identified 117 cybersecurity regulations established by 37 federal agencies for private entities, spanning nine critical infrastructure sectors. Most of those regulations either contain the same kind of reporting requirement applicable to a sector or the same reporting requirement as at least one other regulation, which may lead to duplication. Specifically, 80 of the 117 regulations (about 70 percent) had at least 125 total reporting requirements (see figure), with some regulations requiring multiple types of reporting.

Cybersecurity Regulations with Reporting Requirements, as of June 2026

Cybersecurity Regulations with Reporting Requirements, as of June 2026

These regulations included sector-specific and cross-sector reporting requirements for private sector entities that may be required to report similar or different cybersecurity information to multiple agencies. For example, a proposed rule from the Department of Homeland Security related to cybersecurity incident reporting by critical infrastructure sectors acknowledged that it may be potentially duplicative with one or more of the 15 existing financial sector regulations that also require such incident reporting. Additionally, cross-sector regulations may duplicate or conflict with regulations focused on a specific sector. For example, one from the Securities and Exchange Commission that requires publicly traded companies across different sectors to provide cybersecurity plans may duplicate or conflict with regulations focused on a specific sector. GAO has ongoing work to obtain additional industry perspectives on federal cybersecurity regulations, including where they perceive overlap and duplication within selected critical infrastructure sectors.

Federal law and the April 2024 National Security Memorandum-22 established the Office of the National Cyber Director (ONCD) as the lead agency responsible for coordinating efforts to streamline, or harmonize, the development and adoption of consistent standards and regulations. ONCD and other federal agencies have initiated actions in recent years to harmonize cybersecurity regulations but have made limited progress. In March 2026, the White House issued a new national cyber strategy which established harmonization and reducing compliance burdens as a priority. According to the strategy, the administration intends to release implementation plans, which could help identify clear lead agency roles, responsibilities, and next steps while enhancing the cybersecurity of the nation’s critical infrastructure.

Why GAO Did This Study

Nearly all the nation’s critical infrastructure are supported by computer-based information systems, and it is vital that public and private sectors work together to protect them. Federal agencies have issued numerous regulations to help protect the nation’s critical infrastructure, which is mostly owned by the private sector. However, according to ONCD, when critical infrastructure sectors are subject to multiple cybersecurity regulations, the result can lead to conflicting guidance, inconsistencies, increased compliance costs and redundancies for regulated entities. Consistency is important to avoid overlap, duplication, or conflicting requirements.

GAO was asked to review federal cybersecurity regulations to identify opportunities for harmonization. This report determines the extent to which federal cybersecurity regulations and requirements are potentially duplicative or conflicting for regulated private sector entities.

GAO reviewed the Electronic Code of Federal Regulations to identify cybersecurity regulations and assess them for potentially duplicative and conflicting reporting requirements. GAO also reviewed available harmonization plans and analyses from ONCD and the Department of Homeland Security. GAO also interviewed relevant officials.

We provided a draft of this report to ONCD for review and comment. ONCD did not provide comments on the report.

For more information, contact David Hinchman at hinchmand@gao.gov.

Full Report

GAO Contacts

David (Dave) Hinchman
Director
Information Technology and Cybersecurity

Media Inquiries

Sarah Kaczmarek
Managing Director
Office of Public Affairs

Public Inquiries

Topics

CybersecurityReporting requirementsCritical infrastructureFederal agenciesHealth care standardsCommunicationsFederal regulationsRailroadsFederal acquisition regulationsPrivate sector