The U. S. Cybersecurity and Infrastructure Security Agency (CISA) is shortly due to issue a final rule implementing the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA).
While the final rule was expected in May 2026, it has been delayed until September 2026. When issued, entities in the 16 critical infrastructure sectors will be required to report substantial cyberattacks to CISA within 72 hours of formulating a reasonable belief that such an incident has occurred. The Trump administration issued a new cybersecurity strategy in March 2026 that prioritized harmonization and the reduction of compliance burdens, while enhancing cybersecurity of the nation’s critical infrastructure.
The nation’s critical infrastructure is dependent on computer-based information systems, most of which are owned by the private sector. Those systems are subject to multiple federal regulations, some of which have overlapping requirements. The Government Accountability Office was asked to review federal cybersecurity requirements for critical infrastructure to identify potential opportunities for harmonization.
A recently published GAO report focuses on the potentially duplicative cybersecurity-related reporting requirements for critical infrastructure sectors. In some cases, the same types of information must be reported to different federal agencies, which requires multiple reports to be written about the same cybersecurity incident or compliance activity. That inevitably means resources are being diverted to compliance activities that could be better used for improving security.
Out of 117 regulations identified by GAO across 9 critical infrastructure sectors, 80 – approximately 70% – had the same kind of reporting requirement as another regulation. Across those 80 regulations, there were at least 125 total reporting requirements, as some regulations required multiple types of reporting – 48 required reporting of cybersecurity incidents, 52 required cybersecurity plans or other technical information, and 25 required reviews, audits, or assessments.
GAO believes that duplicative reporting requirements add an unnecessary administrative burden on critical infrastructure entities, which will soon face the additional reporting requirements of CIRCIA. While CIRCIA will improve federal visibility into cybersecurity incidents, it will certainly add to the reporting burden. GAO is working on obtaining additional industry perspectives on federal cybersecurity regulations, such as where there are overlapping and duplicative reporting requirements, and it intends to issue an implementation plan to help streamline cybersecurity regulations for critical infrastructure entities.
The post GAO Report Identifies Potentially Duplicative Cyber Reporting Requirements for Critical Infrastructure appeared first on The HIPAA Journal .
Originally published at hipaajournal.com