A recent report from the Government Accountability Office (GAO) has found that a significant majority of federal cybersecurity reporting requirements are duplicative. The study, conducted at the request of House Homeland Security Chairman Andrew Garbarino and Senate Homeland Security and Governmental Affairs Committee ranking member Gary Peters, examined 117 rules across 37 federal agencies.
The GAO determined that 80 of these 117 rules, or approximately 70%, contained reporting requirements that either applied the same kind of reporting to a specific sector or were identical to requirements found in at least one other regulation. This widespread overlap creates a complex and often redundant compliance landscape for the private sector.
The report specifically scrutinized regulations that mandate private companies to submit cybersecurity incident reports, plans, and reviews to federal agencies. The GAO highlighted that efforts to harmonize these conflicting rules have largely been delayed or have made limited progress.
For instance, the Cybersecurity and Infrastructure Security Agency (CISA) is currently developing a regulation under the 2022 Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA). This forthcoming rule will require critical infrastructure owners and operators to report major cyberattacks and ransomware payments. However, the GAO noted that elements of the financial services sector, for example, could already be subject to up to 15 existing cybersecurity reporting rules, depending on their oversight agency, in addition to the impending CIRCIA requirements.
The Biden administration had initiated a push to regulate cybersecurity more aggressively and to harmonize conflicting regulations. A 2024 national security memorandum specifically tasked the Office of the National Cyber Director (ONCD) and the Department of Homeland Security (DHS) with addressing these overlaps. While both agencies made some progress, these harmonization efforts were subsequently paused after the Trump administration issued an executive order in March of the previous year to conduct a study of the 2024 memo. This study was still ongoing as of last month, according to the GAO.
The GAO's findings underscore a persistent challenge in federal cybersecurity policy, where numerous agencies have independently developed reporting requirements, leading to a fragmented and often burdensome system for regulated entities. The report focused exclusively on federal regulations, though other analyses have also considered the impact of state-level and other reporting obligations.






