A new report from the U.S. Government Accountability Office (GAO) found that industry representatives from three critical infrastructure sectors identified duplication and conflicts among federal cybersecurity regulations, which can make it difficult for organizations to meet multiple reporting requirements while responding to cyber threats. Participants from the energy, financial services, and healthcare and public health sectors cited conflicts involving federal and sector-specific cybersecurity incident reporting requirements. They also identified the Department of Homeland Security’s proposed cyber incident reporting rule and the Securities and Exchange Commission’s cybersecurity disclosure rules as duplicative or conflicting with requirements in their respective sectors.
In its Monday report, the GAO said industry participants saw opportunities to further harmonize federal cybersecurity requirements, including by establishing consistent definitions for incident-reporting timeframes and thresholds and designating a lead agency to coordinate and receive cyber incident reports. While participants acknowledged progress over the previous year, including increased regulatory guidance for financial institutions, half said the progress remained limited. GAO said conflicting guidance, inconsistencies, higher compliance costs and redundant requirements can result when critical infrastructure sectors are subject to multiple cybersecurity regulations.
“You asked us to convene a series of discussions with industry representatives to gather their perspectives on federal progress in harmonizing cybersecurity regulations, and to provide periodic updates on these discussions,” David B. Hinchman, GAO’s director for information technology and cybersecurity, wrote in a letter to Gary C. Peters, Ranking Member of Committee on Homeland Security and Governmental Affairs and Andrew R. Garbarino, Chairman of Committee on Homeland Security. “Our previous two reports in this series were issued in July 2025 and March 2026.4 This is the third report in the series and summarizes the views shared by selected industry participants in a July 16, 2026, panel discussion. Participants commented on duplication or conflicts among federal cybersecurity regulations that affect selected critical infrastructure sectors, federal agencies’ progress in harmonizing regulations, and further opportunities for harmonization.”
Hinchman said the GAO has previously identified concerns about potentially duplicative or conflicting cybersecurity regulations and efforts to harmonize them. In May 2020, the GAO identified adverse impacts that varying cybersecurity requirements issued by selected federal agencies, and the related compliance assessments, had on state government agencies. In June 2024, it testified that consistent cybersecurity regulations could help protect against the increasing risks that threaten the nation’s critical infrastructure sector. In July 2024, it reported on the Department of Homeland Security’s efforts to implement federal cyber incident reporting requirements and the challenges with harmonizing those requirements.
The GAO convened a three-hour panel of industry participants from multiple critical infrastructure sectors. The participants were selected randomly from those who had submitted public comments on a proposed rule for CIRCIA implementation and on a request for information from the Office of the National Cyber Director regarding views on cyber regulatory harmonization. The panel was held virtually on July 16, 2026.
Six industry participants attended the panel, representing three selected critical infrastructure sectors. Denny Brennan of the Massachusetts Health Data Consortium and Dr. Steven Waldren of the American Academy of Family Physicians represented healthcare and public health. Jennifer DeCesaro of the Edison Electric Institute and Bill Zuretti of the Electric Power Supply Association represented energy. Jeremy Greenberg of America’s Credit Unions and Rick Van Luvender of Fiserv represented financial services.
In July 2025 and March 2026, the GAO summarized the views of selected industry participants from panel discussions it held on cybersecurity regulations and harmonization, in which participants expressed concerns about potentially duplicative or conflicting regulatory requirements, among other things. In July 2026, it identified 117 cybersecurity regulations established by 37 federal agencies for private entities, spanning nine critical infrastructure sectors. Most of those regulations either contain the same kind of reporting requirement applicable to a sector or the same reporting requirement as at least one other regulation, which may lead to duplication.
Several actions have been taken in recent years to improve federal coordination on cyber regulations. Congress enacted the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA), which established a Cyber Incident Reporting Council to coordinate, deconflict, and harmonize federal incident reporting requirements. CIRCIA requires the Cybersecurity and Infrastructure Security Agency, within the Department of Homeland Security, to issue regulations to implement the act’s reporting provisions.
As of August 2026, the final rule is expected to be finalized in September 2026. The White House issued a national critical infrastructure directive in April 2024. In support of the previous national cybersecurity strategy, ONCD issued a request for information that invited public comments on opportunities for, and obstacles to, harmonizing cybersecurity regulations.
In July 2024, and then again in May 2025 during the following Congressional session, proposed legislation known as the Streamlining Federal Cybersecurity Regulations Act was introduced in the Senate, which included requirements aimed at reducing duplicative or conflicting cybersecurity regulations. In March 2026, the White House issued a new national cyber strategy, which described cybersecurity priorities intended to increase coordination between the government and private sector, address adversarial threats, remove burdensome or ineffective regulations, and modernize information systems.
In June 2026, the Congressional Research Service identified several options for Congress to consider if it chose to address disparate cyber incident notification and response frameworks. These options included codifying a harmonized incident reporting framework by statute, empowering ONCD with binding cross-agency authority over cybersecurity harmonization, and evaluating whether the resulting rules, from legislation like CIRCIA, achieve sufficient harmonization before intervening legislatively.
Industry participants in the GAO’s July 2026 panel identified three opportunities to harmonize federal cybersecurity regulations.
Most participants said incident reporting should be harmonized, including the related time frames, thresholds, and definitions. They noted that using substantially similar definitions for reporting time frames and thresholds can reduce duplicative and multiple reporting obligations. One participant added that CIRCIA’s ‘substantially similar reporting’ provision could offer a positive opportunity to streamline requirements and reduce duplication.
Participants also said that establishing a single entity with authority over regulatory consistency could be beneficial. They agreed that a coordinated federal reporting model could help, in which an agency with leading authority, such as the CISA, receives incident reporting information and coordinates or disseminates it to other federal agencies. Finally, most participants said that increasing collaboration between government agencies and industry could help, noting that ongoing engagement on harmonization efforts would be beneficial.


