IndustrialCyber

TSA updates cybersecurity reporting and assessment requirements for surface transportation


The U.S. Transportation Security Administration has sent the Office of Management and Budget a revised information collection request covering cybersecurity measures for surface transportation operators, with the proposal applying to certain freight rail, mass transit and passenger rail, and over-the-road bus operators. The revised collection includes requirements for designating cybersecurity coordinators, reporting cybersecurity incidents to the Cybersecurity and Infrastructure Security Agency within 72 hours, maintaining cybersecurity incident response plans, and completing cybersecurity assessments. 

TSA estimates the collection will cover 67 respondents and impose 22,167 hours of annual burden, down from an earlier estimate of 846 respondents and 210,684 hours. Public comments are due Oct. 1. The notice covers owners and operators of freight rail, mass transit and passenger rail, and over-the-road bus operations.

In a Federal Register notice published Tuesday, Christina A. Walsh, Paperwork Reduction Act Officer for Information Technology at the TSA, detailed that the agency is soliciting comments to evaluate whether the proposed information requirement is necessary for the proper performance of the functions of the agency, including whether the information will have practical utility; evaluate the accuracy of the agency’s estimate of the burden; enhance the quality, utility and clarity of the information to be collected; and minimize the burden of the collection of information on those who are to respond, including using appropriate automated, electronic, mechanical or other technological collection techniques or other IT forms.

TSA has authority to impose transportation security measures without notice or comment. In December 2021, it issued mandatory security directives requiring higher-risk railroads and rail transit operators to implement cybersecurity measures to protect infrastructure. A complementary directive followed in October 2022 targeting freight and passenger railroads. TSA has also issued voluntary guidance recommending similar measures for operators not covered by the mandates, most recently in October 2025 recommending incident reporting to TSA.

“On January 15, 2026, TSA revised the SD 1580-21-01 series, SD 1582-21-01 series, to require that any non-U.S. citizen serving as a primary or alternate Cybersecurity Coordinator must be a current member of NEXUS, Global Entry, or another program determined by TSA to include a comparable security threat assessment,” Walsh wrote in the notice. “TSA is revising the collection to include this new requirement.”

The notice detailed that owners and operators must designate a primary and at least one alternate Cybersecurity Coordinator. Any non-U.S. citizen serving as a primary or alternate Cybersecurity Coordinator must be a current member of NEXUS, Global Entry or another program determined by TSA to include a comparable security threat assessment and must submit documentation of such membership to TSA. This requirement is a revision to the original collection, as discussed above, stemming from the revision of these SD series. 

TSA expects that fewer than 10 owners and operators will respond to the information collection annually. However, this new requirement burden is covered under OMB control number 1651-0121, Trusted Traveler Programs and U.S. APEC Business Travel Card. Owners and operators must report cybersecurity incidents to the Cybersecurity and Infrastructure Security Agency no later than 72 hours after identifying a cybersecurity incident. Also, owners and operators must develop a Cybersecurity Incident Response Plan and submit it to TSA, and they must complete a cybersecurity vulnerability assessment using the TSA-issued form and submit the completed assessment to TSA.

Information collection is also being revised to remove mandatory requirements associated with the SD 1580-21-01 series and the SD 1582-21-01 series, specifically the cybersecurity vulnerability assessment for rail owners and operators subject to these SDs. These rail owners and operators have satisfied the SD requirements, and TSA expects that fewer than 10 owners and operators will respond to the collection annually.

In addition, TSA is revising the collection to include updates to the Cybersecurity Incident Response Plan requirements. Owners and operators have developed their initial Cybersecurity Incident Response Plans, satisfying the SD requirements, and TSA expects fewer than 10 new owners and operators will need to submit a plan annually. However, TSA also requires these owners and operators to maintain up-to-date Cybersecurity Incident Response Plans, which necessitates periodic updates. TSA is revising the collection to include these updates.

As part of the SD 1580/82-2022-01 Series, the notice identified that it includes three information collection requirements. Owners and operators must submit a Cybersecurity Implementation Plan to TSA for approval that identifies how they will achieve the required security outcomes outlined in the SD. They must also submit a Cybersecurity Assessment Plan and an annual Cybersecurity Assessment Plan report. In addition, owners and operators must provide documentation to TSA upon request when necessary to establish compliance.

The ICs also recommend, but do not require under the SDs, that owners and operators notify TSA’s Transportation Security Operations Center as soon as possible, and no later than 12 hours after discovering an actual or potential significant cybersecurity incident.

TSA is also revising the collection to include updates and reports associated with the mandatory requirements of the SD 1580-21-01 and SD 1582-21-01 series, specifically the Cybersecurity Implementation Plan and Cybersecurity Assessment Plan for rail owners and operators subject to these SDs. These rail owners and operators have satisfied the Cybersecurity Implementation Plan requirements, and TSA expects fewer than 10 new owners and operators to respond to the collection annually. However, TSA estimates that about half of owners and operators will provide updates to their Cybersecurity Implementation Plans each year. TSA is revising the collection to account for these updates.

TSA is also revising the collection to include updates to the Cybersecurity Incident Response Plan requirements. Owners and operators have developed their initial Cybersecurity Incident Response Plans, satisfying the SD requirements, and TSA expects fewer than 10 new owners and operators will need to submit a plan annually. However, these owners and operators are required to maintain up-to-date Cybersecurity Incident Response Plans, which necessitates periodic updates. TSA is revising the collection to include these updates.

In addition, TSA is revising the collection to include Cybersecurity Assessment Plan reports. In October 2023, SD 1580/82-2022-01 required owners and operators to submit an annual report. These owners and operators are also required to conduct annual assessments of their cybersecurity measures and submit an annual report of the assessment results to TSA. TSA is updating the collection to include these reports.



Source link