Policy · 53 days ago
The problem is not missing reporting rules. It is too many rules asking for the same incident in different forms, on different clocks, from the same company. That splits incident response across compliance teams instead of helping agencies get a clean picture fast.
GAO found 80 of 117 federal cybersecurity reporting rules overlap across 37 agencies. It also said harmonization efforts have stalled, including work tied to the 2024 national security memorandum, and that some sectors can face several nearly duplicate obligations at once, including pending CIRCIA rules on top of older sector requirements.
2 sources covering this story
GAO report details scope of cybersecurity regulation overlap
A morass of rules is forcing companies to report the same information multiple times — and sometimes, those rules conflict.
Most federal cybersecurity reporting rules are duplicative, study finds
A new GAO report reveals 70% of federal cybersecurity reporting rules overlap, while efforts to streamline redundant requirements continue to face delays.
Part of the PlainSec briefing for 2026-07-24