A Government Accountability Office report to Congress found that federal cybersecurity reporting requirements are heavily fragmented and often duplicative, with 80 of 117 regulations issued by 37 agencies overlapping across nine critical infrastructure sectors. GAO said those rules contain at least 125 reporting requirements, many of which impose the same written reporting obligations on regulated entities or create potentially conflicting demands across sector-specific and cross-sector regimes.
The report said harmonization efforts have made only limited progress despite federal directives assigning the Office of the National Cyber Director a lead role in reducing overlap and compliance burdens. GAO highlighted the impact on critical infrastructure and financial services organizations, which can face multiple incident-reporting and disclosure obligations from different regulators, including possible overlap involving Department of Homeland Security incident-reporting rules, Securities and Exchange Commission cybersecurity disclosure requirements, and pending Cyber Incident Reporting for Critical Infrastructure Act implementation.

See the reporting duties and controls this puts on the clock.
4 events from the most recent confirmed update back to the earliest known activity.
Some federal work to harmonize overlapping cybersecurity reporting requirements was paused after a Trump executive order, pending further review.
A 2024 national security memorandum directed the Office of the National Cyber Director and the Department of Homeland Security to harmonize conflicting federal cybersecurity regulations.
The White House's March 2026 national cyber strategy made harmonizing cybersecurity regulations and reducing compliance burdens a priority, with implementation plans expected to clarify agency roles and next steps.
GAO reported that it reviewed 117 cybersecurity regulations issued by 37 federal agencies and found that 80 contained at least 125 reporting requirements, many of which appear duplicative or potentially conflicting for critical infrastructure entities.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.