Skip to main content
Compliance

GAO Report Exposes Duplication in Federal Cybersecurity Reporting Rules

Government building with papers and binder in foreground, hinting at bureaucracy.

"Seven out of 10 federal cyber regulations requiring written reports to federal agencies are duplicated elsewhere," the Government Accountability Office told Congress in a report released Wednesday.

GAO counted overlap at 37 agencies: 80 of 117 rules duplicate reporting

At the request of two congressional leaders, the GAO reviewed cybersecurity regulations at 37 federal agencies and found substantial duplication. The watchdog counted 117 federal rules that require written reporting to agencies and concluded that 80 of those rules “either contain the same kind of reporting requirement applicable to a sector or the same reporting requirement as at least one other regulation.” The finding — that roughly seven in 10 reporting rules are duplicated — frames the agency’s central concern about regulatory complexity for entities that must comply.

CIRCIA and CISA: a pending rule that could layer on top of 15 existing financial-sector requirements

The report highlights how a single sector can be subject to multiple overlapping obligations. The Cybersecurity and Infrastructure Security Agency has been developing a regulation to implement the 2022 Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), which would require critical infrastructure owners and operators to report when they suffer major attacks or make ransomware payments. GAO noted that elements of the financial services sector might fall under one of 15 preexisting cybersecurity reporting rules depending on the agency with oversight, and those entities could also become subject to the pending CIRCIA regulation once finalized.

2024 national security memorandum, ONCD and DHS, and an executive-branch pause

Efforts to harmonize duplicative rules tracked back to a 2024 national security memorandum that assigned the Office of the National Cyber Director and the Department of Homeland Security responsibility to reconcile conflicting regulations. According to the GAO, both offices "made some progress" toward those harmonization goals. That work, however, stalled after a presidential executive order issued in March of last year prompted an administration-wide study of the 2024 memorandum. GAO reported the study was still underway "as of last month," and described harmonization overall as an area where "many past federal efforts have experienced delays and made limited progress."

Congressional drivers: requests from Garbarino and Peters

GAO’s review was undertaken at the request of House Homeland Security Chairman Andrew Garbarino, R‑N.Y., and the top Democrat on the Senate counterpart to Garbarino’s panel, Gary Peters, D‑Mich. The bipartisan request underscores congressional interest in reducing conflicting reporting requirements that affect regulated entities across critical infrastructure sectors.

What this means for financial services, CISA and DHS, and incident response firms

  • Financial services sector: Firms in parts of the sector could be subject to as many as 15 preexisting federal reporting rules and, depending on final CIRCIA implementation, could receive additional overlapping reporting obligations from CISA.
  • Cybersecurity and Infrastructure Security Agency and DHS: CISA’s pending rulemaking under CIRCIA is a central node in the duplicative landscape; DHS and the Office of the National Cyber Director were tasked by a 2024 memorandum to harmonize such rules but have only "made some progress" and saw work paused after a March executive order.
  • Incident response firms and private-sector reporters: BreachRx, a cyber incident response firm, published a companion report Wednesday that broadened the analysis to include state and nonfederal reporting sources, illustrating how overlap is not limited to federal rules alone.

The GAO confined its formal study to federal regulations, but the simultaneous release of work by a private incident-response firm pointed to the wider reporting environment that companies already navigate. GAO’s summary—that many efforts to harmonize have been delayed and achieved limited progress—frames a persistent administrative and compliance problem rather than a single technical fix.

With 80 of 117 reviewed federal reporting rules duplicative and the study of the 2024 national security memorandum still underway, the GAO’s finding leaves open when and how the government will remove overlap that can complicate incident reporting, regulatory oversight, and compliance planning. For organizations that face multiple potential reporting paths — and for the agencies charged with overseeing them — the next steps are procedural and institutional as much as they are technical.

Original report