← Browse Policy Library · Report

Cybersecurity: Considerations on Regulatory Harmonization

The Department of Homeland Security (DHS) is simultaneously pursuing three major cybersecurity regulatory initiatives—each issued by a different agency, each addressing a different critical infrastructure sector, and each with its own definitions, timelines, and reporting requirements for cybersecurity incidents. Some stakeholders have raised concerns about the potential burdens that the three separate, but overlapping, mandates may impose on regulated entities. The three rules are the U.S. Coast Guard’s (USCG) Cybersecurity in the Marine Transportation System, the Transportation Security Administration’s (TSA) proposed rule Enhancing Surface Cyber Risk Management, and the Cybersecurity and Infrastructure Security Agency’s (CISA) proposed rule implementing the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA). All three would require cyber incident reporting. The USCG and TSA rules would also impose some cybersecurity standards on business operations. The USCG rule became effective July 16, 2025, applying to U.S.-flagged vessels, Outer Continental Shelf facilities, and facilities subject to the Maritime Transportation Security Act of 2002 (MTSA). It requires incident reporting to the National Response Center (NRC) immediately upon a reportable event, with a phased schedule for training and cybersecurity plan submissions. TSA’s notice of proposed rulemaking (NPRM), issued on November 7, 2024, has not been finalized, but would cover approximately 293 pipeline, freight rail, passenger rail, and bus operators designated as high-risk if finalized. CISA’s CIRCIA rule was proposed on April 4, 2024, and has also not yet been finalized, but would cover an estimated 316,000 entities across all 16 critical infrastructure sectors if finalized. Despite sharing the common goal of reducing cyber risk to critical infrastructure, the three rules have notable differences. They use different definitions of a reportable cyber incident. They require reports to be sent to different agencies—the USCG rule directs reports to the NRC, TSA and the CIRCIA rule requires reports directly to CISA. They also impose different reporting timelines: USCG requires notification “without delay,” TSA proposes a 24-hour window, and CIRCIA mandates 72 hours for substantial incidents and 24 hours for ransomware payments. For certain operators, such as maritime pipeline facilities classified as critical infrastructure, this fragmentation could require simultaneous compliance with all three regimes, potentially creating an administrative burden and adding complexity to the response. Some have suggested that regulatory harmonization is necessary to relieve covered entities from duplicative efforts. While there is this potential overlap, it is unclear how many facilities would be subject to the overlapping requirements, or if a push towards harmonization would quash sector-specific reporting benefits. Despite no clear account of the scope of the problem, various stakeholders have been working toward potential solutions. The Office of the National Cyber Director (ONCD), the Government Accountability Office (GAO), industry groups, and (to some extent) cybersecurity regulatory agencies have all raised concerns about the proliferation of inconsistent cybersecurity requirements. For instance, a July 2025 GAO report found that industry participants believe the federal government has not made progress in harmonizing cybersecurity regulations. Meanwhile, through executive order, the Trump Administration has directed agencies to reduce regulatory burdens. This action could delay the timing and ultimate scope of the CIRCIA and TSA final rules. If Congress chooses to address disparate cyber incident notification and response frameworks (which could result if all three rules are finalized and given effect), it has several options. It could codify a harmonized incident reporting framework by statute, resolving definitional inconsistencies that agencies have been unable to reconcile on their own. It could empower ONCD with binding cross-agency authority over cybersecurity harmonization. Alternatively, Congress could wait for the CIRCIA and TSA rulemaking processes to conclude and evaluate whether the resulting rules achieve sufficient harmonization before intervening legislatively.

Full content not yet available.