Why It Matters
Three separate Department of Homeland Security (DHS) agencies are imposing different cybersecurity rules on the same companies, forcing some operators to navigate conflicting definitions, timelines, and reporting requirements. A Congressional Research Service (CRS) report released in June examines how this fragmentation is straining industry compliance efforts and what Congress might do to fix it.
Industry participants told the Government Accountability Office (GAO) that some firms spend up to 50 percent of their staff's time just managing cybersecurity regulatory compliance. One operator summed up the stalemate bluntly: "We are no closer today than we were 10 years ago on creating a solution for harmonization." A 2021 ransomware attack on Colonial Pipeline shut down major portions of its pipeline network serving the Eastern Seaboard for 6 days, demonstrating why regulators moved to tighten cybersecurity standards across critical infrastructure sectors.
The Big Picture
Three separate DHS agencies have each issued their own cybersecurity rules for critical infrastructure that conflict with each other. The U.S. Coast Guard (USGC) rule became effective July 16, 2025, applying to U.S.-flagged vessels, Outer Continental Shelf facilities, and facilities subject to the Maritime Transportation Security Act of 2002. The Transportation Security Administration (TSA) issued a proposed rule on November 7, 2024 covering approximately 293 pipeline, freight rail, passenger rail, and bus operators designated as high-risk, though it has not been finalized. The Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), administered by the Cybersecurity and Infrastructure Security Agency (CISA), represents the third rule. All three would require cyber incident reporting, but they use different definitions of a reportable cyber incident.
The USCG rule directs cyber incident reports to the National Response Center and requires notification without delay. The TSA proposes a 24-hour reporting window. Some entities, such as a maritime pipeline terminal, could simultaneously fall under all three regulatory regimes, creating overlapping compliance obligations. The exact number of facilities subject to these overlapping requirements remains unclear.
The July 2025 GAO report (GAO-25-108436) found that industry participants believe the federal government has not made progress in cybersecurity regulatory harmonization. Congress has identified six potential approaches to address the fragmentation. These include mandating common definitions and reporting standards for cyber incidents, empowering a single harmonization authority such as the Office of the National Cyber Director with binding cross-agency authority, directing reciprocity among sector regulators to allow compliance with one agency's program to satisfy another's requirements, establishing a unified reporting portal, and directing the three agencies to jointly develop compliance guides for entities under multiple regimes.
The report notes a distinction between *harmonization*, which makes actual requirements consistent across agencies, and *reciprocity*, which allows agencies to accept each other's compliance assessments. It is unclear whether harmonization would eliminate sector-specific reporting benefits that regulators may value.
The Bottom Line
The most direct path forward lies within DHS itself: the Secretary could direct the three agencies to align their cyber incident reporting definitions, timelines, and destinations without requiring new legislation. However, two significant constraints may slow or complicate this approach.
First, Executive Order 14192, titled Unleashing Prosperity Through Deregulation," issued by Pres. Trump in January 2025, prioritizes regulatory reduction across the federal government. It remains unclear whether this deregulation mandate will delay or prevent TSA and CISA from finalizing their proposed cybersecurity rules, potentially leaving the current fragmentation in place indefinitely.
Second, CISA faces significant workforce and budget constraints that have intensified since 2025. These resource limitations may reduce the agency's capacity to negotiate harmonization agreements or implement new reporting infrastructure, even if leadership commits to doing so.
Congress may need to act if executive action stalls. The CRS report suggests that legislative options such as mandating common definitions, establishing a unified reporting authority, or requiring reciprocity agreements, could break the current deadlock and reduce compliance burdens on industry while strengthening critical infrastructure security.
***
Access the Legis1 platform for comprehensive political news, data, and insights
---
Spot something wrong? Report an issue with this article