A new watchdog report reveals that roughly 70 percent of federal cybersecurity regulations contain reporting requirements that duplicate or potentially conflict with at least one other regulation, creating compliance burdens across nine critical infrastructure sectors.
The Government Accountability Office identified 117 cybersecurity regulations issued by 37 federal agencies governing private-sector entities. Of those, 80 regulations carried at least 125 total reporting requirements, many of which ask regulated companies to submit similar cybersecurity information to multiple agencies. The report, published July 22, 2026, underscores longstanding concerns that fragmented oversight is driving up costs without proportionally improving security.
How the Overlap Works in Practice
The GAO pointed to concrete examples of duplication. The Securities and Exchange Commission requires publicly traded companies across different sectors to file cybersecurity plans. Those filings may overlap or conflict with sector-specific regulations imposed by other agencies on the same companies. A separate proposed rule from the Department of Homeland Security for critical infrastructure incident reporting acknowledged that it could duplicate as many as 15 existing financial-sector regulations that already require similar incident reporting.
Cross-sector regulations add another layer of complexity. When a single company falls under both a broad regulation and a sector-specific one, it may face inconsistent definitions, timelines, or thresholds for the same cybersecurity event. The GAO is continuing to gather industry perspectives on where the perceived overlap is most acute.
Critical Infrastructure Sectors Bear the Brunt
Nearly all of the nation’s critical infrastructure relies on computer-based information systems, and most of those systems are owned and operated by the private sector. Federal agencies have issued a patchwork of regulations to protect them, but the GAO found that the patchwork itself has become a problem. Regulated entities frequently must interpret similar requirements from multiple agencies, each with its own reporting format and timeline.
According to the Office of the National Cyber Director, when critical infrastructure sectors are subject to multiple cybersecurity regulations, the result can be conflicting guidance, inconsistencies, increased compliance costs, and redundancies. The GAO’s findings quantify a concern that ONCD has raised previously but had not been systematically measured until now.
Harmonization Efforts and Limited Progress
Federal law and the April 2024 National Security Memorandum-22 designated ONCD as the lead agency responsible for coordinating efforts to streamline, or harmonize, the development and adoption of consistent cybersecurity standards and regulations. ONCD and other federal agencies have initiated actions in recent years to harmonize cybersecurity regulations, but the GAO found that progress has been limited.
In March 2026, the White House issued a new national cyber strategy that established harmonization and reducing compliance burdens as a priority. According to the strategy, the administration intends to release implementation plans that could help identify clear lead agency roles, responsibilities, and next steps while enhancing the cybersecurity of the nation’s critical infrastructure. Those plans have not yet been released.
What Happens Next
The GAO’s findings put pressure on ONCD to deliver a concrete implementation plan with defined agency responsibilities and deadlines. Without clear lead-agency assignments for each critical infrastructure sector, regulated entities will continue navigating overlapping cybersecurity regulations with no single authoritative standard. Watch for the administration’s implementation plan, which could arrive in the coming months and will signal whether harmonization moves from priority to practice. The GAO also has ongoing work to obtain additional industry perspectives on federal cybersecurity regulations, which could inform future legislative or regulatory action to consolidate reporting requirements.
— Sofia Alvarez, government desk, AXO News


