GAO Confirms Cyber Reporting Burdens as CIRCIA Rules Loom The Government Accountability Office (GAO) released on July 22 a comprehensive assessment of federal cybersecurity requirements, and its conclusion will sound familiar to many regulated companies: overlapping requirements are widespread, reporting obligations are duplicative, and harmonization efforts have not worked. In its report, Cybersecurity Regulations: Multiple Sectors Are Subject to Potentially Duplicative Reporting Requirements (GAO-26-108606), GAO examined cybersecurity regulations affecting private sector entities across critical infrastructure and found a substantial amount of potential for duplication and conflict across the federal government. The report arrives at a particularly apt time, as the Cybersecurity and Infrastructure Security Agency (CISA) moves toward finalizing new reporting regulations under the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA). GAO Finds Substantial Regulatory Overlap GAO identified a whopping 117 existing cybersecurity regulations administered by 37 federal agencies across nine critical infrastructure sectors. Of those, it found that 80 regulations (about 70%) have affirmative reporting requirements, collectively imposing at least 125 separate reporting obligations on private sector entities. These obligations include cyber incident reporting, submission of cybersecurity plans and technical information, and reporting related to audits, reviews, and assessments. The report found that many regulations require regulated entities to provide similar information to different federal agencies, such that companies may need to prepare multiple reports concerning the same cybersecurity event or compliance activity. GAO highlighted potential overlap across all three reporting categories, including 48 regulations requiring cyber incident reporting, 52 requiring cybersecurity plans or technical information, and 25 requiring audits, reviews, or assessments. (And this does not even touch on state obligations, which are proliferating). This figure from the GAO report shows the number and nature of the requirements: GAO's findings reinforce concerns that industry and cyberattack victims have raised for years. As Wiley previously observed,