What GAO Found GAO identified 117 cybersecurity regulations established by 37 federal agencies for private entities, spanning nine critical infrastructure sectors. Most of those regulations either contain the same kind of reporting requirement applicable to a sector or the same reporting requirement as at least one other regulation, which may lead to duplication. Specifically, 80 of the 117 regulations (about 70 percent) had at least 125 total reporting requirements (see figure), with some regulations requiring multiple types of reporting.
Cybersecurity Regulations: Multiple Sectors Are Subject to Potentially Duplicative Reporting Requirements
calendar_today
July 22, 2026
domain
government-accountability-office