GAO third panel finds CIRCIA and SEC rules conflict with sector regs
After two rounds of industry feedback, the picture isn't improving: energy, financial, and healthcare participants say reporting thresholds, timelines, and definitions across federal rules can't all be met.
TL;DR
GAO's third industry panel report, delivered September 28 to Senators Peters and Garbarino, documents conflicts between CISA's proposed CIRCIA rule, the SEC's 2023 cyber disclosure rules, and sector-specific regulations, NERC-CIP, TSA pipeline requirements, HIPAA, the Bank Secrecy Act, and others. Participants from energy, financial services, and healthcare and public health each described reporting thresholds, timelines, and definitions that diverge across the rules they're subject to. Most participants said federal harmonization progress over the past year has been limited. The panel floated establishing a single entity with authority over regulatory consistency.
GAO has now run three industry panels on cyber regulatory harmonization at the request of Senate Homeland Security ranking member Gary Peters and House Homeland Security Chairman Andrew Garbarino. The first two, published in July 2025 and March 2026, surfaced overlapping regulations and administrative burden. This third round (delivered September 28 and summarizing a July 16, 2026 panel) gets more concrete about where the conflicts actually sit.
Participants from energy, financial services, and healthcare and public health identified specific incompatibilities between CISA's proposed CIRCIA rule, the SEC's 2023 cyber incident disclosure rules, and their own sector regulations. The GAO report states that "most participants noted that reporting thresholds, timelines, and definitions in these rules conflicted with regulations from their sector, making it difficult to fully satisfy all reporting requirements and remediate cyber threats within the required time frames."
For energy, the conflict set includes NERC-CIP standards, DOE's Form 417, and TSA's pipeline cybersecurity requirements, which GAO describes as having "duplicative and conflicting cyber incident reporting requirements." One participant also flagged potential duplication between government acquisition rules, CMMC, and GSA's CUI requirements.
Financial sector participants layered CIRCIA and the SEC rules on top of NCUA requirements and the Bank Secrecy Act. Healthcare and public health participants pointed to HIPAA breach rules and ONC information-blocking rules as additional frameworks that don't align cleanly with the cross-sector mandates.
The harmonization picture isn't getting better
"Most participants stated that there has been some progress made in working toward federal cybersecurity regulatory harmonization for their respective sectors over the past year," the report says. "However, several participants agreed that the federal government's progress has been limited in harmonizing existing duplication and addressing conflicts among cybersecurity regulations."
That's the third report in a row saying essentially the same thing. GAO's own regulatory mapping, published separately in July 2026, found that 80 of 117 cybersecurity regulations (roughly 70%) contain the same kind of reporting requirement as at least one other regulation.
What industry wants
The participants' top ask is straightforward: harmonize incident reporting. "Most participants stated that cybersecurity incident reporting and the related reporting time frames, thresholds, and definitions should be harmonized," the report says. They also floated establishing a single entity with authority over regulatory consistency and called for more ongoing collaboration between agencies and industry.
None of these recommendations are new. What's notable is that after three rounds of panels and GAO's own regulatory inventory confirming the scope of the problem, the recommendation list hasn't changed, because the underlying conflicts haven't either.
Published ·Deep Fathom