TSA Revises Surface-Mode Cybersecurity ICR, Routes Incidents to CISA
The revision formalizes what had been guidance-era incident reporting, pulling surface transportation operators into CISA's growing pipeline of mandatory disclosures.
TL;DR
TSA forwarded a revised Information Collection Request (OMB control number 1652-0074) to OMB for the surface-mode cybersecurity program, updating incident reporting to CISA, cybersecurity assessment requirements, and contingency planning obligations. The ICR covers designation of a Cybersecurity Coordinator, incident reporting, development of a contingency and recovery plan, and completion of a cybersecurity assessment. The notice was published September 1, 2026; the prior ICR extension dates to April 2022.

TSA's surface-mode cybersecurity program now has a revised paperwork backbone. The September 1 notice forwards the updated ICR to OMB, replacing the extension that's been running since April 2022. The collection covers four items: designating a Cybersecurity Coordinator, reporting cybersecurity incidents to CISA, developing a contingency and recovery plan, and completing a cybersecurity assessment.
The notice itself is skeletal. It doesn't disclose the revised burden estimate, the specific surface modes in scope, or which pieces of the collection changed from the prior version. What it does signal is that TSA has moved beyond the 2021 emergency directive and 2022 proposed rulemaking posture into a formal, OMB-reviewed collection framework. That's a procedural escalation: the ICR is the mechanism through which TSA can require covered entities to produce incident data, and if it lapses, the authority to demand that information goes with it.
The CISA reporting channel is the operational thread to watch. The ICR routes incident reports to CISA rather than keeping them inside TSA, which means surface transportation incidents now feed the same pipeline as CIRCIA-covered critical infrastructure sectors. Whether the reporting timelines and thresholds align across the two frameworks is an open question the notice doesn't answer. For compliance directors at freight rail, passenger rail, and over-the-road bus operators (the modes covered under the 2022 directives) the practical question is whether the revised ICR imposes a different reporting cadence than what their teams already built around the 24-hour CISA notification window in the existing security directives.
Until TSA publishes the supporting statement with the full burden estimate and item-by-item changes, the only thing that's clear is that the collection isn't going away. It's being tightened.
Published ·Deep Fathom