Opportunity
Federal Register #2026-17894
TSA Cybersecurity Information Collection Revision for Surface Transportation
Buyer
Transportation Security Administration
Posted
September 01, 2026
Respond By
October 01, 2026
Identifier
2026-17894
NAICS
926120
This opportunity concerns the Transportation Security Administration (TSA), part of the Department of Homeland Security, revising its cybersecurity information collection requirements for surface transportation modes. - Government Buyer: - Transportation Security Administration (TSA), Department of Homeland Security - OEMs and Vendors: - No specific OEMs or vendors are named; this is a regulatory notice - Products/Services Requested: - Designation of Cybersecurity Coordinators (with new requirements for non-U.S. citizens) - Mandatory reporting of cybersecurity incidents to the Cybersecurity and Infrastructure Security Agency - Development and periodic updating of cybersecurity contingency/recovery and incident response plans - Completion and submission of cybersecurity vulnerability and assessment plans - Annual submission of cybersecurity assessment reports - Unique/Notable Requirements: - Non-U.S. citizen Cybersecurity Coordinators must be members of trusted traveler programs - Applies to owner/operators in freight rail, mass transit, passenger rail, and over-the-road bus sectors - Focus is on regulatory compliance and information collection, not procurement of goods or services
Description
This notice announces that the Transportation Security Administration (TSA) has forwarded the Information Collection Request (ICR), Office of Management and Budget (OMB) control number 1652-0074, to OMB for a revision of the currently approved collection under the Paperwork Reduction Act (PRA). The collection involves the designation of a Cybersecurity Coordinator; the reporting of cybersecurity incidents to the Cybersecurity and Infrastructure Security Agency; the development of a cybersecurity contingency/recovery plan to address cybersecurity gaps; and the completion of a cybersecurity assessment. The revision includes updates to requirements for Cybersecurity Coordinators, incident reporting, and cybersecurity plans for surface transportation modes including rail and bus.