Opportunity

Federal Register #2026-17894

TSA Cybersecurity Information Collection Revision for Surface Transportation

Buyer

Transportation Security Administration

Posted

September 01, 2026

Respond By

October 01, 2026

Identifier

2026-17894

NAICS

926120

This opportunity concerns the Transportation Security Administration (TSA), part of the Department of Homeland Security, revising its cybersecurity information collection requirements for surface transportation modes. - Government Buyer: - Transportation Security Administration (TSA), Department of Homeland Security - OEMs and Vendors: - No specific OEMs or vendors are named; this is a regulatory notice - Products/Services Requested: - Designation of Cybersecurity Coordinators (with new requirements for non-U.S. citizens) - Mandatory reporting of cybersecurity incidents to the Cybersecurity and Infrastructure Security Agency - Development and periodic updating of cybersecurity contingency/recovery and incident response plans - Completion and submission of cybersecurity vulnerability and assessment plans - Annual submission of cybersecurity assessment reports - Unique/Notable Requirements: - Non-U.S. citizen Cybersecurity Coordinators must be members of trusted traveler programs - Applies to owner/operators in freight rail, mass transit, passenger rail, and over-the-road bus sectors - Focus is on regulatory compliance and information collection, not procurement of goods or services

Description

This notice announces that the Transportation Security Administration (TSA) has forwarded the Information Collection Request (ICR), Office of Management and Budget (OMB) control number 1652-0074, to OMB for a revision of the currently approved collection under the Paperwork Reduction Act (PRA). The collection involves the designation of a Cybersecurity Coordinator; the reporting of cybersecurity incidents to the Cybersecurity and Infrastructure Security Agency; the development of a cybersecurity contingency/recovery plan to address cybersecurity gaps; and the completion of a cybersecurity assessment. The revision includes updates to requirements for Cybersecurity Coordinators, incident reporting, and cybersecurity plans for surface transportation modes including rail and bus.

View original listing