# GAO Highlights Conflicting Cybersecurity Rules

A Government Accountability Office report published September 29, 2026, highlights industry concerns that overlapping federal cybersecurity rules impose conflicting incident-reporting thresholds, timelines, and definitions across critical infrastructure sectors. The report points to CISA’s forthcoming incident-reporting rule and possible harmonization efforts as developments that could affect contractors’ reporting obligations and create demand for regulatory mapping and cybersecurity compliance support. It identifies no specific procurement or solicitation.

- Contractors serving critical infrastructure should map applicable incident-reporting thresholds, timelines, and definitions to identify conflicts across federal rules.
- CISA’s forthcoming rule could change reporting requirements; organizations providing compliance or reporting support may find demand for services that address the regulatory overlap described in the report.
- Procurement teams can use the findings to assess whether existing contractor reporting processes and support services account for differing agency requirements.

**Jurisdictions:** federal
**Industries:** Information Technology
**Topics:** Cybersecurity, Regulatory Compliance
**Published:** September 29, 2026

### Government Entities
- Government Accountability Office (GAO)
- Cybersecurity and Infrastructure Security Agency (CISA)
- Securities and Exchange Commission (SEC)
- Transportation Security Administration (TSA)
- National Credit Union Administration (NCUA)

### Key Quotes
> Cybersecurity professionals should be focused on staying ahead of increasingly sophisticated threats — not spending scarce time and resources navigating conflicting and duplicative requirements.
> — Henry Young, Senior Director of Policy, BSA

### Sources
- [GAO report spotlights industry’s concerns about overlapping cybersecurity regulations | Cybersecurity Dive](https://www.cybersecuritydive.com/news/cybersecurity-regulation-industry-feedback-harmonization-gao/831619) - Cybersecurity Dive