Evidence record 12730 · automatically gathered

Cybersecurity Regulations: Multiple Sectors Are Subject to Potentially Duplicative Reporting Requirements

What GAO Found GAO identified 117 cybersecurity regulations established by 37 federal agencies for private entities, spanning nine critical infrastructure sectors. Most of those regulations either contain the same kind of reporting requirement applicable to a sector or the same reporting requirement as at least one other regulation, which may lead to duplication. Specifically, 80 of the 117 regulations (about 70 percent) had at least 125 total reporting requirements (see figure), with some regul

Record details

Published: 22 July 2026
Source: US GAO Reports
Category: Policy
Topics: Regulation
Retrieved: 23 July 2026

source-onlyevidence status

These records share source-supplied organisations, an exact publisher byline, automatic topics or regions. The reason is shown on every link; related does not mean supporting, agreeing with or verifying this record.

How to cite this record

ethics.ai (22 July 2026), “Cybersecurity Regulations: Multiple Sectors Are Subject to Potentially Duplicative Reporting Requirements,” evidence record 12730, https://ethics.ai/record/12730 (originally published by US GAO Reports).

JSON

Use and limitations

This page is a stable index and citation surface for a source record. ethics.ai did not author the underlying report and has not independently verified every claim. Automatic topics may be imperfect. For consequential use, quote and cite the original publisher.