Eighty of 117 federal cybersecurity regulations had the same type of reporting requirement as at least one other rule, creating potential duplication for companies that operate critical infrastructure, according to GAO.
The watchdog's inventory covered rules issued by 37 federal agencies across nine critical-infrastructure sectors. Roughly 70% contained a reporting category that appeared elsewhere in the regulatory set.

A shared category does not automatically prove that two rules conflict or require an identical filing. GAO used it as a screen for potential duplication that may impose redundant or inconsistent duties on regulated entities.
Requirements can apply at different moments and for different purposes. Companies may have to report incidents, disclose cybersecurity plans, document risk management or notify agencies and investors under separate authorities.
GAO cited Securities and Exchange Commission requirements for public companies as one example that can overlap with sector-specific obligations. An entity operating in more than one regulated role can face several reporting clocks and formats.
Most U.S. critical-infrastructure information systems are privately owned, while federal agencies regulate distinct safety, financial, communications and security missions. That divided authority helps explain why reporting rules accumulated across agencies.

The administration intends to issue an implementation plan to streamline cybersecurity regulation. GAO's inventory supplies a baseline for that work but does not itself repeal, consolidate or suspend any requirement.
Streamlining also carries a tradeoff: a filing that looks duplicative to a company may provide different information to agencies with different mandates. Any consolidation must preserve the timeliness and detail needed for response and oversight.
The report's practical test is therefore narrower than the headline count. Regulators must determine which of the 80 flagged rules can share definitions, forms or submission channels without creating gaps in public protection.
