Compliance Pulse — Thursday, July 23, 2026

GAO Counts 117 Federal Cyber Regulations — What Overlap Costs Maritime and Defense Operators

July 23, 2026

Compliance Pulse · Thursday, July 23, 2026


Most compliance leaders track the rule that governs their own sector. That is the right instinct — for now. But GAO published a count on Wednesday: 117 federal cybersecurity regulations across 37 agencies, roughly 70 percent carrying reporting requirements that duplicate another rule. Meanwhile the FAR CUI comment window closes today.

USCG Subpart F: Under Twelve Months to an Approved Cyber Plan

The Coast Guard's Cybersecurity in the Marine Transportation System rule took effect July 16, 2025. Two phases have closed: incident reporting to the National Response Center from the effective date, and annual training under 33 CFR 101.650 from January 12, 2026.

The final phase lands July 16, 2027. By that date, owners and operators of U.S.-flagged vessels, MTSA-regulated facilities, and OCS facilities must designate a Cybersecurity Officer, complete a Cybersecurity Assessment, and submit a Cybersecurity Plan for Coast Guard approval under 33 CFR 104.410, 105.410, and 106.410.

Read that verb carefully. The plan must be submitted for approval, not merely written. Coast Guard review time is not the operator's to control, and it does not extend the deadline.

Bottom line for maritime operators and port facility owners: Less than twelve months remain, and the assessment feeding the plan has to finish well before submission.

FAR Case 2026-001: The CUI Comment Window Closes Today

The FAR Council published its Revolutionary FAR Overhaul package at 91 FR 37550 on June 23. Comments close today alongside companion cases 2026-002, 2026-005, and 2026-007.

The substance outlasts the deadline. FAR Part 40 is reorganized, and a new clause — FAR 52.240-7 — carries NIST SP 800-171 Rev. 3 into any contract involving CUI, at any dollar value. Contracts solely for commercial off-the-shelf items are generally exempt; most service and support work is not. A new Standard Form will identify the CUI involved and how it must be safeguarded. CUI incident reporting moves to 72 hours from discovery — DoD contractors through DIBNet, civilian-agency contractors through CISA.

Bottom line for federal contractors and their CFOs: Rev. 3 is no longer a DoD conversation. Contract eligibility across the civilian agencies is being rewritten around it.

GAO-26-108606: The Overlap Now Has a Number

GAO published the count July 22: 117 cybersecurity regulations from 37 federal agencies across nine critical infrastructure sectors. Eighty of those — roughly 70 percent — duplicate the reporting requirement of at least one other rule.

CIRCIA's final rule is targeted for September 2026, adding 72-hour incident and 24-hour ransomware payment reporting across sixteen sectors. A maritime facility that also qualifies as critical infrastructure can owe the National Response Center, CISA under CIRCIA, and — with a federal contract — CUI reporting under the new FAR clause. CIRCIA's substantially-similar exception relieves that duplication only where a formal agreement exists between the sector regulator and CISA.

Bottom line for CISOs and board members: This is not one reporting clock. Budget and staff it as several.

What This Means for Multi-Framework Operators

Every organization here is being asked the same question by three different agencies, on three different timelines, in three different formats. The operators who handle 2027 well will build one incident-reporting capability and map it outward to each regime, rather than standing up a separate program each time a rule lands. That capability protects contract eligibility, port access, and the client trust that survives public disclosure.

The organizations that treat convergence as an architecture problem will spend less than the ones that treat it as a paperwork problem.

Which of these three clocks is furthest along in your program — and which one has no owner yet? I would like to hear how maritime and DIB teams are sequencing the work.

Back to Blog