One Incident, Several Reports: What GAO's Panel & CISA's Town Halls Say About Harmonization

By Patrick Miller

A single cyber incident at a utility can owe reports to several federal agencies, each with its own clock and definition. The Government Accountability Office's latest panel heard that again, and electric, gas, oil, and water groups told the Cybersecurity and Infrastructure Security Agency the same thing in June. This post looks at where the overlap sits and where the reporting rule stands.

Overview

The Government Accountability Office (GAO) released the third report in its series on cybersecurity regulatory harmonization on September 28, 2026, and for the energy sector it mostly confirms what the sector has been saying for a while now. The report summarizes a single three-hour panel held on July 16, 2026, with six industry representatives, two each from energy, financial services, and healthcare and public health. Every sector identified federal cybersecurity rules it considered duplicative or conflicting, and most participants pointed to either the Cybersecurity and Infrastructure Security Agency's (CISA) proposed rule under the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) or the Securities and Exchange Commission's (SEC) disclosure rules as colliding with their own sector's requirements. I think the energy detail in the report is thin, but it lines up closely with what electric, gas, oil, and water organizations told CISA on the record at the CIRCIA town halls a month earlier.

Who Was on the Panel, and What the Numbers Mean

GAO picked participants from organizations that had filed public comments on the CIRCIA proposal or on the Office of the National Cyber Director's 2023 harmonization request for information. The energy seats went to the Edison Electric Institute (EEI) and the Electric Power Supply Association, so the energy view in this report comes from the investor-owned utilities and competitive suppliers those two associations represent. Cooperatives and municipal utilities weren't at the table, and neither were transmission-only entities. The report says the summary doesn't necessarily reflect a unanimous view of the panel or a collective view of any sector, and it defines its own quantifiers, so "a few" means one or two participants, "several" means three, and "most" means four or more. Most of the energy-specific findings are attributed to "a few" participants or to "one participant," so I'd be careful about reading the report as the energy sector's comprehensive position.

The financial and healthcare material is more specific on timelines. A few financial services participants described reporting a single incident within 72 hours to the National Credit Union Administration, within 24 to 72 hours under the proposed CIRCIA rule depending on the incident type, and within four business days under the SEC's rules, each with its own definition of what counts. The healthcare participants described the same problem across CIRCIA, the SEC, and the Health Insurance Portability and Accountability Act breach rules.

The Energy Stack

Energy participants identified eight federal regulations they viewed as duplicative or conflicting, the two cross-sector rules plus six of their own. A few said overlapping requirements often mean reporting the same incident to multiple agencies, each on its own timeline, and they named the North American Electric Reliability Corporation's (NERC) Critical Infrastructure Protection (CIP) standards, the Department of Energy's (DOE) Form OE-417, and the Transportation Security Administration's (TSA) pipeline security directives. One participant added the Federal Acquisition Regulation, the Defense Federal Acquisition Regulation Supplement and its Cybersecurity Maturity Model Certification clause, and the General Services Administration's controlled unclassified information policy.

GAO's separate July 2026 review counted 117 federal cybersecurity regulations from 37 agencies, and of the 19 it attributes to energy, only two require incident reporting, Form OE-417 and CIP-008-6. TSA's pipeline directive is counted under transportation and the Nuclear Regulatory Commission's rules under nuclear, so I'd read most of what an energy company stacks as coming from rules written for other sectors, or for everyone.

The thresholds under those reports don't agree either. CIP-008-6 reporting runs to the Electricity Information Sharing and Analysis Center (E-ISAC) and CISA, and NERC's 2024 annual report on Cyber Security Incidents counted sixteen reports across the standard's first four years, none of them a Reportable Cyber Security Incident. OE-417 asks a different question at a different threshold, and the gap between what utilities reported to DOE and what reached NERC was part of the record behind the Federal Energy Regulatory Commission's Order No. 848, as we laid out in our post on the E-ISAC's 2025 report. The same NERC filing notes that entities can already submit CIP-008-6 reports on the OE-417 form, so the electric sector has a small working example of one form serving two regimes.

One participant also raised a conflict between CIP's information safeguarding requirements and reporting rules that call for sensitive incident detail to go to regulators. GAO doesn't elaborate, and nobody at the town halls raised it in those terms, so this is my read and not the panel's. I think it's probably a CIP-011 problem, since the details that make an incident report useful may qualify (depending on the situation) as Bulk Electric System (BES) Cyber System Information. Concern about where that information ends up is part of why some entities disclose only what's required, a point we made in 2025.

What the Electric Sector Told CISA on the Record

Unlike GAO's confidential panel, CISA's four virtual town halls on June 15 through 18, 2026 are on the record, with transcripts in the CIRCIA docket. EEI was on the GAO panel and also spoke at the June 18 session, where Jennifer DeCesaro said electric companies already report through NERC, DOE, TSA, and state authorities, and asked CISA to fully use the substantially similar reporting exception, broaden it so it reaches existing regimes, clarify how reports sent to other agencies count, and lean on interagency data sharing over repeated submissions. That's EEI's public position, but the GAO report doesn't say which participant said what, so I wouldn't tie any particular line in the report to her.

The cooperatives and municipals who weren't on GAO's panel made the same point at the town halls. At the June 17 session, John Ransom of the National Rural Electric Cooperative Association (NRECA) asked that the agreements between CISA and agencies like NERC be finalized and in effect before any entity with an existing reporting obligation has to report under CIRCIA. He also argued the proposal's electric-sector criteria sweep in effectively every utility, around 3,000 by his count, because nearly all of them file OE-417. CISA's Nichole Clagett read the proposal differently, saying OE-417 filers would only need to report under CIRCIA if they mark the form's cyber cause checkbox. The final rule will have to settle which reading holds. At the same session, Tim Pospisil of Nebraska Public Power District, whose utility reports under both NERC and nuclear requirements, said he could see reporting five different ways to five different entities, and Andrew Thome of Energy Northwest suggested CISA act as an aggregator of data other agencies already collect. At the June 18 session, Latif Nurani of the American Public Power Association asked to see how coordination with DOE and NERC will work before the rule is final, so utilities aren't filing three reports during one incident.

"The objective should be one report that satisfies multiple federal requirements where information is [substantially] the same." (Industry panel participant, GAO-26-109197)

Oil and Gas See the Overlap Inside DHS

GAO's energy participants named TSA's pipeline directives, and the oil and gas associations at the town halls described the overlap at the department level. At the June 18 session, Suzanne Lemieux of the American Petroleum Institute noted her members already report to TSA and the Coast Guard, both components of the Department of Homeland Security (DHS), the same department as CISA, and asked that CIRCIA align with rules DHS already runs. Jeff Gunnulfsen of the American Fuel and Petrochemical Manufacturers listed TSA, the Coast Guard, the SEC, and the Department of Defense, plus international regimes, and asked that the trigger be a confirmed cyber incident, since a site may need the full 72 hours just to confirm one. The American Chemistry Council described a single facility with a pipeline regulated by TSA, a port regulated by the Coast Guard, and defense obligations on top.

The gas associations focused on report content. At the June 16 session, Maggie O'Connell of the Interstate Natural Gas Association of America (INGAA) and Chandler Holgate of the American Gas Association (AGA) each asked CISA to limit the first 72-hour report to the incident's impact and severity, its estimated timeline, and indicators of compromise. Both argued that when a vendor is the one compromised, the vendor should report, since customers won't have the technical detail. INGAA also raised the security of whatever CISA collects, pointing to the 2024 Ivanti exploitation that led to a breach of CISA's own Chemical Security Assessment Tool, and AGA made a similar point about aggregated data becoming a target. That's a different concern from the CIP-011 question above, since it's about the recipient's systems rather than a conflict between rules.

Water, and the State Layer

Water wasn't part of GAO's panel, but the American Water Works Association (AWWA) spoke at the June 16 town hall. Kevin Morley asked CISA to drop "publicly owned" from the wastewater definition so privately owned treatment systems are treated consistently, and argued for a 50,000-population threshold like the one the proposal uses for emergency services, since small municipalities usually run information technology centrally and a reporting obligation on one department doesn't reduce anyone's burden. He also argued that because CIRCIA limits enforcement against state and local government entities, the rule would in practice fall on privately held systems, many of which already report to the SEC. That's his reading of the statute, and AWWA has its own stake in how federal water oversight gets built, since it backs the sector-led model in H.R. 2594.

New York community water systems serving more than 3,300 people have had to report cybersecurity incidents to the state Department of Health within 24 hours since March 11, 2026, which we covered when Appendix 5-E took effect. A New York system that's also a CIRCIA covered entity would face both clocks. New York's reporting form also lets a system send one report to the Department of Health, the Department of Environmental Conservation, and the Division of Homeland Security and Emergency Services at once, though only if all three are selected together and only for state agencies. Several town hall speakers asked CISA for something similar at the federal level. In our post on H.R. 2594 I asked whether a future federal water requirement would be a floor New York clears or a pattern it has to conform to, and CIRCIA raises the same question for reporting.

Narrower Triggers and the Poland Record

Many of the sector speakers at the town halls wanted a narrower trigger, whether that meant confirmed incidents, a clear line between events and incidents, or the significant cyber incident definition in Presidential Policy Directive 41. The second combined heat and power plant hit in Poland on December 29, 2025 first logged its attack as a contractor maintenance error and reported it "for informational purposes only," and it was only understood as a cyberattack because CERT Polska investigated anyway, as we covered in Part Two of our Poland coverage. Even in a US equivalent, I'm not sure that plant's incident would have reached a CIP-008 report. A plant that size might not have been BES at all, and even if it were, the obligation starts once someone recognizes the event as a Cyber Security Incident, which is exactly the determination the plant didn't make that morning.

Where CIRCIA Stands on September 30

GAO wrote that as of August 2026 the final CIRCIA rule was expected in September. As of September 30, CISA hadn't published it, and the rule wasn't under review at the White House Office of Information and Regulatory Affairs, which a significant rule like this one has to clear before it publishes. CISA's own regulatory agenda entry still projects a September 2026 final rule, against a statutory deadline of October 4, 2025. The proposed rule is still the only text on the table, and it said CISA would have to delay the effective date of the final rule by 60 days. GAO's July review also found that the Office of the National Cyber Director hadn't answered its questions on harmonization as of June 2026, and that as of May 2026 DHS hadn't reported progress on the Cyber Incident Reporting Council's September 2023 recommendations, which included model definitions of a reportable incident. The National Cyber Strategy released in March includes a pillar on streamlining cyber regulations, but GAO found the administration still hadn't released implementation plans for it as of July. On September 29, National Cyber Director Sean Cairncross said a lot of attention was going into harmonizing the reporting structure, without giving a date. When we wrote about ANCHOR-CI in July the town halls were still ahead, and with them done the rule is still pending.

The substantially similar reporting provision is where most of the energy asks converge, and GAO's footnote on it is the plainest description I've seen. A covered entity that reports substantially similar information to another federal agency, in a substantially similar time frame, doesn't have to report the same information to CISA, but only if CISA and that agency have an information sharing mechanism and agreement in place. GAO notes the provision could still change in the final rule. That's why I think NRECA's ask, agreements first and reporting second, matters more than any single definition, because without those agreements the exception probably doesn't help a registered entity that's already filing with the E-ISAC and DOE.

Sources and Further Reading

 

Featured Posts

Next
Next

When AI Changes Without a Change Request