2026-17894NoticeWallet

TSA Revises Cybersecurity Info Collection for Surface Transport

Published Date: 9/1/2026

Notice

Summary

This notice announces that the Transportation Security Administration (TSA) has forwarded the Information Collection Request (ICR), Office of Management and Budget (OMB) control number 1652-0074, abstracted below, to OMB for a revision of the currently approved collection under the Paperwork Reduction Act (PRA). The ICR describes the nature of the information collection and its expected burden. The collection involves the designation of a Cybersecurity Coordinator; the reporting of cybersecurity incidents to the Cybersecurity and Infrastructure Security Agency; the development of a cybersecurity contingency/recovery plan to address cybersecurity gaps; and the completion of a cybersecurity assessment.

Analyzed Economic Effects

5 provisions identified: 2 benefits, 3 costs, 0 mixed.

Designate Cybersecurity Coordinators

If you are an Owner/Operator covered by 49 CFR parts 1580, 1582, or 1584, you must designate a primary and at least one alternate Cybersecurity Coordinator and submit documentation. As of a January 15, 2026 revision, any non-U.S. citizen serving as a primary or alternate coordinator must be a current member of NEXUS, Global Entry, or another TSA‑determined comparable program.

Plans and Annual Assessment Reports Required

Covered Owner/Operators must develop and submit Cybersecurity Incident Response Plans and Cybersecurity Implementation Plans, complete cybersecurity vulnerability assessments (where required), conduct annual cybersecurity assessments, and submit annual Cybersecurity Assessment Plan reports to TSA. TSA also requires periodic updates to these plans and reports.

Estimated Respondents and Burden Reduced

TSA updated its estimates: the number of respondents is now estimated at 67 and the total estimated annual burden hours are 22,167 (revised down from 846 respondents and 210,684 hours).

Mandatory Incident Reporting Timeline

Owner/Operators must report cybersecurity incidents to the Cybersecurity and Infrastructure Security Agency no later than 72 hours after the Owner/Operator identifies an incident. TSA also recommends (via IC Surface-2025-01) notifying TSA's Operations Center as soon as possible and no more than 12 hours after discovery for actual or potential significant incidents.

Removal of Certain Mandatory Rail Assessment

TSA revised the collection to remove the mandatory cybersecurity vulnerability assessment requirement for rail Owner/Operators subject to SD 1580-21-01 and SD 1582-21-01 because those rail Owner/Operators have satisfied the SD requirements.

Personalized for You

How does this regulation affect your finances?

Personalize government policy and PRIA will tell you what this federal register document means for your household, plus every other regulation we track. PRIA reads each provision against your financial profile to show you exactly what matters to your wallet.

Key Dates

Published Date
Comments Due
9/1/2026
10/1/2026

Department and Agencies

Department
Independent Agency
Agency
Homeland Security Department
Transportation Security Administration
Source: View HTML

Related Federal Register Documents

Previous / Next Documents

Back to Federal Register