TSA Revises Cybersecurity Info Collection for Surface Transport
Published Date: 9/1/2026
Notice
Summary
This notice announces that the Transportation Security Administration (TSA) has forwarded the Information Collection Request (ICR), Office of Management and Budget (OMB) control number 1652-0074, abstracted below, to OMB for a revision of the currently approved collection under the Paperwork Reduction Act (PRA). The ICR describes the nature of the information collection and its expected burden. The collection involves the designation of a Cybersecurity Coordinator; the reporting of cybersecurity incidents to the Cybersecurity and Infrastructure Security Agency; the development of a cybersecurity contingency/recovery plan to address cybersecurity gaps; and the completion of a cybersecurity assessment.
Analyzed Economic Effects
5 provisions identified: 2 benefits, 3 costs, 0 mixed.
Designate Cybersecurity Coordinators
If you are an Owner/Operator covered by 49 CFR parts 1580, 1582, or 1584, you must designate a primary and at least one alternate Cybersecurity Coordinator and submit documentation. As of a January 15, 2026 revision, any non-U.S. citizen serving as a primary or alternate coordinator must be a current member of NEXUS, Global Entry, or another TSA‑determined comparable program.
Plans and Annual Assessment Reports Required
Covered Owner/Operators must develop and submit Cybersecurity Incident Response Plans and Cybersecurity Implementation Plans, complete cybersecurity vulnerability assessments (where required), conduct annual cybersecurity assessments, and submit annual Cybersecurity Assessment Plan reports to TSA. TSA also requires periodic updates to these plans and reports.
Estimated Respondents and Burden Reduced
TSA updated its estimates: the number of respondents is now estimated at 67 and the total estimated annual burden hours are 22,167 (revised down from 846 respondents and 210,684 hours).
Mandatory Incident Reporting Timeline
Owner/Operators must report cybersecurity incidents to the Cybersecurity and Infrastructure Security Agency no later than 72 hours after the Owner/Operator identifies an incident. TSA also recommends (via IC Surface-2025-01) notifying TSA's Operations Center as soon as possible and no more than 12 hours after discovery for actual or potential significant incidents.
Removal of Certain Mandatory Rail Assessment
TSA revised the collection to remove the mandatory cybersecurity vulnerability assessment requirement for rail Owner/Operators subject to SD 1580-21-01 and SD 1582-21-01 because those rail Owner/Operators have satisfied the SD requirements.
Personalized for You
How does this regulation affect your finances?
Personalize government policy and PRIA will tell you what this federal register document means for your household, plus every other regulation we track. PRIA reads each provision against your financial profile to show you exactly what matters to your wallet.
Key Dates
Department and Agencies
Related Federal Register Documents
2026-16991, Extension of Agency Information Collection Activity Under OMB Review: Security Threat Assessment for Individuals Applying for a Hazardous Materials Endorsement for a Commercial Driver's License
This notice announces that the Transportation Security Administration (TSA) has forwarded the Information Collection Request (ICR), Office of Management and Budget (OMB) control number 1652-0027, abstracted below to OMB for review and approval of extension of the currently approved collection under the Paperwork Reduction Act (PRA). The ICR describes the nature of the information collection and its expected burden. The collection involves the submission of biometric and biographic information that TSA uses to verify identity and conduct a Security Threat Assessment (STA), used to issue a Hazardous Materials Endorsement to the Commercial Driver's License, and a customer satisfaction survey.
2026-14855, Intent To Request Extension From OMB of One Current Public Collection of Information: Transportation Security Officer Medical Questionnaire
The TSA is asking to keep using its medical questionnaire for Transportation Security Officer (TSO) candidates to make sure they’re fit for the job. They want to extend this paperwork approval and are inviting the public to share thoughts by September 21, 2026. This won’t cost extra money but helps keep airport security strong and safe!
2026-14074, New Agency Information Collection Activity Under OMB Review: Insider Threat Incident Reporting Tool
The TSA is rolling out a new tool for the public to report insider threats—people who might cause security problems from the inside. They’re asking for your feedback by August 12, 2026, to make sure this tool works well and isn’t too much hassle. This new process aims to keep everyone safer without costing extra money or time.
2026-13098, Crewmember Access Point
Starting January 1, 2027, aircraft operators who want their crewmembers to skip long security lines at certain U.S. airports will pay a $19 yearly fee per employee to join the Crewmember Access Point program. This change affects airlines like Delta, American, and FedEx, making it easier and faster for their crews to get through security while helping TSA keep things safe. Operators will get clear instructions on how to sign up and pay the fee.
2026-11784, New Agency Information Collection Activity Under OMB Review: Real-Time Wait-Time Dashboarding
The TSA is asking for approval to collect real-time wait-time data from airports to help passengers know how long security lines are. This info won’t include any personal details and will be gathered electronically. If you want to share your thoughts, you have until July 13, 2026, to comment before the plan moves forward.
2026-11552, Temporary Exemption for Certain Over-the-Road Bus Owner/Operators That Provide Fixed-Route Service to the Public
The TSA is giving certain bus owner/operators a temporary break from some security training rules so they can run fixed-route services during the FIFA World Cup 2026. This exemption covers buses traveling through or starting/ending in key U.S. cities hosting the event, from June 10 to July 31, 2026. It helps buses get fans where they need to go without extra paperwork, making the big soccer event smoother and more fun!
Previous / Next Documents
Previous: 2026-17892, Deregistration Under Section 8(f) of the Investment Company Act of 1940
Applicant, a closed-end investment company, seeks an order declaring that it has ceased to be an investment company. The applicant has transferred its assets to First Trust Active Global Quality Income ETF, a series of First Trust Exchange-Traded Fund VIII, and on November 11, 2023 made a final distribution to its shareholders based on net asset value. Expenses of $509,897.68 incurred in connection with the reorganization were paid by the applicant. Filing Date: The application was filed on July 29, 2026. Applicant's Address: 120 East Liberty Drive, Suite 400, Wheaton, Illinois 60187.
Next: 2026-17896, Center for Scientific Review; Notice of Closed Meetings
The NIH’s Center for Scientific Review is holding several closed virtual meetings in October 2026 to review and decide on grant applications. These meetings protect private info and trade secrets while helping decide who gets research funding. Scientists applying for grants should note these dates as they impact funding decisions but don’t involve public attendance or new costs.