{"description":"Documents matching 'cybersecurity'","count":4634,"total_pages":50,"next_page_url":"https://www.federalregister.gov/api/v1/documents?conditions%5Bterm%5D=cybersecurity&format=json&page=2","results":[{"title":"Revision of Agency Information Collection Activity Under OMB Review: Cybersecurity Measures for Surface Modes","type":"Notice","abstract":"This notice announces that the Transportation Security Administration (TSA) has forwarded the Information Collection Request (ICR), Office of Management and Budget (OMB) control number 1652-0074, abstracted below, to OMB for a revision of the currently approved collection under the Paperwork Reduction Act (PRA). The ICR describes the nature of the information collection and its expected burden. The collection involves the designation of a Cybersecurity Coordinator; the reporting of cybersecurity incidents to the Cybersecurity and Infrastructure Security Agency; the development of a cybersecurity contingency/recovery plan to address cybersecurity gaps; and the completion of a cybersecurity assessment.","document_number":"2026-17894","html_url":"https://www.federalregister.gov/documents/2026/09/01/2026-17894/revision-of-agency-information-collection-activity-under-omb-review-cybersecurity-measures-for","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2026-09-01/pdf/2026-17894.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2026-17894.pdf?1787948108","publication_date":"2026-09-01","agencies":[{"raw_name":"DEPARTMENT OF HOMELAND SECURITY","name":"Homeland Security Department","id":227,"url":"https://www.federalregister.gov/agencies/homeland-security-department","json_url":"https://www.federalregister.gov/api/v1/agencies/227","parent_id":null,"slug":"homeland-security-department"},{"raw_name":"Transportation Security Administration","name":"Transportation Security Administration","id":494,"url":"https://www.federalregister.gov/agencies/transportation-security-administration","json_url":"https://www.federalregister.gov/api/v1/agencies/494","parent_id":227,"slug":"transportation-security-administration"}],"excerpts":"Reduction Act (PRA). The ICR describes the nature of the information collection and its expected burden. The collection involves the designation of a <span class=\"match\">Cybersecurity</span> Coordinator; the reporting of <span class=\"match\">cybersecurity</span> incidents to the <span class=\"match\">Cybersecurity</span> and Infrastructure Security Agency; the development of a <span class=\"match\">cybersecurity</span> contingency/recovery plan to address <span class=\"match\">cybersecurity</span> gaps; and the completion of a <span class=\"match\">cybersecurity</span> assessment. \n \n \n DATES: \n Send your comments by October 1, 2026. A comment to OMB is most effective if OMB receives it within 30 days of publication"},{"title":"Intent To Request a Revision From OMB of One Current Public Collection of Information: Cybersecurity Measures for Surface Modes","type":"Notice","abstract":"The Transportation Security Administration (TSA) invites public comment on one currently-approved Information Collection Request (ICR), Office of Management and Budget (OMB) control number 1652-0074, abstracted below, that we will submit to OMB for a revision in compliance with the Paperwork Reduction Act (PRA). The ICR describes the nature of the information collection and its expected burden. The collection concerns data concerning the designation of a Cybersecurity Coordinator; the reporting of cybersecurity incidents to the Cybersecurity and Infrastructure Security Agency; the development of a cybersecurity contingency/recovery plan to address cybersecurity gaps; and the completion of a cybersecurity assessment.","document_number":"2026-07364","html_url":"https://www.federalregister.gov/documents/2026/04/16/2026-07364/intent-to-request-a-revision-from-omb-of-one-current-public-collection-of-information-cybersecurity","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2026-04-16/pdf/2026-07364.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2026-07364.pdf?1776257113","publication_date":"2026-04-16","agencies":[{"raw_name":"DEPARTMENT OF HOMELAND SECURITY","name":"Homeland Security Department","id":227,"url":"https://www.federalregister.gov/agencies/homeland-security-department","json_url":"https://www.federalregister.gov/api/v1/agencies/227","parent_id":null,"slug":"homeland-security-department"},{"raw_name":"Transportation Security Administration","name":"Transportation Security Administration","id":494,"url":"https://www.federalregister.gov/agencies/transportation-security-administration","json_url":"https://www.federalregister.gov/api/v1/agencies/494","parent_id":227,"slug":"transportation-security-administration"}],"excerpts":"(PRA). The ICR describes the nature of the information collection and its expected burden. The collection concerns data concerning the designation of a <span class=\"match\">Cybersecurity</span> Coordinator; the reporting of <span class=\"match\">cybersecurity</span> incidents to the <span class=\"match\">Cybersecurity</span> and Infrastructure Security Agency; the development of a <span class=\"match\">cybersecurity</span> contingency/recovery plan to address <span class=\"match\">cybersecurity</span> gaps; and the completion of a <span class=\"match\">cybersecurity</span> assessment. \n \n \n DATES: \n Send your comments by June 15, 2026. \n \n \n ADDRESSES: \n \n Comments may be emailed to \n TSAPRA@tsa.dhs.gov \n or delivered"},{"title":"Protecting the Nation's Communications Systems From Cybersecurity Threats","type":"Notice","abstract":"In this document, the Federal Communications Commission (\"Commission\" or \"FCC\") announces that it has reconsidered and rescinded a prior Declaratory Ruling and Notice of Proposed Rulemaking, neither of which had been published in the Federal Register. The Declaratory Ruling misconstrued the Communications Assistance for Law Enforcement Act (CALEA), and the Notice of Proposed Rulemaking was based in part on the Declaratory Ruling's flawed legal analysis and proposed ineffective cybersecurity requirements. This Order follows the FCC's engagement with providers to help strengthen their cybersecurity posture.","document_number":"2025-22830","html_url":"https://www.federalregister.gov/documents/2025/12/15/2025-22830/protecting-the-nations-communications-systems-from-cybersecurity-threats","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2025-12-15/pdf/2025-22830.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2025-22830.pdf?1765547125","publication_date":"2025-12-15","agencies":[{"raw_name":"FEDERAL COMMUNICATIONS COMMISSION","name":"Federal Communications Commission","id":161,"url":"https://www.federalregister.gov/agencies/federal-communications-commission","json_url":"https://www.federalregister.gov/api/v1/agencies/161","parent_id":null,"slug":"federal-communications-commission"}],"excerpts":"into their <span class=\"match\">cybersecurity</span> programs. CISA also provides voluntary tools and services to aid in strengthening <span class=\"match\">cybersecurity</span> practices, including the <span class=\"match\">Cybersecurity</span> Performance Goals (CPGs), which are baseline practices that critical infrastructure entities can use to manage and reduce <span class=\"match\">cybersecurity</span> risks. CISA's cross-sector CPGs provide sector-agnostic, prioritized guidance to help organizations focus resources on the most effective risk-reduction measures. To support CPG adoption, CISA offers Assessment Training with regional <span class=\"match\">cybersecurity</span> experts to"},{"title":"Modernization of the Nation's Alerting Systems; Protecting the Nation's Communications Systems From Cybersecurity Threats","type":"Rule","abstract":"In the Report and Order, the Federal Communications Commission (the FCC or the Commission) seeks to preserve the public's trust in the Emergency Alert System (EAS) by requiring targeted cybersecurity improvements that will help protect against hijacking by cybercriminals and our nation's adversaries.","document_number":"2026-15601","html_url":"https://www.federalregister.gov/documents/2026/07/31/2026-15601/modernization-of-the-nations-alerting-systems-protecting-the-nations-communications-systems-from","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2026-07-31/pdf/2026-15601.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2026-15601.pdf?1785415525","publication_date":"2026-07-31","agencies":[{"raw_name":"FEDERAL COMMUNICATIONS COMMISSION","name":"Federal Communications Commission","id":161,"url":"https://www.federalregister.gov/agencies/federal-communications-commission","json_url":"https://www.federalregister.gov/api/v1/agencies/161","parent_id":null,"slug":"federal-communications-commission"}],"excerpts":"commenters, such as NCTA, express concern that requiring EAS Participants to implement a specific <span class=\"match\">cybersecurity</span> framework would “freeze <span class=\"match\">cybersecurity</span> practices in time and hamper an EAS Participant's ability to develop and implement <span class=\"match\">cybersecurity</span> measures in response to its specific <span class=\"match\">cybersecurity</span> risk profile, to the detriment of public safety.” The requirements we adopt today will not hamper an EAS Participant's ability to respond to evolving <span class=\"match\">cybersecurity</span> threats. Rather, they represent a minimum acceptable baseline that will harden critical communications"},{"title":"Agency Information Collection Activities: State and Local Cybersecurity Grant Program (SLCGP) Evaluation","type":"Notice","abstract":"The Stakeholder Engagement Division (SED) Grant Analytics Branch within the Cybersecurity and Infrastructure Security Agency (CISA) submits the following Information Collection Request (ICR) to the Office of Management and Budget (OMB) for review and clearance in accordance with the Paperwork Reduction Act of 1995.","document_number":"2026-10893","html_url":"https://www.federalregister.gov/documents/2026/06/01/2026-10893/agency-information-collection-activities-state-and-local-cybersecurity-grant-program-slcgp","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2026-06-01/pdf/2026-10893.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2026-10893.pdf?1780058725","publication_date":"2026-06-01","agencies":[{"raw_name":"DEPARTMENT OF HOMELAND SECURITY","name":"Homeland Security Department","id":227,"url":"https://www.federalregister.gov/agencies/homeland-security-department","json_url":"https://www.federalregister.gov/api/v1/agencies/227","parent_id":null,"slug":"homeland-security-department"}],"excerpts":"governance structures, including by developing, implementing, or revising <span class=\"match\">Cybersecurity</span> Plans, to improve capabilities to respond to <span class=\"match\">cybersecurity</span> incidents and ensure continuity of operations. \n 2. Understand their current <span class=\"match\">cybersecurity</span> posture and areas for improvement based on continuous testing, evaluation, and structured assessments. \n 3. Implement security protections commensurate with risk. \n 4. Ensure organization personnel are appropriately trained in <span class=\"match\">cybersecurity</span> commensurate with responsibility. \n The evaluation will assess the SLCGP's"},{"title":"Infrastructure Security Division, Cybersecurity and Infrastructure Security Agency, Information Collection Activities; Submission to the Office of Management and Budget for Review and Approval; Comment Request; Cybersecurity and Infrastructure Security Agency Vulnerability Assessments","type":"Notice","abstract":"The Infrastructure Security Division, an office within Cybersecurity and Infrastructure Security Agency submits the following information collection request) to the Office of Management and Budget for review and clearance. The is an extension of a previously cleared information collection request on November 15, 2023, with an expiration date of November 30, 2026. The purpose of this notice is to allow additional 60 days for public comments.","document_number":"2026-16270","html_url":"https://www.federalregister.gov/documents/2026/08/11/2026-16270/infrastructure-security-division-cybersecurity-and-infrastructure-security-agency-information","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2026-08-11/pdf/2026-16270.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2026-16270.pdf?1786365908","publication_date":"2026-08-11","agencies":[{"raw_name":"DEPARTMENT OF HOMELAND SECURITY","name":"Homeland Security Department","id":227,"url":"https://www.federalregister.gov/agencies/homeland-security-department","json_url":"https://www.federalregister.gov/api/v1/agencies/227","parent_id":null,"slug":"homeland-security-department"}],"excerpts":"environment. \n \n The <span class=\"match\">Cybersecurity</span> and Infrastructure Security Agency Act of 2018 provides the <span class=\"match\">Cybersecurity</span> and Infrastructure Security Agency with a mission, mandate, and responsibility to take various measures and lead various efforts to help secure the nation's critical infrastructure. To support this mission, <span class=\"match\">Cybersecurity</span> and Infrastructure Security Agency's Infrastructure Security Division conducts voluntary on-site security and resiliency assessments for various critical infrastructure entities, which requires <span class=\"match\">Cybersecurity</span> and Infrastructure"},{"title":"Cybersecurity in the Marine Transportation System","type":"Rule","abstract":"The Coast Guard is updating its maritime security regulations by establishing minimum cybersecurity requirements for U.S.-flagged vessels, Outer Continental Shelf facilities, and facilities subject to the Maritime Transportation Security Act of 2002 regulations. This final rule addresses current and emerging cybersecurity threats in the marine transportation system by adding minimum cybersecurity requirements to help detect risks and respond to and recover from cybersecurity incidents. These include requirements to develop and maintain a Cybersecurity Plan, designate a Cybersecurity Officer, and take various measures to maintain cybersecurity within the marine transportation system. The Coast Guard is also seeking comments on a potential delay for the implementation periods for U.S.-flagged vessels.","document_number":"2025-00708","html_url":"https://www.federalregister.gov/documents/2025/01/17/2025-00708/cybersecurity-in-the-marine-transportation-system","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2025-01-17/pdf/2025-00708.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2025-00708.pdf?1736802922","publication_date":"2025-01-17","agencies":[{"raw_name":"DEPARTMENT OF HOMELAND SECURITY","name":"Homeland Security Department","id":227,"url":"https://www.federalregister.gov/agencies/homeland-security-department","json_url":"https://www.federalregister.gov/api/v1/agencies/227","parent_id":null,"slug":"homeland-security-department"},{"raw_name":"Coast Guard","name":"Coast Guard","id":53,"url":"https://www.federalregister.gov/agencies/coast-guard","json_url":"https://www.federalregister.gov/api/v1/agencies/53","parent_id":227,"slug":"coast-guard"}],"excerpts":"by establishing minimum <span class=\"match\">cybersecurity</span> requirements for U.S.-flagged vessels, Outer Continental Shelf facilities, and facilities subject to the Maritime Transportation Security Act of 2002 regulations. This final rule addresses current and emerging <span class=\"match\">cybersecurity</span> threats in the marine transportation system by adding minimum <span class=\"match\">cybersecurity</span> requirements to help detect risks and respond to and recover from <span class=\"match\">cybersecurity</span> incidents. These include requirements to develop and maintain a <span class=\"match\">Cybersecurity</span> Plan, designate a <span class=\"match\">Cybersecurity</span> Officer, and take various"},{"title":"Defense Federal Acquisition Regulation Supplement: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041)","type":"Rule","abstract":"DoD is issuing a final rule amending the Defense Federal Acquisition Regulation Supplement (DFARS) to incorporate contractual requirements related to the final Cybersecurity Maturity Model Certification program rule, titled Cybersecurity Maturity Model Certification Program. This final DFARS rule also partially implements a section of the National Defense Authorization Act for Fiscal Year 2020 that directed the Secretary of Defense to develop a consistent, comprehensive framework to enhance cybersecurity for the U.S. defense industrial base.","document_number":"2025-17359","html_url":"https://www.federalregister.gov/documents/2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2025-09-10/pdf/2025-17359.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2025-17359.pdf?1757421911","publication_date":"2025-09-10","agencies":[{"raw_name":"DEPARTMENT OF DEFENSE","name":"Defense Department","id":103,"url":"https://www.federalregister.gov/agencies/defense-department","json_url":"https://www.federalregister.gov/api/v1/agencies/103","parent_id":null,"slug":"defense-department"},{"raw_name":"Defense Acquisition Regulations System","name":"Defense Acquisition Regulations System","id":97,"url":"https://www.federalregister.gov/agencies/defense-acquisition-regulations-system","json_url":"https://www.federalregister.gov/api/v1/agencies/97","parent_id":103,"slug":"defense-acquisition-regulations-system"}],"excerpts":"Notice of <span class=\"match\">Cybersecurity</span> Maturity Model Certification Level Requirements (Nov 2025) \n \n (a) \n Definitions. \n As used in this provision, \n controlled unclassified information (CUI), current, \n \n <span class=\"match\">Cybersecurity</span> Maturity Model Certification (CMMC) status, <span class=\"match\">Cybersecurity</span> Maturity Model Certification unique identifier (CMMC UID), \n \n Federal contract information (FCI), \n and \n Plan of action and milestones \n have the meaning given in the Defense Federal Acquisition Regulation Supplement 252.204-7021, Contractor Compliance With the <span class=\"match\">Cybersecurity</span> Maturity"},{"title":"Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions; Guidance for Industry and Food and Drug Administration Staff; Availability","type":"Notice","abstract":"The Food and Drug Administration (FDA or Agency) is announcing the availability of a final guidance entitled \"Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions.\" This guidance updates the previous version of the guidance, of the same title, issued on September 27, 2023, and finalizes the draft guidance entitled \"Select Updates for the Premarket Cybersecurity Guidance: Section 524B of the FD&C Act\" issued on March 13, 2024. This guidance provides FDA's recommendations to industry regarding cybersecurity device design, labeling, and the documentation that FDA recommends be included in premarket submissions for devices with cybersecurity risk. Additionally, this guidance has been updated to identify the information FDA generally considers to be necessary for cyber devices to support obligations under the new amendments to the Federal Food, Drug, and Cosmetic Act (FD&C Act) for ensuring cybersecurity of devices.","document_number":"2025-11669","html_url":"https://www.federalregister.gov/documents/2025/06/27/2025-11669/cybersecurity-in-medical-devices-quality-system-considerations-and-content-of-premarket-submissions","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2025-06-27/pdf/2025-11669.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2025-11669.pdf?1750941908","publication_date":"2025-06-27","agencies":[{"raw_name":"DEPARTMENT OF HEALTH AND HUMAN SERVICES","name":"Health and Human Services Department","id":221,"url":"https://www.federalregister.gov/agencies/health-and-human-services-department","json_url":"https://www.federalregister.gov/api/v1/agencies/221","parent_id":null,"slug":"health-and-human-services-department"},{"raw_name":"Food and Drug Administration","name":"Food and Drug Administration","id":199,"url":"https://www.federalregister.gov/agencies/food-and-drug-administration","json_url":"https://www.federalregister.gov/api/v1/agencies/199","parent_id":221,"slug":"food-and-drug-administration"}],"excerpts":"announcing the availability of a final guidance entitled “<span class=\"match\">Cybersecurity</span> in Medical Devices: Quality System Considerations and Content of Premarket Submissions.” This guidance updates the previous version of the guidance, of the same title, issued on September 27, 2023, and finalizes the draft guidance entitled “Select Updates for the Premarket <span class=\"match\">Cybersecurity</span> Guidance: Section 524B of the FD&amp;C Act” issued on March 13, 2024. This guidance provides FDA's recommendations to industry regarding <span class=\"match\">cybersecurity</span> device design, labeling, and the documentation that"},{"title":"Federal Acquisition Regulation: Strengthening America's Cybersecurity Workforce","type":"Proposed Rule","abstract":"DoD, GSA, and NASA are proposing to amend the Federal Acquisition Regulation (FAR) to incorporate a framework for describing cybersecurity workforce knowledge and skill requirements used in contracts for information technology support services and cybersecurity support services in line with an Executive Order to enhance the cybersecurity workforce.","document_number":"2024-30504","html_url":"https://www.federalregister.gov/documents/2025/01/03/2024-30504/federal-acquisition-regulation-strengthening-americas-cybersecurity-workforce","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2025-01-03/pdf/2024-30504.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2024-30504.pdf?1735825509","publication_date":"2025-01-03","agencies":[{"raw_name":"DEPARTMENT OF DEFENSE","name":"Defense Department","id":103,"url":"https://www.federalregister.gov/agencies/defense-department","json_url":"https://www.federalregister.gov/api/v1/agencies/103","parent_id":null,"slug":"defense-department"},{"raw_name":"GENERAL SERVICES ADMINISTRATION","name":"General Services Administration","id":210,"url":"https://www.federalregister.gov/agencies/general-services-administration","json_url":"https://www.federalregister.gov/api/v1/agencies/210","parent_id":null,"slug":"general-services-administration"},{"raw_name":"NATIONAL AERONAUTICS AND SPACE ADMINISTRATION","name":"National Aeronautics and Space Administration","id":301,"url":"https://www.federalregister.gov/agencies/national-aeronautics-and-space-administration","json_url":"https://www.federalregister.gov/api/v1/agencies/301","parent_id":null,"slug":"national-aeronautics-and-space-administration"}],"excerpts":"information technology and <span class=\"match\">cybersecurity</span> services. DoD, GSA, and NASA are proposing to revise the FAR to ensure that when acquiring information technology support services or <span class=\"match\">cybersecurity</span> support services, agencies describe the <span class=\"match\">cybersecurity</span> workforce tasks, knowledge, skills, and work roles to align with the NICE Framework.\n \n \n The NICE Framework is a nationally focused resource that categorizes and describes <span class=\"match\">cybersecurity</span> work. The NICE Framework establishes a common language that defines and categorizes <span class=\"match\">cybersecurity</span> competency areas and work"},{"title":"Agency Information Collection Activities: Cybersecurity and Infrastructure Security Agency (CISA) Speaker Request Form","type":"Notice","abstract":"The External Affairs (EA) within Cybersecurity and Infrastructure Security Agency (CISA) submits the following information collection request (ICR) to the Office of Management and Budget (OMB) for review and clearance.","document_number":"2025-09688","html_url":"https://www.federalregister.gov/documents/2025/05/29/2025-09688/agency-information-collection-activities-cybersecurity-and-infrastructure-security-agency-cisa","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2025-05-29/pdf/2025-09688.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2025-09688.pdf?1748436324","publication_date":"2025-05-29","agencies":[{"raw_name":"DEPARTMENT OF HOMELAND SECURITY","name":"Homeland Security Department","id":227,"url":"https://www.federalregister.gov/agencies/homeland-security-department","json_url":"https://www.federalregister.gov/api/v1/agencies/227","parent_id":null,"slug":"homeland-security-department"}],"excerpts":"documents or comments received, go to \n http://www.regulations.gov \n .\n \n \n \n FOR FURTHER INFORMATION CONTACT: \n \n Bryana Thomas, 771-217-0728, \n bryana.thomas@mail.cisa.dhs.gov \n .\n \n \n \n \n SUPPLEMENTARY INFORMATION: \n The <span class=\"match\">Cybersecurity</span> and Infrastructure Security Agency Act of 2018 (Pub. L. 115-278) created the <span class=\"match\">Cybersecurity</span> and Infrastructure Security Agency (CISA). CISA is responsible for protecting the Nation's critical infrastructure from physical and cyber threats. This mission requires effective coordination and collaboration from government"},{"title":"Agency Information Collection Activities: Extension/Renewal of a Currently Approved Information Collection for Cybersecurity and Infrastructure Security Agency (CISA) Visitor Request Form","type":"Notice","abstract":"The Office of the Chief Security Officer (OCSO) within Cybersecurity and Infrastructure Security Agency (CISA) submits the following Information Collection Request (ICR) to the Office of Management and Budget (OMB) for review and clearance.","document_number":"2025-15860","html_url":"https://www.federalregister.gov/documents/2025/08/20/2025-15860/agency-information-collection-activities-extensionrenewal-of-a-currently-approved-information","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2025-08-20/pdf/2025-15860.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2025-15860.pdf?1755607558","publication_date":"2025-08-20","agencies":[{"raw_name":"DEPARTMENT OF HOMELAND SECURITY","name":"Homeland Security Department","id":227,"url":"https://www.federalregister.gov/agencies/homeland-security-department","json_url":"https://www.federalregister.gov/api/v1/agencies/227","parent_id":null,"slug":"homeland-security-department"}],"excerpts":"appropriate automated, electronic, mechanical, or other technological collection techniques or other forms of information technology, \n e.g., \n permitting electronic submissions of responses.\n \n Analysis \n \n Agency: \n <span class=\"match\">Cybersecurity</span> and Infrastructure Security Agency (CISA), Department of Homeland Security (DHS).\n \n \n Title: \n <span class=\"match\">Cybersecurity</span> and Infrastructure Security Agency (CISA) Visitor Request Form.\n \n \n OMB Number: \n 1670-0036.\n \n \n Frequency: \n Annually.\n \n \n Affected Public: \n Private and Public Sector.\n \n \n Number of Respondents: \n 20,000.\n \n"},{"title":"Schools and Libraries Cybersecurity Pilot Program","type":"Rule","abstract":"In this document, the Federal Communications Commission (Commission) announces that the Office of Management and Budget (OMB) has approved, for a period of three years, an information collection associated with the rules for the Schools and Libraries Cybersecurity Pilot Program contained in the Commission's Schools and Libraries Cybersecurity Pilot Program Report and Order, WC Docket No. 23-234; FCC 24-63. This document is consistent with the Schools and Libraries Cybersecurity Pilot Program Report and Order, which stated that the Commission would publish a document in the Federal Register announcing the effective date of the new information collection requirements.","document_number":"2024-21466","html_url":"https://www.federalregister.gov/documents/2024/09/20/2024-21466/schools-and-libraries-cybersecurity-pilot-program","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2024-09-20/pdf/2024-21466.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2024-21466.pdf?1726749929","publication_date":"2024-09-20","agencies":[{"raw_name":"FEDERAL COMMUNICATIONS COMMISSION","name":"Federal Communications Commission","id":161,"url":"https://www.federalregister.gov/agencies/federal-communications-commission","json_url":"https://www.federalregister.gov/api/v1/agencies/161","parent_id":null,"slug":"federal-communications-commission"}],"excerpts":"and Libraries <span class=\"match\">Cybersecurity</span> Pilot Program.\n \n \n Form Number: \n FCC Forms 470, 471, 472, 474—<span class=\"match\">Cybersecurity</span>, 484 and 488—<span class=\"match\">Cybersecurity</span>.\n \n \n Type of Review: \n New information collection.\n \n \n Respondents: \n State, local or tribal government institutions, and other not-for-profit institutions.\n \n \n Number of Respondents and Responses: \n 23,000 respondents; 201,100 responses.\n \n \n Estimated Time per Response: \n 4 hours for FCC Form 470—<span class=\"match\">Cybersecurity</span>, 5 hours for FCC Form 471—<span class=\"match\">Cybersecurity</span>, 1.75 hours for FCC Forms 472/474—<span class=\"match\">Cybersecurity</span>, 15 hours for"},{"title":"HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information","type":"Proposed Rule","abstract":"The Department of Health and Human Services (HHS or \"Department\") is issuing this notice of proposed rulemaking (NPRM) to solicit comment on its proposal to modify the Security Standards for the Protection of Electronic Protected Health Information (\"Security Rule\") under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH Act). The proposed modifications would revise existing standards to better protect the confidentiality, integrity, and availability of electronic protected health information (ePHI). The proposals in this NPRM would increase the cybersecurity for ePHI by revising the Security Rule to address: changes in the environment in which health care is provided; significant increases in breaches and cyberattacks; common deficiencies the Office for Civil Rights has observed in investigations into Security Rule compliance by covered entities and their business associates (collectively, \"regulated entities\"); other cybersecurity guidelines, best practices, methodologies, procedures, and processes; and court decisions that affect enforcement of the Security Rule.","document_number":"2024-30983","html_url":"https://www.federalregister.gov/documents/2025/01/06/2024-30983/hipaa-security-rule-to-strengthen-the-cybersecurity-of-electronic-protected-health-information","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2025-01-06/pdf/2024-30983.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2024-30983.pdf?1735334119","publication_date":"2025-01-06","agencies":[{"raw_name":"DEPARTMENT OF HEALTH AND HUMAN SERVICES","name":"Health and Human Services Department","id":221,"url":"https://www.federalregister.gov/agencies/health-and-human-services-department","json_url":"https://www.federalregister.gov/api/v1/agencies/221","parent_id":null,"slug":"health-and-human-services-department"},{"raw_name":"Office of the Secretary"}],"excerpts":"Through Strengthening <span class=\"match\">Cybersecurity</span>,” \n supra \n note 306.\n \n \n \n \n 313 \n  \n See, e.g., \n “Free <span class=\"match\">Cybersecurity</span> Services and Tools,” <span class=\"match\">Cybersecurity</span> &amp; Infrastructure Security Agency, U.S. Department of Homeland Security, \n https://www.cisa.gov/resources-tools/resources/free-<span class=\"match\">cybersecurity</span>-services-and-tools; \n “Cyber Hygiene Services,” <span class=\"match\">Cybersecurity</span> &amp; Infrastructure Security Agency, U.S. Department of Homeland Security, \n https://www.cisa.gov/cyber-hygiene-services; \n “<span class=\"match\">Cybersecurity</span> Resources for High-Risk Communities,” <span class=\"match\">Cybersecurity</span> &amp; Infrastructure"},{"title":"Cybersecurity Labeling for Internet of Things","type":"Rule","abstract":"In this document, the Federal Communications Commission (Commission or FCC) establishes a voluntary cybersecurity labeling program for wireless consumer Internet of Things, or IoT, products. The program will provide consumers with an easy-to-understand and quickly recognizable FCC IoT Label that includes the U.S. Cyber Trust Mark and a QR code linked to a dynamic, decentralized, publicly available registry of more detailed cybersecurity information. This program will help consumers make safer purchasing decisions, raise consumer confidence regarding the cybersecurity of the IoT products they buy, and encourage manufacturers to develop IoT products with security-by- design principles in mind.","document_number":"2024-14148","html_url":"https://www.federalregister.gov/documents/2024/07/30/2024-14148/cybersecurity-labeling-for-internet-of-things","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2024-07-30/pdf/2024-14148.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2024-14148.pdf?1722257113","publication_date":"2024-07-30","agencies":[{"raw_name":"FEDERAL COMMUNICATIONS COMMISSION","name":"Federal Communications Commission","id":161,"url":"https://www.federalregister.gov/agencies/federal-communications-commission","json_url":"https://www.federalregister.gov/api/v1/agencies/161","parent_id":null,"slug":"federal-communications-commission"}],"excerpts":"help inform the IoT product developer about the product's actual <span class=\"match\">cybersecurity</span> posture.\n \n \n (8) \n Information and Query Reception: \n The IoT product developer has the ability to receive information relevant to <span class=\"match\">cybersecurity</span> and respond to queries from the customer and others about information relevant to <span class=\"match\">cybersecurity</span>.\n \n \n i. \n <span class=\"match\">Cybersecurity</span> Utility: \n As IoT products are used by customers, those customers may have questions or reports of issues that can help improve the <span class=\"match\">cybersecurity</span> of the IoT product over time.\n \n \n (9)\n Information Dissemination:"},{"title":"Schools and Libraries Cybersecurity Pilot Program","type":"Rule","abstract":"In this document, the Federal Communications Commission (Commission or FCC) stablishes the Schools and Libraries Cybersecurity Pilot Program (Pilot or Pilot Program). The Pilot Program will enable the Commission to evaluate the impact that using Universal Service Fund (USF or Fund) support for eligible cybersecurity services and equipment will have on protecting school and library broadband networks and data. In so doing, the Commission seeks to address the apparent needs of schools and libraries for additional support for cybersecurity services and equipment, while evaluating the impact that providing that support would have on the USF.","document_number":"2024-15866","html_url":"https://www.federalregister.gov/documents/2024/07/30/2024-15866/schools-and-libraries-cybersecurity-pilot-program","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2024-07-30/pdf/2024-15866.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2024-15866.pdf?1722257112","publication_date":"2024-07-30","agencies":[{"raw_name":"FEDERAL COMMUNICATIONS COMMISSION","name":"Federal Communications Commission","id":161,"url":"https://www.federalregister.gov/agencies/federal-communications-commission","json_url":"https://www.federalregister.gov/api/v1/agencies/161","parent_id":null,"slug":"federal-communications-commission"}],"excerpts":"for the proposed project, and the <span class=\"match\">cybersecurity</span> risks the proposed Pilot project will prevent or address. \n • The <span class=\"match\">cybersecurity</span> equipment and services the applicant plans to request as part of its proposed project, the ability of the project to be self-sustaining once established, and whether the applicant has a <span class=\"match\">cybersecurity</span> officer or other senior-level staff member designated to be the <span class=\"match\">cybersecurity</span> officer for its Pilot project. \n \n • Whether the applicant has previous experience implementing <span class=\"match\">cybersecurity</span> protections or measures (answered on"},{"title":"National Cybersecurity Awareness Month, 2025","type":"Presidential Document","abstract":null,"document_number":"2025-19640","html_url":"https://www.federalregister.gov/documents/2025/10/22/2025-19640/national-cybersecurity-awareness-month-2025","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2025-10-22/pdf/2025-19640.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2025-19640.pdf?1761059705","publication_date":"2025-10-22","agencies":[{"raw_name":"EXECUTIVE OFFICE OF THE PRESIDENT","name":"Executive Office of the President","id":538,"url":"https://www.federalregister.gov/agencies/executive-office-of-the-president","json_url":"https://www.federalregister.gov/api/v1/agencies/538","parent_id":null,"slug":"executive-office-of-the-president"}],"excerpts":"Proclamation 10985 of October 17, 2025 \n National <span class=\"match\">Cybersecurity</span> Awareness Month, 2025 \n \n A Proclamation \n This National <span class=\"match\">Cybersecurity</span> Awareness Month, my Administration renews its commitment to strengthening our Nation's <span class=\"match\">cybersecurity</span> to improve American lives, defend American sovereignty, and uphold the rights of every American citizen. \n In recent years, advancements in <span class=\"match\">cybersecurity</span> have presented new threats to our national defense and personal privacy. Criminal organizations and our foes overseas have continued to wage cyber campaigns targeting"},{"title":"Cybersecurity Maturity Model Certification (CMMC) Program","type":"Rule","abstract":"With this final rule, DoD establishes the Cybersecurity Maturity Model Certification (CMMC) Program in order to verify contractors have implemented required security measures necessary to safeguard Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). The mechanisms discussed in this rule will allow the Department to confirm a defense contractor or subcontractor has implemented the security requirements for a specified CMMC level and is maintaining that status (meaning level and assessment type) across the contract period of performance. This rule will be updated as needed, using the appropriate rulemaking process, to address evolving cybersecurity standards, requirements, threats, and other relevant changes.","document_number":"2024-22905","html_url":"https://www.federalregister.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certification-cmmc-program","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2024-10-15/pdf/2024-22905.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2024-22905.pdf?1728650732","publication_date":"2024-10-15","agencies":[{"raw_name":"DEPARTMENT OF DEFENSE","name":"Defense Department","id":103,"url":"https://www.federalregister.gov/agencies/defense-department","json_url":"https://www.federalregister.gov/api/v1/agencies/103","parent_id":null,"slug":"defense-department"},{"raw_name":"Office of the Secretary"}],"excerpts":"protection of CUI. CMMI is focused on improving the software development process, while CMMC is focused on verifying the proper implementation of DIB <span class=\"match\">cybersecurity</span> requirements. Incorporating requirements into new or other existing standards would unacceptably delay action to improve DIB <span class=\"match\">cybersecurity</span>. The DoD must take action to improve DIB <span class=\"match\">cybersecurity</span>, regardless of the global state of <span class=\"match\">cybersecurity</span>. DoD's publication of this rule follows completion of OMB's formal rulemaking process, which includes both DoD internal coordination and Interagency"},{"title":"Notice of Solicitation of Proposals for the Department of Defense University Consortium for Cybersecurity Support Center","type":"Notice","abstract":"The Secretary of Defense has determined the need for a Support Center (Center) for the University Consortium for Cybersecurity (UC2). The Center will provide, during a two-year term, administrative support for the academic research and engagement activities of UC2. To be eligible, interested institutions must have been designated as National Centers of Academic Excellence (NCAE) in cybersecurity for at least 24 months from the date of the publication of this notice and, further, must demonstrate an understanding of cybersecurity research, be eligible for access to classified material, and demonstrate commitment to the UC2 mission of a closer collaboration between academia and the DoD.","document_number":"2024-20652","html_url":"https://www.federalregister.gov/documents/2024/09/12/2024-20652/notice-of-solicitation-of-proposals-for-the-department-of-defense-university-consortium-for","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2024-09-12/pdf/2024-20652.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2024-20652.pdf?1726058734","publication_date":"2024-09-12","agencies":[{"raw_name":"DEPARTMENT OF DEFENSE","name":"Defense Department","id":103,"url":"https://www.federalregister.gov/agencies/defense-department","json_url":"https://www.federalregister.gov/api/v1/agencies/103","parent_id":null,"slug":"defense-department"},{"raw_name":"Office of the Secretary"}],"excerpts":"designation was created to manage a collaborative <span class=\"match\">cybersecurity</span> educational program with community colleges, colleges, and universities that: (1) establishes standards for <span class=\"match\">cybersecurity</span> curriculum and academic excellence; (2) includes competency development among students and faculty; (3) values community outreach and leadership in professional development; (4) integrates <span class=\"match\">cybersecurity</span> practice within the institution across academic disciplines; and (5) actively engages in solutions to challenges facing <span class=\"match\">cybersecurity</span> education. \n There are three types of designations:"},{"title":"Agency Information Collection Activities: National Initiative for Cybersecurity Careers and Studies Cybersecurity Education and Training Catalog Collection","type":"Notice","abstract":"NICCS within CISA will submit the following Information Collection Request (ICR) to the Office of Management and Budget (OMB) for review and clearance in accordance with the Paperwork Reduction Act of 1995. CISA previously published this information collection request (ICR) in the Federal Register on June 20, 2024, for a 60-day public comment period. No comments were received by CISA. The purpose of this notice is to allow additional 30-days for public comments.","document_number":"2025-17049","html_url":"https://www.federalregister.gov/documents/2025/09/05/2025-17049/agency-information-collection-activities-national-initiative-for-cybersecurity-careers-and-studies","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2025-09-05/pdf/2025-17049.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2025-17049.pdf?1756989915","publication_date":"2025-09-05","agencies":[{"raw_name":"DEPARTMENT OF HOMELAND SECURITY","name":"Homeland Security Department","id":227,"url":"https://www.federalregister.gov/agencies/homeland-security-department","json_url":"https://www.federalregister.gov/api/v1/agencies/227","parent_id":null,"slug":"homeland-security-department"}],"excerpts":"website is a national online resource for <span class=\"match\">cybersecurity</span> awareness, education, talent management, and professional development and training. Its mission is to provide comprehensive <span class=\"match\">cybersecurity</span> resources to the public. To promote <span class=\"match\">cybersecurity</span> education, and to provide a comprehensive resource for the Nation, NICCS developed the <span class=\"match\">Cybersecurity</span> Training and Education Catalog. The NICCS Education and Training Catalog is a central location to help <span class=\"match\">cybersecurity</span> professionals of all skill levels find <span class=\"match\">cybersecurity</span>-related courses online and in person across"}]}