World Watch/United States/Cybersecurity

Cybersecurity · United States

Cybersecurity - United States

Sectoral rulesSector-specific rules (SEC, FTC, HIPAA) plus CISA as lead civilian cyber agency; CIRCIA (2022) cross-sector incident-reporting rule pending final adoption

The United States does not have a single comprehensive federal cybersecurity law. Obligations are imposed through a patchwork of sector-specific regulations — covering public companies (SEC), non-bank financial institutions (FTC Safeguards Rule), healthcare (HIPAA Security Rule), and critical infrastructure — alongside voluntary NIST standards referenced in federal procurement. The Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA, 2022) will create the closest analog to a cross-sector mandatory reporting regime once CISA issues its final rule, now anticipated after May 2026 due to appropriations-related delays.

CIRCIA — Cross-Sector Incident Reporting

Signed into law March 2022, CIRCIA requires CISA to promulgate rules mandating covered critical-infrastructure entities to report cyber incidents within 72 hours and ransom payments within 24 hours. The NPRM was published April 4, 2024; the final rule was targeted for May 2026 but faces further delay due to DHS appropriations lapses.

SEC Cybersecurity Disclosure Rules (2023)

Adopted July 26, 2023 and effective December 2023, SEC rules require public companies to disclose material cybersecurity incidents on Form 8-K within four business days of a materiality determination, and to provide annual disclosures of cybersecurity risk-management processes and governance in Form 10-K.

FTC Safeguards Rule — Financial Sector Breach Notification

Non-banking financial institutions (mortgage lenders, payment processors, tax preparers, etc.) covered by the Gramm-Leach-Bliley Act must notify the FTC within 30 days of a security breach affecting 500 or more consumers. This breach-notification amendment took effect May 2024.

HIPAA Security Rule — Healthcare Cybersecurity NPRM

HHS published a Notice of Proposed Rulemaking on January 6, 2025 to strengthen HIPAA's Security Rule, proposing stricter technical safeguards for electronic protected health information (ePHI), mandatory encryption, and enhanced incident-response requirements for covered healthcare entities and their business associates.

NIST Cybersecurity Framework 2.0 & Executive Orders

NIST CSF 2.0 (published February 2024) added a 'Govern' function and supply-chain emphasis; though voluntary for the private sector, it is referenced in federal procurement requirements. Executive Order 14144 (January 2025) and EO 14306 (June 2025) extended federal agency requirements around secure software development (SSDF), post-quantum cryptography transition, and third-party software accountability.

Telecom Sector — FCC Cybersecurity Rule (2025)

A Federal Register rule published December 15, 2025 addresses cybersecurity threats to the nation's communications systems, extending sector-specific obligations to telecommunications providers under FCC authority.

Machine-assisted translation · verified 5/24/2026 · orientation, not legal advice. English version →