TSA Decides It Is 67 Operators, Not 846
A revised information collection cuts the estimated respondent count by 92% and the annual burden from 210,684 hours to 22,167 — a large change in who actually carries surface transport cyber obligations.

The Transportation Security Administration published a 30-day notice on 1 September forwarding a revised information collection request to the Office of Management and Budget, covering cybersecurity measures for surface transport modes. Buried in the arithmetic is a substantial change: after comments on the April 60-day notice, TSA revised the estimated number of respondents from 846 down to 67, and the estimated annual time burden from 210,684 hours down to 22,167.
That is a 92 per cent cut in the population and an 89 per cent cut in the hours. Burden estimates in these notices are often treated as bureaucratic furniture, but they are the agency's own statement of how many organisations it believes are actually covered, and a revision of that size means the earlier figure was counting operators the directives do not reach. For anyone in freight rail, passenger rail, mass transit or over-the-road bus who has been uncertain whether the requirements apply to them, the revised estimate is a useful signal — though it settles nothing legally, since the directives define applicability, not the burden table.
The obligations themselves are unchanged and remain substantial for those covered. Cybersecurity incidents must be reported to CISA no later than 72 hours after identification. Since October 2023, covered operators must maintain a Cybersecurity Implementation Plan submitted for TSA approval, a Cybersecurity Assessment Plan, and an annual assessment report; TSA estimates about half of covered operators submit plan updates each year. A separate information circular from October 2025 recommends voluntary notification of TSA's Transportation Security Operations Center within 12 hours of discovering a significant incident — recommended, not required, and a much tighter clock than the mandatory 72 hours.
One requirement worth flagging for international operators: since January 2026, any non-US citizen serving as primary or alternate Cybersecurity Coordinator must be a current member of NEXUS, Global Entry or a comparable TSA-approved programme. That is a personnel constraint rather than a technical one, and it has caught organisations that assigned the role on competence alone.
Comments on the revised collection are due by 1 October 2026. The collection covers owner-operators under 49 CFR parts 1580, 1582 and 1584, under the security directive series first issued in December 2021 and expanded in October 2022.
Source: Federal Register