 Establishing and Using Cyber Requirements to Protect Critical Infrastructure The NCS calls for the use of incentives and requirements to align the interests of individuals and organizations with our collective goals of national security, public safety, and economic prosperity. The Federal Government’s proactive approach to cybersecurity requirements recognizes that every sector must be accounted for. Where cybersecurity requirements do not exist or are poorly defined, we are pursuing new requirements that are agile enough to adapt as adversaries increase their capabilities and change tactics. Where the regulatory landscape is already mature, we are working to harmonize and align new and existing regulatory requirements. We are also paying close attention to regulatory action in other countries where such efforts can serve as a model, or where these actions may impact U.S. critical infrastructure owners, operators, or third-party service providers. In the past year, new or updated cybersecurity rules went into effect across several critical infrastructure sectors. The Transportation Security Administration (TSA) issued updated requirements for oil and natural gas pipelines, airport and aircraft operators, and rail carriers. The Securities and Exchange Commission (SEC) adopted new rules requiring public companies to disclose information related to material cybersecurity incidents and risk management practices. In the healthcare and public health (HPH) sector, an amendment to the Federal Food, Drug, and Cosmetic Act, one of the Food and Drug Administration’s (FDA) authorizing statutes, now requires manufacturers of certain types of medical devices to design, develop, and maintain cybersecure medical devices, including through the creation of comprehensive lists of software components. FDA also finalized updated recommendations for medical device manufacturers to comply with FDA rules related to medical device cybersecurity. For the Defense Industrial Base (DIB), the Department of Defense (DoD) released revisions to its Cybersecurity Maturity Model Certification program to establish new requirements for DIB contractors and subcontractors and expanded access to the voluntary DIB Cybersecurity (CS) Program. And, in the maritime sector, the President signed EO 14116 on Amending Regulations Relating to the Safeguarding of Vessels, Harbors, Ports, and Waterfront Facilities of the United States alongside the U.S. Coast Guard issuing a Maritime Security Directive and Notice of Proposed Rulemaking (NPRM) to bolster port and maritime cybersecurity. Across all critical infrastructure sectors, implementation of CIRCIA will establish new requirements for covered entities to report certain cybersecurity incidents to the Federal Government. In March 2024, CISA published an NPRM setting out proposed regulations for cyber incident and ransom payment reporting, as well as other aspects of the CIRCIA regulatory program. The information contained in these reports will provide increased visibility into malicious cyber activity, improve our understanding of cross-sector risks, and strengthen our collective defense. The Federal Government is prioritizing measures to harmonize baseline regulatory requirements across sectors. Chaired by the Federal Communications Commission (FCC), the Cybersecurity Forum for Independent and Executive Branch Regulators enables Federal agencies to coordinate efforts to improve the effectiveness and consistency of regulatory activity. In September 2023, the Cyber Incident Reporting Council delivered a report to Congress on streamlining and harmonizing Federal cyber incident reporting requirements. 2024 REPORT 10 ON THE CYBERSECURITY OF THE UNITED STATES POSTURE

Select target paragraph3