The U.S. Transportation Security Administration has sent the Office of Management and Budget a revised information collection request covering cybersecurity measures for surface transportation operators, with the proposal applying to certain freight rail, mass transit and passenger rail, and over-the-road bus operators. The revised collection includes requirements for designating cybersecurity coordinators, reporting cybersecurity incidents to the Cybersecurity and Infrastructure Security Agency within 72 hours, maintaining cybersecurity incident response plans, and completing cybersecurity assessments.
TSA estimates the collection will cover 67 respondents and impose 22,167 hours of annual burden, down from an earlier estimate of 846 respondents and 210,684 hours. Public comments are due Oct. 1. The notice covers owners and operators of freight rail, mass transit and passenger rail, and over-the-road bus operations.
In a Federal Register notice published Tuesday, Christina A. Walsh, Paperwork Reduction Act Officer for Information Technology at the TSA, detailed that the agency is soliciting comments to evaluate whether the proposed information requirement is necessary for the proper performance of the functions of the agency, including whether the information will have practical utility; evaluate the accuracy of the agency’s estimate of the burden; enhance the quality, utility and clarity of the information to be collected; and minimize the burden of the collection of information on those who are to respond, including using appropriate automated, electronic, mechanical or other technological collection techniques or other IT forms.
TSA has authority to impose transportation security measures without notice or comment. In December 2021, it issued mandatory security directives requiring higher-risk railroads and rail transit operators to implement cybersecurity measures to protect infrastructure. A complementary directive followed in October 2022 targeting freight and passenger railroads. TSA has also issued voluntary guidance recommending similar measures for operators not covered by the mandates, most recently in October 2025 recommending incident reporting to TSA.
“On January 15, 2026, TSA revised the SD 1580-21-01 series, SD 1582-21-01 series, to require that any non-U.S. citizen serving as a primary or alternate Cybersecurity Coordinator must be a current member of NEXUS, Global Entry, or another program determined by TSA to include a comparable security threat assessment,” Walsh wrote in the notice. “TSA is revising the collection to include this new requirement.”
The notice detailed that owners and operators must designate a primary and at least one alternate Cybersecurity Coordinator. Any non-U.S. citizen serving as a primary or alternate Cybersecurity Coordinator must be a current member of NEXUS, Global Entry or another program determined by TSA to include a comparable security threat assessment and must submit documentation of such membership to TSA. This requirement is a revision to the original collection, as discussed above, stemming from the revision of these SD series.
TSA expects that fewer than 10 owners and operators will respond to the information collection annually. However, this new requirement burden is covered under OMB control number 1651-0121, Trusted Traveler Programs and U.S. APEC Business Travel Card. Owners and operators must report cybersecurity incidents to the Cybersecurity and Infrastructure Security Agency no later than 72 hours after identifying a cybersecurity incident. Also, owners and operators must develop a Cybersecurity Incident Response Plan and submit it to TSA, and they must complete a cybersecurity vulnerability assessment using the TSA-issued form and submit the completed assessment to TSA.
Information collection is also being revised