<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<REGINFO_RIN_DATA xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" RUN_DATE="2026-04-04-04:00" xsi:noNamespaceSchemaLocation="https://www.reginfo.gov/public/xml/REGINFO_XML_Ver10262011.xsd">
    <RIN_INFO>
        <RIN>3090-AJ85</RIN>
        <PUBLICATION>
            <PUBLICATION_ID>201804</PUBLICATION_ID>
            <PUBLICATION_TITLE>Unified Agenda of Federal Regulatory and Deregulatory Actions</PUBLICATION_TITLE>
        </PUBLICATION>
        <AGENCY>
            <CODE>3090</CODE>
            <NAME>General Services Administration</NAME>
            <ACRONYM>GSA</ACRONYM>
        </AGENCY>
        <RULE_TITLE>General Services Administration Acquisition Regulation (GSAR); GSAR Case 2016-G515, Cyber Incident Reporting</RULE_TITLE>
        <ABSTRACT><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>GSA is proposing to amend the General Services Administration Acquisition Regulation (GSAR) to provide requirements for GSA contractors to report cyber incidents that could potentially affect GSA or its customer agencies.&nbsp;The rule integrates the existing cyber incident reporting policy within GSA Order CIO 9297.2C, GSA Information Breach Notification Policy that did not previously go through the rulemaking process into the GSAR. By incorporating cyber incident reporting requirements into the GSAR, the GSAR will provide centralized guidance to ensure consistent application of cybersecurity principles across the organization. Integrating these requirements into the GSAR will also allow industry to provide public comments through the rulemaking process.</p>
<p>The rule outlines the roles and responsibilities of the GSA contracting officer, contractors, and agencies ordering off of GSA&rsquo;s contracts in the reporting of a cyber incident.</p>
<p>The rule establishes a contractor&rsquo;s responsibility to report any cyber incident where the confidentiality, integrity, or availability of GSA information or information systems are potentially compromised or where the confidentiality, integrity, or availability of information or information systems owned or managed by or on behalf of the U.S. Government is potentially compromised. It establishes an explicit timeframe for reporting cyber incidents, details the required elements of a cyber incident report, and provides the required Government's points of contact for submitting the cyber incident report.</p>
<p>The rule also outlines the additional contractor requirements that may apply for any cyber incidents involving personally identifiable information. In addition, the rule clarifies both GSA and ordering agencies&rsquo; authority to access contractor systems in the event of a cyber incident. It also establishes the role of GSA in the cyber incident reporting process and outlines how the primary response agency for a cyber incident is determined. In addition, it establishes the requirement for the contractor to preserve images of affected systems and ensure contractor employees receive appropriate training for reporting cyber incidents. The rule also outlines how contractor attributional/proprietary information provided as part of the cyber incident reporting process will be protected and used.</p>
</body>
</html>]]></ABSTRACT>
        <PRIORITY_CATEGORY>Other Significant</PRIORITY_CATEGORY>
        <RIN_STATUS>Previously Published in The Unified Agenda</RIN_STATUS>
        <RULE_STAGE>Proposed Rule Stage</RULE_STAGE>
        <MAJOR>No</MAJOR>
        <UNFUNDED_MANDATE_LIST>
            <UNFUNDED_MANDATE>No</UNFUNDED_MANDATE>
        </UNFUNDED_MANDATE_LIST>
        <EO_13771_DESIGNATION>Other</EO_13771_DESIGNATION>
        <CFR_LIST>
            <CFR>48 CFR 501</CFR>
            <CFR>48 CFR 502</CFR>
            <CFR>48 CFR 504</CFR>
            <CFR>48 CFR 539</CFR>
            <CFR>48 CFR 552</CFR>
        </CFR_LIST>
        <LEGAL_AUTHORITY_LIST>
            <LEGAL_AUTHORITY>40 U.S.C. 121(c)</LEGAL_AUTHORITY>
        </LEGAL_AUTHORITY_LIST>
        <LEGAL_DLINE_LIST/>
        <RPLAN_ENTRY>No</RPLAN_ENTRY>
        <TIMETABLE_LIST>
            <TIMETABLE>
                <TTBL_ACTION>NPRM</TTBL_ACTION>
                <TTBL_DATE>10/00/2018</TTBL_DATE>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>NPRM Comment Period End</TTBL_ACTION>
                <TTBL_DATE>12/00/2018</TTBL_DATE>
            </TIMETABLE>
        </TIMETABLE_LIST>
        <RFA_REQUIRED>Yes</RFA_REQUIRED>
        <SMALL_ENTITY_LIST>
            <SMALL_ENTITY>Businesses</SMALL_ENTITY>
        </SMALL_ENTITY_LIST>
        <GOVT_LEVEL_LIST>
            <GOVT_LEVEL>Federal</GOVT_LEVEL>
        </GOVT_LEVEL_LIST>
        <FEDERALISM>No</FEDERALISM>
        <FURTHER_INFO_URL>www.regulations.gov</FURTHER_INFO_URL>
        <PUBLIC_COMMENT_URL>www.regulations.gov</PUBLIC_COMMENT_URL>
        <PRINT_PAPER>Yes</PRINT_PAPER>
        <INTERNATIONAL_INTEREST>No</INTERNATIONAL_INTEREST>
        <AGENCY_CONTACT_LIST>
            <CONTACT>
                <FIRST_NAME>Kevin</FIRST_NAME>
                <LAST_NAME>Funk</LAST_NAME>
                <TITLE>Program Analyst</TITLE>
                <AGENCY>
                    <CODE>3090</CODE>
                    <NAME>General Services Administration</NAME>
                    <ACRONYM>GSA</ACRONYM>
                </AGENCY>
                <PHONE>202 357-5805</PHONE>
                <EMAIL>kevin.funk@gsa.gov</EMAIL>
                <MAILING_ADDRESS>
                    <STREET_ADDRESS>1800 F Street, NW,</STREET_ADDRESS>
                    <CITY>Washington</CITY>
                    <STATE>DC</STATE>
                    <ZIP>20405</ZIP>
                </MAILING_ADDRESS>
            </CONTACT>
        </AGENCY_CONTACT_LIST>
    </RIN_INFO>
</REGINFO_RIN_DATA>
