At the federal layer the United States has no single cross-sector product-security or cyber-resilience statute comparable to the Cyber Resilience Act or the United Kingdom's Product Security and Telecommunications Infrastructure Act.
What exists instead is a set of regimes that each bind a specifically defined class of regulated entity, a financial institution, an Securities and Exchange Commission (SEC) reporting company, a critical-infrastructure operator, or a medical-device sponsor, rather than any developer who simply ships or distributes software.
The Federal Trade Commission's Safeguards Rule under the Gramm-Leach-Bliley Act, 16 CFR 314.3 and 314.4(a) through (i), requires a financial institution over which the FTC has jurisdiction under Gramm-Leach-Bliley Act section 505(a)(7) to develop, implement, and maintain a written information security program: a designated Qualified Individual, a periodic risk assessment, access controls, encryption of customer information, multi-factor authentication, oversight of service providers, a written incident response plan, and at least annual reporting to the board of directors.
The Rule's separate breach-notification duty, 16 CFR 314.4(j), effective May 13, 2024, is already this jurisdiction's privacy row and is not repeated here.
The Securities and Exchange Commission requires an SEC reporting company to describe its cybersecurity risk management processes and its board's and management's oversight of cybersecurity risk in its annual report under Item 106 of Regulation S-K, and to report, within four business days of determining that a cybersecurity incident is material, that incident under Item 1.05 of Form 8-K. The Cyber Incident Reporting for Critical Infrastructure Act of 2022, 6 U.S.C. 681b, enacted in March 2022, directs the Cybersecurity and Infrastructure Security Agency to issue regulations requiring a covered entity across sixteen critical-infrastructure sectors to report a covered cyber incident within 72 hours and a ransom payment within 24 hours, but the Agency has not yet published the final rule implementing that duty.
Nobody is bound to report under it until the rule takes effect, and the statute is recorded below at the stage it has actually reached rather than the one it will reach: the proposed rule is docket CISA-2022-0010, published 4 April 2024, the statutory deadline for a final rule passed on 4 October 2025, and the Agency held further town halls in June 2026 before finalising.
Section 524B of the Federal Food, Drug, and Cosmetic Act, 21 U.S.C. 360n-2, in effect since March 29, 2023, requires the sponsor of a premarket submission for a cyber device (a device with sponsor-installed software, internet connectivity, and a technological characteristic that could be vulnerable to a cybersecurity threat) to submit a plan for monitoring and coordinated disclosure of postmarket vulnerabilities, maintain secure design and patching processes, and provide a software bill of materials; the Food and Drug Administration administers this as a premarket-submission completeness requirement rather than through a separate penalty schedule.
There is no general federal statute imposing a reasonable-security duty on a business simply because it holds personal data; the closest analogue is the Federal Trade Commission's own Section 5 unfairness authority applied to data-security failures, already this jurisdiction's privacy row rather than a second row here, since that row already carries the general federal privacy and data-security enforcement vehicle rather than being split the way a state safeguards statute is split between the two topics.
The Internet of Things Cybersecurity Improvement Act of 2020, Public Law 116-207, is a federal-procurement standard rather than a market-wide manufacturer duty: since December 5, 2022 it bars a federal agency, not a manufacturer, from procuring or renewing a contract for an Internet of Things device that does not meet standards the National Institute of Standards and Technology developed under the Act, so it does not reach a vendor who sells only outside the federal government.
None of the regimes above creates a private right of action. The National Institute of Standards and Technology's Cybersecurity Framework and the Federal Communications Commission's Cyber Trust Mark labeling program are voluntary and are not law. Two further federal incident regimes are recorded below.
The banking agencies' joint computer-security incident notification rule, adopted by the Office of the Comptroller of the Currency, the Federal Reserve Board and the Federal Deposit Insurance Corporation in identical terms and in force since 1 May 2022, requires a banking organization to notify its primary federal regulator within 36 hours of determining that a notification incident has occurred, and requires a bank service provider, which is where a cloud or AI vendor serving a bank is reached, to notify each affected bank customer as soon as possible once a disruption lasting four hours or more is determined or likely.
DFARS 252.204-7012, the clause 48 CFR 204.7304 requires in every Department of Defense contract in its scope, requires a contractor to report a cyber incident within 72 hours of discovering it and to preserve forensic images for at least 90 days from submitting that report. The lint does not reach that clause: its bound party is a defense contractor, a class no role in the activity vocabulary names, and it is recorded here with no activity flagged rather than flagged on a guess.