Showing posts with label OIRA. Show all posts
Showing posts with label OIRA. Show all posts

Thursday, September 4, 2025

RegInfo Down Again

Sometime yesterday the OMB’s RegInfo.gov web site started having problems similar to the one I reported on August 19th and then reported as corrected on Tuesday. Once again, the site’s search function is not reporting rulemaking or information collection requests submitted to OMBs Office of Information and Regulatory Affairs (OIRA), or OIRA final action on such submissions, after August 1st, 2025; older data appears to be fine. Other functions of the site appear to be functioning normally. There is currently no indication on the site that OIRA is aware of, or is taking action to fix, the problem.

I use this site almost daily to report on the behind-the-scenes processing of rulemakings, and to help identify problematic ICRs that may be covered in this blog.

I am beginning to wonder if there are OMB IT staffing issues (or other DOGE related issues) at play here. Beyond the periodic shutdowns of the site (typically on weekends) for routine maintenance, I do not recall this type of problem occurring in the years that I have been following the site.


UPDATE 22:00 EDT 9-4-25

RegInfo.com is once again working as advertised. Ten new rulemakings were submitted, 2 rulemakings were approved, and 26 ICRs were approved since last Friday. None of these were of specific interest here.


Tuesday, September 2, 2025

RegInfo.gov Is Now Working

On August 19th, 2025 I reported problems with the RegInfo.gov website, with search data not available on their Regulatory Review tab and their Information Collection Review tab. Today the search function on both tabs are now active.

The OMB’s Office of Information and Regulatory Affairs (OIRA) has not been out of business while these search functions have not been working. They have still been accepting rulemakings from federal agencies for review and approving rulemakings. They have also been approving new and revised information collection requests. All of these actions have been fodder for blog posts here.

Since August 18th OIRA has accepted 24 rulemakings for review. The table below shows the ten rulemakings in that period that would probably been covered in this blog:


During the same period OIRA approved nine rulemakings. Three of those rulemakings probably would have been covered in this blog:


Just a quick reminder, my blog posts about such OIRA actions does not necessarily mean that I will cover the rulemakings in any depth when they are published in the Federal Register. In most cases the only mention of that publication will be found in my ‘Short Takes’ blog post on the day of publication.

OIRA also approved 124 ICR submissions/renewals during the period of the outage. None of those approvals would have been covered in this blog.

Friday, January 24, 2025

Review – OIRA and the Regulatory Freeze

Since Trump’s regulatory freeze took effect on January 20th, the OMB’s Office of Information and regulatory affairs (OIRA) has not done much work on its normal job of processing rulemakings and information collection requests. They have almost certainly stayed busy, working with agencies in assessing their actions under that freeze, but their normal business has dropped off considerably.

The table below shows those normal actions that have been processed since January 20th:


OIRA Actions

We can see from that table that the only thing that has been proceeding with any normality is the receiving of information collection request (ICR) submissions from federal agencies. This is one area that was not addressed in Trump’s regulatory freeze order. Technically, these ICR’s are not supposed to be initiating new policy, but new ICRs and revisions certainly reflect recent changes in the operation of those programs.

 

For more information on the DHS ICR’s currently being reviewed by OIRA, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/oira-and-the-regulatory-freeze - subscription required.

Tuesday, January 14, 2025

OIRA Continues Announcing Rulemaking Withdrawals

The OMB’s Office of Information and Regulatory Affairs announced that yesterday it had ‘approved’ ten rulemaking actions. Seven of those actions were ‘Withdrawal’ approvals (none of specific interest here). This is one of those little noticed activities during transitions between administrations with significantly different regulatory outlooks. It is a recognition that the incoming Trump Administration is unlikely (at best) to continue working on these efforts. It helps to clear the decks for the incoming political appointees.

The agencies involved in yesterday’s announced actions were:

• FDA (5) – guidance documents,

• USCIS – refugee issues, and

• FAR – climate change requirements.

 

Thursday, March 23, 2023

FDA Sends Medical Device Cybersecurity Notice to OMB

Yesterday, the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had receive a notice from the Federal Drug Administration (FDA) on “Cybersecurity in Medical Devices: Refuse to Accept Policy for Cyber Devices and Related Systems Under Section 524B of the FD&C Act”. There is no listing for this action in the Fall 2022 Unified Agenda.

The new §524B was added to the Food, Drug, and Cosmetic Act by §3305 (pg 1374), Ensuring Cybersecurity of Medical Devices, of the Consolidated Appropriations Act, 2023 (PL 117-328, HR 2617). Subsection 3305(b) amended 21 USC 331(q) making it unlawful for medical device manufacturers to fail  to comply with any requirement under §524B(b)(2). That paragraph reads:

‘‘(2) design, develop, and maintain processes and procedures to provide a reasonable assurance that the device and related systems are cybersecure, and make available postmarket updates and patches to the device and related systems to address—

‘‘(A) on a reasonably justified regular cycle, known unacceptable vulnerabilities; and

‘‘(B) as soon as possible out of cycle, critical vulnerabilities that could cause uncontrolled risks;”

It looks like this notice may be related to that section in relation to ‘§524B’.

Thursday, March 16, 2023

OMB Reports Two FAR Cybersecurity NPRMS Were Withdrawn

The OMB’s Office of Information and Regulatory Affairs (OIRA) announced yesterday that the Federal Acquisition Regulation (FAR) notice of proposed rulemaking for “FAR Case 2021-017, Cyber Threat and Incident Reporting and Information Sharing” had been withdrawn from consideration. The NPRM was submitted to OIRA back in December. There is no discussion as to why it was withdrawn.

Similarly, ORIA announced that the FAR NPRM for “FAR Case 2021-019, Standardizing Cybersecurity Requirements for Unclassified Information Systems” was withdrawn. That NPRM was submitted to OIRA at the same time.

It is possible that this is related to the recent publication of the updated cybersecurity strategy and that substantial changes are being made to the requirements of the two rules. Making changes before the NPRMs were published would effectively shorten the rulemaking process from what would have been required if the government wanted to make changes subsequent to publication.

Friday, April 1, 2022

OMB Approves TRIA ICR Revision Adding Cyber Carrier Information

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved an information collection request (ICR) revision by the Treasury Department for their ICR on “Collection of Data from Property and Casualty Insurers for Reports Concerning the Terrorism Risk Insurance Program” (1505-0257). The revision was required because of a need for more information on captive insurers and cyber insurance required by TRIA changes mandated in the latest reauthorization of the program in Title V, Division I of PL 116-94.

According to the supporting document (NOTE: this is a DOCX download link) provided to OIRA:

“The proposed changes regarding cyber insurance seek more detailed information concerning cyber insurance written by insurers subject to the Program, in lines of insurance both covered and not covered by the Program, so that Treasury may better evaluate the Program’s response to cyber-related incidents that could have implications for the Program and its effectiveness, and Treasury’s administration of it.  In addition, the proposed changes seek information on the type of policyholders, by size, obtaining cyber insurance, and also request detailed information on coverage for ransomware-related losses, including existing claims information.”

The data collection form (2022 Data Call Non-Small Insurers (Proposed Revisions).xlsx NOTE: this is an XLSX download link) now includes a page {Cyber (US)} that includes 29 lines for the collection of data about cyber insurance policies (including ransomware losses).

Thursday, February 24, 2022

PHMSA Sends Gas Pipeline Safety Final Rule to OMB

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a final rule from the DOT’s Pipeline and Hazardous Materials Safety Administration (PHMSA) for “Pipeline Safety: Safety of Gas Transmission Pipelines, Repair Criteria, Integrity Management Improvements, Cathodic Protection, Management of Change, and Other Related Amendments.”

According to the entry in the Fall 2021 Unified Agenda for this rulemaking:

“This rulemaking would amend the pipeline safety regulations relevant to gas transmission pipelines by adjusting the repair criteria in high consequence areas and creating new criteria for non-high consequence areas, requiring the inspection of pipelines following extreme events, requiring safety features on in-line inspection tool launchers and receivers, updating and bolstering pipeline corrosion control, codifying a management of change process, clarifying certain integrity management provisions, and strengthening integrity management assessment requirements.”

There was no notice of proposed rulemaking issued for this action. It first appeared in the Spring 2018 Long-Term Actions portion of the Agenda listed as a final rule. It was split off from the 2137-AE72 rulemaking that had its NPRM published on March 8th, 2016.

Friday, December 17, 2021

PHMSA Sends Valve Installation and Rupture Detection Rule to OMB

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a final rule from DOT’s Pipeline and Hazardous Material Safety Administration (PHMSA) for “Pipeline Safety: Amendments to Parts 192 and 195 to require Valve installation and Minimum Rupture Detection Standards”.  The notice of proposed rulemaking (NPRM) for this rule was published on February 6th, 2020.

According to the abstract for this rulemaking in the Fall 2021 Unified Agenda:

“This rulemaking action would revise the Pipeline Safety Regulations applicable to most newly constructed and entirely replaced onshore natural gas transmission and hazardous liquid pipelines to improve rupture mitigation and shorten pipeline segment isolation times. The rulemaking action would define "notification of potential rupture" and outline certain performance standards related to rupture identification and pipeline segment isolation. This rulemaking action also would require specific valve maintenance and inspection requirements, and 9-1-1 notification requirements to help operators achieve better rupture response and mitigation.”

Friday, October 15, 2021

OMB Approves BIS Information Security Controls Interim Final Rule

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved the interim final rule submitted by the DOC’s Bureau of Industry and Security (BIS) on “Information Security Controls: Cybersecurity Items”. This action is a continuation of the BIS attempt in 2015 to publish Export Administration Regulations (EAR) implementing export security controls on selected cybersecurity products. This rulemaking was submitted to OIRA on September 17th, 2021.

Interestingly, the OIRA announcement list this as an ‘interim final rule’ while the Spring 2021 Unified Agenda listing shows that it should be a ‘notice of proposed rulemaking’. We will have to wait for BIS to publish the rule in the Federal Register in the coming week or two.

Friday, August 13, 2021

OMB Approves DHS Cybersecurity Talent Management System Final Rule

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a final rule for the DHS Cybersecurity Talent Management System. That final rule had been submitted to OIRA in June 2021. This is a direct final rule with no previous ‘publish and comment’ actions being taken by DHS.

According to the abstract published in the Spring 2021 Unified Agenda for this rulemaking:

“Under 6 U.S.C. 658, the Department of Homeland Security "shall prescribe regulations” to implement Department-specific hiring and compensation flexibilities granted in section 658 to recruit and retain persons with the necessary skills to fulfill the Department’s cybersecurity responsibilities. Under this authority, the Department is establishing a new personnel system for cybersecurity personnel, the Department of Homeland Security Cybersecurity Talent Management System (CTMS).”

There are a number of specific congressional mandates in 6 USC 658 that are clear enough to justify the use of a direct final rule, including specific authority to ‘prescribe regulations’ without any reference to the publish and comment process in §658(b)(6). There are, however, a number of provisions in that section that are permissive in nature, so it will be interesting to see which (if any) of those are included in this new regulation. I suspect that we will see publication of the final rule more quickly than we saw similar rulemaking proceed to publication under the Trump Administration. I would not be surprised to see it published in the Federal Register next week.

Friday, August 6, 2021

DOC Sends Cybersecurity ANPRM to OMB – 8-6-21

Yesterday, OMB’s Office of Information and Regulatory Affairs announced that it had received an advanced notice of proposed rulemaking (ANPRM) from the Department of Commerce on “Taking Additional Steps to Address the National Emergency with Respect to Significant Malicious Cyber-Enabled Activities”.

This rulemaking was not listed in the Spring 2021 Unified Agenda, which makes it difficult to tell for sure what the ANPRM may cover. There are, however, two regulation making requirements in EO 13984, Taking Additional Steps To Address the National Emergency With Respect to Significant Malicious Cyber-Enabled Activities, for DOC.

NOTE: EO 13984 was not one of the Trump executive orders repudiated by the incoming Biden Administration in EO 13992.

The first is for DOC to “propose for notice and comment regulations that require United States IaaS [Infrastructure as a Service] providers to verify the identity of a foreign person that obtains an Account”. This requirement called for DOC to propose those regulations within 180 days of January 19th 2021, or July 18th.

The same deadline was set for the second regulation proposing requirement for “Special Measures for Certain Foreign Jurisdictions or Foreign Persons.”

In any case, without the listing in the Unified Agenda, it is not possible to say for sure if the rulemaking sent to OIRA yesterday was either, both, or something completely different.


Friday, July 30, 2021

Review Filing Comments on 30-day ICR Notices

Yesterday I published a short notice about the 2nd revision to an information collection notice (ICR) for the Chemical Facility Anti-Terrorism Standards (CFATS) program. In addition to the change in the end of comment date that was presumably the reason for the 2nd revision, there was also a change in the language describing how to submit comments on the ICR. This online submission of comments on the 30-day ICR notices is a change from the old method of emailing the comments to the action officer at OMB’s Office of Information and Regulatory Affairs. Comments for 60-day ICRs are still posted (except for TSA) to www.Regulations.gov.

Of course, it was easier still when you just had to email the comments to the OIRA action officer for the ICR. I suspect, however, that this on-line process was initiated to weed out ‘letter writing’ campaigns that many activist organizations use to ‘influence’ the OIRA approval process. Those quotes are because those organizations know that OIRA (nor any other federal agency) is actually influenced by being inundated with multiple duplicate comments. No the organizations are usually using those campaigns for fund raising efforts.

For a detailed description on how to actually follow those instructions, or an easier way that I found, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/filing-comments-on-30-day-icr-notices - subscription required.

Tuesday, March 16, 2021

DOC Supply Chain Regulations to OMB

Yesterday the OMB’s Office of Information and Regulatory Affairs announced that it had received an advanced notice of proposed rulemaking (ANPRM) from the Department of Commerce on “Securing the Information and Communications Technology and Services Supply Chain: Licensing Procedures”. This rulemaking was not listed in the Fall 2020 Unified Agenda.

It is not unusual for rulemakings to appear without being mentioned in the most recent Unified Agenda, but at the start of a new administration it typically means (especially when it is an ANPRM) that this is a new initiative of the new administration. An ANPRM is an indication of early interest in establishing a regulatory framework of some sort, but the agency is looking to industry and the public for guidance in how it could go about it.

Monday, February 1, 2021

Biden Administration Review of Trump Pending Rules

We are now 11 days into the Biden Administration, and it appears that their review of rules pending review by OMB’s Office of Information and Regulatory Affairs (OIRA) is complete. Agencies have withdrawn 60 pending rulemakings, leaving 10 under consideration by OIRA; see the table below for the list of remaining rulemakings.

2502-ZA37

HUD/OH

Amendments to HUD's Non-Borrowing Spouse Policy for all Home Equity Conversion Mortgage (HECM) Loans

2502-ZA36

HUD/OH

Home Equity Conversion Mortgage (HECM) Program – Changes to Interest Rate Requirements Including Removal of the London Interbank Offered Rate (LIBOR) Index

1018-BE29

DOI/FWS

Endangered and Threatened Wildlife and Plants; Critical Habitat Designation for the Western Distinct Population Segment of the Yellow-Billed Cuckoo

2120-AK31

DOT/FAA

Pilot Records Database (HR 5900)

2120-ZA26

DOT/FAA

Exception for Limited Recreational Operations of Unmanned Aircraft

1010-AE07

DOI/BOEM

Rescission of Certain Unsolicited Lease Requests and Multiple-Factor Bidding From Renewable Energy Regulations

1006-ZA02

DOI/RB

Business Practice Guidelines for Central Valley Project Improvement Act Receipts, Program Accounting, Cost Allocation and Cost Recovery

1651-AB33

DHS/USCBP

Mandatory Advance Electronic Information for International Mail Shipments

1625-AC48

DHS/USCG

Clarification of Certain Mariner Training Requirements

3209-AA50

OGE

Legal Expense Fund Regulation

None of the rulemakings that were withdrawn have been covered in this blog.

At this point in the Trump Administration 24 rulemakings had been withdrawn, leaving only one to go to completion. The differences in the numbers of withdrawn rulemakings is more a measure of the efficacy of the Obama and Trump administrations in getting rulemakings completed during their tenure than in the intensity of the Trump and Biden administrations in clearing rulemakings from the previous administration.

NOTE: All of the data for this post was derived from search tools on the Reginfo.gov website.

Thursday, January 7, 2021

OMB Approves NHTSA Cybersecurity Request for Comments

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a notice from the DOT’s National Highway Transportation Safety Administration (NHTSA) for “Request for Comments on Cybersecurity Best Practices for the Safety of Modern Vehicles”. Documents such as this are not listed in the Unified Agenda, so there is no public information about what may be included. This type of document is typically a prequel [sorry that should have been 'prelude'] to the initiation of rulemaking.

I would expect this to be published in the Federal Register in the next week or two.

Wednesday, December 9, 2020

OMB Approves NISPOM Interim Final Rule

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved the DOD’s National Industrial Security Program Operating Manual (NISPOM) interim final rule. This rulemaking was submitted to ORIA back in August.

According to the Spring 2020 Unified Agenda entry for this rulemaking:

“This rule will codify the National Industrial Security Program Operating Manual (NISPOM) which prescribes specific requirements, restrictions, and other safeguards that are necessary to preclude unauthorized disclosure and control authorized disclosure of Federal Government classified information to contractors, licensees, or grantees. The NISPOM applies to the release of classified information during all phases of the contracting process, including bidding, negotiation, award, performance, and termination of contractors, the licensing process or the grant process, with or under the control of departments or agencies.”

Again, I am not intending to delve deeply into the DOD’s Industrial Security Program. I am highlighting this rulemaking because this manual is going to be a good guide to information security requirements for anyone that wants to gain routine access to classified information, for example government cyber-threat intel.

Thursday, July 9, 2020

OMB Receives PHMSA Pipeline Location NPRM for Review


On Tuesday the OMB’s Office of Information and Regulatory Affairs announced that it had received a notice of proposed rulemaking for review from DOT’s Pipeline and Hazardous Material Safety Administration (PHMSA) concerning “Pipeline Safety: Class Location Requirements “. The advanced notice of proposed rulemaking for this action was published in July 2018.

According to the 2019 Spring Unified Agenda entry for this rulemaking:

“This rulemaking regards existing class location requirements for natural gas transmission lines, specifically as they pertain to actions operators are required to take following class location changes due to population growth near the pipeline. Operators have suggested that performing integrity management measures on pipelines where class locations have changed due to population increases would be an equally safe but less costly alternative to the current requirements of either reducing pressure, pressure testing, or replacing pipe. The ANPRM requested public comment to inform future regulatory or deregulatory efforts related to this topic.”

Saturday, June 20, 2020

OMB Approves LNG by Rail Final Rule


Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved a final rule from the DOT’s Pipeline and Hazardous Material Safety Administration (PHMSA) on “Hazardous Materials: Liquefied Natural Gas by Rail”. The rule was sent to OIRA for approval on May 1st. The notice of proposed rulemaking (NPRM) for this action was published in October 2019.

With the possibility becoming more pronounced that Trump may be a single-term President, we are starting to approach the time when an outgoing administration begins to worry about its legacy. Trump came into office as an anti-regulatory campaigner. While that has not generally changed, the Administration is becoming more prolific in writing permissive regulations that allow industry to take actions that were not previously allowed.

This rulemaking certainly fits that description and that is almost certainly the reason that we have seen such a quick turnaround of the final bill (less than six months since the end of the comment period) even with the large number of comments that were submitted in opposition to the proposed rule. The downside of this is that if Trump is not re-elected and the Republicans to not retain control of the Senate, this rulemaking would be a prime target for reversal under the Congressional Review Act of 1996.

Friday, May 29, 2020

DOD Cybersecurity Certification NPRM to OMB


Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a notice of proposed rulemaking from the Department of Defense on “Strategic Assessment and Cybersecurity Certification Requirements”. This rulemaking was not listed in the Fall 2019 Unified Agenda.

According to a recent DOD document this rulemaking:

“Implements a standard DoD-wide methodology for assessing DoD contractor compliance with all security requirements in the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations and a DoD certification process, known as the Cybersecurity Maturity Model Certification (CMMC), that measures a company’s maturity and institutionalization of cybersecurity practices and processes. Partially implements section 1648 of the FY20 NDAA.”

 
/* Use this with templates/template-twocol.html */