Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsThe Supreme Court’s 2024 decision ending Chevron deference made it harder for federal agencies to defend cybersecurity rules that depend on ambiguous or open-ended statutes. It did not repeal those rules. Courts must now independently decide whether Congress authorized an agency’s requirement, leaving some cybersecurity initiatives with greater litigation risk and uncertain durability.
What the Chevron ruling changed
On June 28, 2024, the Supreme Court decided Loper Bright Enterprises v. Raimondo and overruled the Chevron framework. Under Chevron, courts generally deferred to an agency’s reasonable interpretation when the law it administered was ambiguous. The Court held that the Administrative Procedure Act instead requires judges to exercise independent judgment about whether an agency acted within its statutory authority.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
Cybersecurity Law | $32.99 | Buy on Amazon |
| 2 |
|
Cybersecurity Law | $76.50 | Buy on Amazon |
| 3 |
|
Cybersecurity Law | $129.00 | Buy on Amazon |
| 4 |
|
THE ENCYCLOPEDIA OF GLOBAL CYBERSECURITY LAW AND DIGITAL GOVERNANCE: A Comprehensive Reference for... | $38.43 | Buy on Amazon |
| 5 |
|
Cybersecurity in Context: Technology, Policy, and Law | $69.50 | Buy on Amazon |
That changes the legal question in a challenge to a cybersecurity rule. A court no longer upholds an agency’s interpretation simply because it finds that interpretation reasonable in the face of ambiguity. It must decide what the statute means and whether the agency’s action fits within the authority Congress gave it.
Which cybersecurity rules face more legal uncertainty?
Cybersecurity duties come from different statutes administered by different agencies. Some laws predate today’s technologies and threat models, so agencies may rely on broad language to address newer risks. Rules resting on a specific congressional mandate have a firmer statutory footing than those relying on implied powers or an expansive reading of older, general authority.
#1 Best Overall
The practical risk turns on the rule’s legal basis and the circumstances of any challenge—not simply on whether the subject is cybersecurity.
- Statutory clarity: Does the law expressly authorize the security measure, reporting duty, or enforcement power?
- Agency authority: Is the agency carrying out a specific delegation, or applying broad statutory language to a newer problem?
- Judicial exposure: Has a regulated party challenged the rule, and which court will review it?
- Operational reach and overlap: How many entities and sectors are affected, and do other agencies impose overlapping duties?
What the ruling could mean for CISA’s CIRCIA rule
CIRCIA—the Cyber Incident Reporting for Critical Infrastructure Act—provides a statutory basis for incident reporting. The legal question is whether the specific requirements in a regulation stay within the authority Congress granted, not whether CISA can regulate cybersecurity in general.
Rank #2
In reporting on the proposed rule, CyberScoop quoted analyst Harley Geiger warning that CISA might need to revise it because some provisions interpret “ambiguous and unclear or open-ended parts” of the statute. That is an assessment of potential legal exposure, not a court ruling that CIRCIA or its reporting framework is invalid. The available account does not establish a later judicial outcome for the proposal, so its ultimate durability cannot be stated here.
Can the FTC still pursue reasonable data-security practices?
The ruling does not, by itself, strip the Federal Trade Commission of all authority over data security. The potential challenge concerns the statutory basis for a particular action—for example, whether the FTC’s use of Section 5 to pursue a data-security practice is authorized by the statute and fits the facts of the case.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
Without Chevron deference, the agency cannot rely on statutory ambiguity alone to secure judicial acceptance of its interpretation. A court must independently assess the law. That raises litigation risk for actions that depend on broad readings of Section 5, but it does not establish that every FTC data-security case will fail.
Does Loper Bright invalidate existing cyber rules?
No. The decision did not automatically erase existing regulations. A rule’s validity must be addressed through the applicable legal process, including a challenge to the agency action and judicial review under the relevant statute and the Administrative Procedure Act. The court then evaluates whether the agency had authority for the challenged action; the absence of Chevron deference is not itself a judgment that the rule exceeded that authority.
Rank #4
So the likely consequence is increased judicial scrutiny and greater uncertainty about the outcome, timing, and scope of particular challenges—not a blanket repeal of federal cybersecurity requirements. No reliable count or percentage establishes how many cyber rules will fail.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Why coordination and congressional detail matter
The Government Accountability Office’s 2025 review describes cybersecurity as a government-wide high-risk area and records industry concerns about overlapping federal requirements. Participants raised harmonization problems and discussed whether one entity should have primary authority over different agencies’ cybersecurity regimes.
Best Value
Those concerns matter alongside the court ruling: overlapping requirements can be burdensome even when each agency has a sound statutory basis, while broad or unclear mandates may invite disputes about authority. More detailed congressional instructions can narrow those disputes. Agencies, in turn, have reason to explain their statutory basis clearly, build a strong administrative record, and coordinate requirements. These are practical implications, not predictions that any named rule will be struck down.
For organizations subject to federal cyber requirements, track the text of applicable rules as well as litigation over them. A challenge to one agency’s authority does not, on its own, suspend an organization’s obligations under a rule or another regulator’s statute.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

