Three separate Department of Homeland Security (DHS) agencies are imposing different cybersecurity rules on the same companies, forcing some operators to navigate conflicting definitions, timelines, and reporting requirements. A Congressional Research Service (CRS) report released in June examines how this fragmentation is straining industry compliance efforts and what Congress might do to fix it.