CXC Insight: Our FAA 2209 Comments Have Been Submitted!

COMMENTS OF THE CENTER FOR CROSS-SECTOR COORDINATION (CXC)

Regarding the Federal Aviation Administration's Proposed Rule,
"Designation—Restrict the Operation of Unmanned Aircraft in Close Proximity to a Fixed Site Facility"  

Docket No. FAA-2026-4558

Executive Summary

The Center for Cross-Sector Coordination (CXC) appreciates the opportunity to comment on the Federal Aviation Administration's proposed rule implementing Section 2209 of the FAA Extension, Safety, and Security Act of 2016.

CXC strongly supports the FAA's efforts to establish a transparent, practical process through which eligible fixed-site facilities may seek restrictions on unmanned aircraft system (UAS) operations where unauthorized activity could threaten public safety, economic security, or national resilience. Implementation of Section 2209 should, in CXC’s view, strengthen security and safety while minimizing unnecessary administrative burden, protecting sensitive facility information, and preserving the many legitimate uses of unmanned aircraft that themselves contribute to infrastructure safety, reliability, emergency response, and resilience.

America's critical infrastructure is increasingly defined by its interconnectedness. The systems that power our communities, move our goods, deliver clean water, enable communications, support healthcare, manufacture essential products, and sustain our economy operate as an integrated network rather than as isolated facilities. As a result, disruption affecting a single high-consequence asset can quickly cascade across multiple infrastructure sectors, amplifying operational, economic, and public safety impacts.

The rapid proliferation of increasingly capable and affordable UAS presents both extraordinary opportunities and evolving security challenges. While drones have become indispensable tools supporting infrastructure inspection, maintenance, emergency response, disaster recovery, and countless other beneficial purposes, they also introduce new vulnerabilities for facilities that provide essential services upon which the Nation depends. Protecting critical infrastructure from unauthorized or malicious UAS activity is therefore not solely an aviation issue; it is also a matter of homeland security, economic security, public safety, and national resilience.

As a national, nonpartisan organization representing critical infrastructure owners and operators, technology and solutions providers, and other security-and-resilience stakeholders, CXC believes this rulemaking presents an important opportunity to establish a durable, risk-informed framework that strengthens infrastructure protection while preserving the continued integration of UAS into the National Airspace System.

To strengthen implementation of Section 2209, CXC respectfully recommends that FAA:

  1. Implement a risk-informed framework that emphasizes operational consequence, infrastructure interdependencies, and national resilience.

  2. Recognize the variances across America's critical infrastructure by providing flexibility for differing facility types, operating environments, and security and safety considerations.

  3. Design a simple, transparent, and scalable program that minimizes unnecessary burden, leverages existing Federal security programs, supports batch applications where appropriate, and limits information requirements to those necessary for informed decision-making.

  4. Build upon existing Federal security and safety programs by streamlining review for facilities already recognized as high-consequence assets.

  5. Ensure operationally meaningful protections through appropriately tailored stand-off distances and implementation of allowed operations that preserve the security value of UAS Flight Restrictions.

  6. Enable portfolio applications for organizations operating multiple similarly situated facilities.

  7. Protect sensitive facility information through data-minimization principles, self-attestation where appropriate, and safeguards against unnecessary public disclosure of sensitive facility information.

  8. Maintain a technology-neutral framework that can adapt to emerging capabilities and evolving threats.

  9. Support and leverage an enduring public-private partnership to contribute to continuous improvement of the Section 2209 program.

  10. Recognize Section 2209 as one element of a broader counter-UAS strategy by continuing to pursue authorities, technologies, and partnerships that enable effective detection, identification, and mitigation of malicious UAS activity.

These recommendations are intended to strengthen implementation of Section 2209 while advancing a shared objective of government and industry: protecting America's critical infrastructure from evolving aerial threats while preserving the many benefits that unmanned aircraft systems provide to commerce, public safety, emergency response, and the Nation's long-term security and resilience.

America's Critical Infrastructure Requires a Risk-Informed Approach to UAS Security

America's critical infrastructure is extraordinarily diverse, yet increasingly interconnected. The systems that generate electricity, provide drinking water, move freight, enable communications, manufacture essential goods, support healthcare, and sustain our economy operate as an integrated network. As a result, disruption at a single high-consequence facility can quickly cascade across multiple sectors, creating consequences far beyond the affected site.

The rapid evolution of unmanned aircraft systems has introduced a new dimension to this risk environment. While UAS technologies have become indispensable tools supporting commerce, infrastructure inspection, emergency response, and other beneficial activities, they also present new opportunities for unauthorized surveillance, operational disruption, and malicious activity targeting facilities essential to national security, economic stability, and public safety. The challenge before FAA is therefore to develop a practical, risk-informed framework that strengthens critical infrastructure security and safety while preserving the continued growth and safe integration of unmanned aircraft into the National Airspace System.

The Center for Cross-Sector Coordination (CXC) was established to help address precisely these types of cross-sector challenges. As a national, nonpartisan organization, CXC brings together critical infrastructure owners and operators, technology and solutions providers, government partners, research institutions, academia, and nonprofit organizations to strengthen the security and resilience of the Nation's critical infrastructure. Unlike organizations representing a single sector, CXC focuses on the shared risks, interdependencies, and collaborative solutions that span all sixteen critical infrastructure sectors.

Accordingly, CXC welcomes FAA's implementation of Section 2209 and offers the following recommendations to strengthen the rule through a uniquely cross-sector perspective while supporting the safe, secure, and responsible integration of unmanned aircraft into the National Airspace System.

Recommendations for Strengthening Implementation of Section 2209

Recommendation 1: Implement the Program Through a Risk-Informed Framework

CXC strongly supports FAA's establishment of a process through which eligible facilities may request restrictions on unauthorized UAS operations. As the Agency finalizes implementation, the program should remain fundamentally risk-informed rather than prescriptive.

The purpose of Section 2209 is not simply to restrict airspace; it is to reduce the security risks posed by unauthorized UAS activity at facilities whose disruption could have significant consequences for public safety, national security, economic stability, or the continuity of essential services. Accordingly, application decisions should emphasize risk and consequence, recognizing that facilities presenting comparable consequences may differ substantially in size, configuration, ownership, and operating environment.

FAA should retain flexibility to consider factors such as: the potential consequences of disruption; a facility's role within broader critical infrastructure systems; dependencies and interdependencies with other infrastructure sectors; existing security measures and regulatory oversight; the operational environment and surrounding land use; and credible threat information developed through existing Federal security programs.

This approach is consistent with longstanding Federal critical infrastructure policy emphasizing consequence-based risk management and resilience.

Recommendation 2: Recognize the Diversity of America's Critical Infrastructure

America's critical infrastructure encompasses an extraordinary range of facilities—from electric substations, water treatment plants, telecommunications hubs, ports, refineries, manufacturing campuses, chemical facilities, and dams to countless other assets that differ dramatically in mission, size, operating environment, ownership, and security posture.

Accordingly, FAA should avoid unnecessarily rigid eligibility criteria or standardized assumptions regarding facility configuration or operational boundaries. Instead, applicants should be afforded the opportunity to demonstrate how their unique operating environments influence the security and safety risks associated with unauthorized UAS activity.

Providing this flexibility will improve the effectiveness of the program while allowing FAA to apply consistent evaluation criteria without forcing critical infrastructure into a one-size-fits-all regulatory model. Recognizing operational diversity will also increase confidence among infrastructure owners and operators that applications will receive informed, equitable consideration.

Recommendation 3: Design the Program for Simplicity, Transparency, and Scalability

Critical infrastructure owners and operators already comply with extensive Federal safety, security, cybersecurity, and emergency preparedness requirements. Wherever practical, the Section 2209 application process should complement and leverage—not duplicate—those existing obligations.

FAA should request only information that is necessary and materially relevant to determining whether a UAS Flight Restriction is warranted. Requiring extensive supporting documentation—including vulnerability assessments, detailed security information, and records of unauthorized UAS activity—may impose unnecessary administrative burdens, discourage participation, produce inconsistent results and, as discussed in Recommendation 7, unnecessarily concentrate sensitive security information. Wherever detailed documentation is not essential, FAA should permit concise summaries, representative examples, or self-attestation supported by applicant-maintained records.

FAA also should not condition eligibility on an applicant's existing UAS detection capabilities. Applicants seeking Section 2209 protections should be permitted to describe planned capabilities, existing security programs, or other appropriate means of documenting unauthorized UAS activity.

CXC recommends a standardized, secure, and transparent application process that includes:

  • standardized electronic applications with secure online submission and applicant status tracking;

  • clear implementation guidance, published review timelines, and streamlined renewal procedures;

  • efficient procedures for correcting incomplete applications without restarting the review process;

  • portfolio (batch) applications for organizations seeking protection for multiple similarly situated facilities under common ownership or management;

  • data-minimization standards limiting submissions to information necessary for FAA's review;

  • dedicated points of contact to assist applicants throughout the application process.

These measures will reduce administrative burden, improve consistency, and enable the Section 2209 program to scale efficiently as participation expands.

Recommendation 4: Build Upon Existing Federal Security Programs and Recognize Existing Security and Safety Investments

The Federal Government has invested decades in identifying, assessing, and protecting facilities whose disruption could have significant consequences for public safety, national security, economic stability, and the continuity of essential services. As FAA implements Section 2209, it should build upon these existing investments rather than requiring applicants to recreate information—or re-establish security concerns—that have already been recognized through other Federal programs.

Many critical infrastructure facilities already operate under comprehensive security, emergency preparedness, and safety requirements administered by Federal departments and agencies. These programs frequently include security plans, vulnerability assessments, consequence analyses, emergency response planning, and regular regulatory oversight that are directly relevant to evaluating Section 2209 applications.

FAA should develop a framework to account for facilities’ participation in other Federal security and safety programs in a fashion that appropriately informs and streamlines the review process while preserving FAA's independent aviation decision-making authority.

Leverage Existing Documentation

Accordingly, CXC recommends that FAA expressly permit applicants to reference or incorporate documentation developed under established Federal security and safety programs, including, where applicable:

  • Maritime Transportation Security Act (MTSA) Facility Security Assessments and Facility Security Plans;

  • Nuclear Regulatory Commission (NRC) security programs;

  • Transportation Security Administration (TSA) security requirements;

  • North American Electric Reliability Corporation Critical Infrastructure Protection standards;

  • Security and resilience assessments conducted by Sector Risk Management Agencies;

  • the Chemical Facility Anti-Terrorism Standards (CFATS) program

Recognizing these existing materials as supporting documentation would reduce duplication, improve administrative efficiency, and allow FAA reviewers to focus on the aviation-specific and operational considerations unique to each application.

Streamline Review for High-Consequence Facilities

FAA should also establish a streamlined review process—or a rebuttable presumption regarding the security basis for an application—for facilities already recognized under significant Federal statutory or regulatory security programs. Examples include MTSA-regulated facilities, NRC licensees, facilities subject to TSA security requirements, and facilities possessing threshold quantities of chemicals formerly identified under Appendix A of the Chemical Facility Anti-Terrorism Standards (CFATS) regulation.

This recommendation does not suggest automatic approval. FAA should continue to evaluate each application based on aviation safety, operational considerations, requested boundaries, and other factors within its statutory authority. Applicants should not, however, be required to repeatedly demonstrate security concerns that they have already established under other Federal statutory or regulatory frameworks.

Leveraging prior Federal determinations in this manner will reduce unnecessary administrative burden, improve consistency across the Federal Government's critical infrastructure protection enterprise, and allow FAA to focus its resources on the issues unique to implementing Section 2209.

Recommendation 5: Ensure Operationally Meaningful UAS Flight Restrictions, including Reasonable Lateral “Stand-Off” Boundaries

A Section 2209 designation should provide meaningful security value by allowing facility personnel and responding authorities sufficient time to detect, assess, communicate, and respond to unauthorized UAS activity. For many facilities, accomplishing these objectives may require operational boundaries extending beyond the physical property line.

Accordingly, FAA should preserve flexibility for applicants to demonstrate the need for reasonable lateral boundaries based on facility-specific circumstances. Such determinations should consider factors including the facility's operational characteristics, surrounding land use, adjacent transportation corridors, terrain, proximity to navigable waterways, aviation safety considerations, impacts on neighboring property owners, and the ability of facility personnel and law enforcement to respond effectively to unauthorized UAS activity. The objective should be to establish boundaries that are operationally meaningful while remaining narrowly tailored to the specific risks presented by each facility.

CXC supports FAA's objective of preserving legitimate governmental, commercial, and infrastructure-supporting UAS operations. At the same time, allowed operations should not diminish the security value of UAS Flight Restrictions for high-consequence facilities. Broad categories of permitted operations may complicate domain awareness by making it more difficult for facility personnel to distinguish authorized from potentially malicious UAS, delaying response during security incidents.

FAA should therefore ensure that allowed operations remain sufficiently limited to preserve the operational value of UAS Flight Restrictions for high-consequence facilities. Where appropriate, the Agency should consider sector-specific implementation, enhanced coordination, or advance notification for certain routine non-emergency operations to improve situational awareness while preserving FAA's exclusive authority over the National Airspace System. Emergency response, military, and other time-sensitive governmental operations should remain unaffected.

The objective should not be to maximize restricted airspace, but to establish operationally meaningful UAS Flight Restrictions that reduce unauthorized UAS risk, improve the ability of facility personnel to distinguish benign from potentially malicious aircraft, and preserve beneficial UAS uses such as infrastructure inspection, maintenance, emergency response, disaster recovery, environmental monitoring, and resilience.

Recommendation 6: Enable Portfolio Applications for Similarly Situated Facilities

Many critical infrastructure owners and operators manage dozens—or even hundreds—of facilities with common ownership, governance, security programs, and operational practices. Requiring separate applications for each facility would create unnecessary burden where much of the supporting information is identical.

CXC recommends that FAA permit portfolio applications and allow applicants to submit common organizational information, shared security documentation, governance materials, and other standardized information once, while providing facility-specific information for individual review. This approach would preserve FAA's ability to evaluate each facility on its own merits while reducing duplication, improving consistency, and enabling the program to scale efficiently.

Recommendation 7: Protect Sensitive Information While Preserving Operational Security

The success of the Section 2209 program will depend on the willingness of critical infrastructure owners and operators to provide FAA with the information needed for informed decision-making. Many applications will necessarily include sensitive security information—including facility layouts, security systems, vulnerability assessments, critical assets, emergency response procedures, and unauthorized UAS activity—that could increase security risks if improperly disclosed or unnecessarily centralized.

FAA should therefore apply principles of data minimization throughout the application process, requesting only the information necessary to evaluate whether a UAS Flight Restriction is warranted. As discussed in Recommendation 3, requiring applicants to submit extensive supporting documentation—including detailed vulnerability assessments, security-system descriptions, comprehensive 24-month incident histories, and other operational information—may impose significant administrative burdens while also unnecessarily concentrating sensitive security information within a centralized repository. Wherever detailed supporting documentation is not essential to FAA's determination, the Agency should permit applicants to provide appropriate certifications or self-attestations, while retaining supporting documentation locally for inspection or validation if necessary. This approach would reduce administrative burden, encourage broader participation, and better protect sensitive security information.

Additionally, FAA should establish clear procedures for the submission, handling, protection, retention, and disposition of application materials. Such guidance should address protection from public disclosure, Freedom of Information Act requests, interagency coordination, records-retention policies, and applicant best practices. Clear procedures will encourage more-complete submissions while strengthening trust between government and critical infrastructure owners and operators.

FAA should also evaluate whether aspects of the proposed notice-and-comment process for facility-specific UAS Flight Restrictions could inadvertently create security risks. Publicly identifying facilities seeking enhanced protection—or disclosing threat assessments, security vulnerabilities, operational timing considerations, or other sensitive information before protections are established—could reveal potential targets or provide malicious actors with valuable security insights. FAA should therefore preserve appropriate transparency while minimizing unnecessary public disclosure of facility-specific security information during the application process.

Recommendation 8: Preserve Flexibility for Emerging Technologies and Future Threats

The pace of innovation within the unmanned aircraft ecosystem continues to accelerate. Advances in autonomy, artificial intelligence, sensing technologies, communications, Remote ID, and other capabilities are rapidly transforming both the opportunities and the risks associated with UAS operations. At the same time, technologies supporting infrastructure protection—including advanced detection systems, integrated sensor networks, automated monitoring platforms, and authorized counter-UAS capabilities—continue to evolve.

Accordingly, FAA should implement Section 2209 through a technology-neutral framework that accommodates continued innovation rather than prescribing technologies or operational approaches that may quickly become outdated.

FAA should also periodically evaluate implementation experience and emerging technologies to determine whether updates to guidance, administrative procedures, or future rulemaking are warranted.

Recommendation 9: Leverage an Enduring Public-Private Partnership

Successful implementation of Section 2209 will require sustained collaboration among FAA; the Cybersecurity and Infrastructure Security Agency (CISA); Sector Risk Management Agencies; state and local governments; critical infrastructure owners and operators and associated convening organizations such as CXC; technology and solutions providers; and other stakeholders responsible for protecting the Nation's essential systems.

Accordingly, CXC encourages FAA to establish a standing Critical Infrastructure UAS Advisory Working Group representing relevant Federal agencies and a diverse cross-section of critical infrastructure sectors. Such a forum would help FAA to identify implementation challenges, including administrative burden; share operational best practices and lessons learned; recommend administrative improvements; monitor emerging technologies and evolving threats; strengthen interagency coordination; and inform future policy development as operational experience grows.  

This collaborative model has proven successful across numerous security initiatives, where sustained engagement between government and industry has consistently produced more practical, effective, and broadly supported outcomes. CXC would welcome the opportunity to participate in such an effort and to help connect FAA with the broader cross-sector critical-infrastructure community.

Recommendation 10: Continue Advancing a Comprehensive Counter-UAS Framework for Critical Infrastructure

CXC believes this rulemaking represents an important milestone in strengthening the security and resilience of America's critical infrastructure. Establishing UAS Flight Restrictions around high-consequence facilities will help distinguish authorized from potentially malicious aircraft and enhance protection against evolving UAS threats.

Section 2209, however, addresses only one component of a broader challenge. While it establishes a framework for restricting UAS operations, it does not itself provide the authorities, technologies, or operational capabilities needed to detect, identify, track, or mitigate malicious UAS activity. Continued progress will require sustained collaboration among FAA, the Department of Homeland Security, the Department of Justice, the Department of Defense, Sector Risk Management Agencies, state and local governments, critical infrastructure owners and operators, technology developers, and other stakeholders.

Accordingly, CXC encourages FAA to continue working with these partners to:

  • develop best practices for protecting critical infrastructure from unauthorized UAS operations;

  • improve reporting and information sharing regarding significant UAS incidents;

  • incorporate UAS scenarios into cross-sector exercises and preparedness activities;

  • harmonize future policies, authorities, and guidance affecting infrastructure protection;

  • encourage innovation that strengthens both aviation safety and critical infrastructure security; and

  • continue advancing the public-private partnerships that underpin the Nation's critical infrastructure security enterprise.

CXC views the Section 2209 program not as a static regulatory framework, but as a living program that should continue to evolve alongside emerging technologies, changing threats, and operational experience.

Conclusion

The Center for Cross-Sector Coordination commends the Federal Aviation Administration for advancing this important rulemaking and appreciates the agency's thoughtful implementation of Section 2209.

The proposed rule recognizes an increasingly important reality: that the continued evolution of unmanned aircraft systems, while creating extraordinary opportunities for commerce, innovation, and public service, also requires practical mechanisms for protecting facilities whose disruption could have significant consequences for public safety, economic security, national defense, and the resilience of the Nation's critical infrastructure.

With targeted refinements emphasizing risk-informed implementation; operational flexibility; reduction of administrative burden; protection of sensitive information; and continued public-private collaboration, the final rule can establish a durable framework that strengthens infrastructure security and resilience while preserving the safe and responsible integration of unmanned aircraft into the National Airspace System.

CXC appreciates the opportunity to provide these comments and looks forward to continued collaboration with FAA, the Cybersecurity and Infrastructure Security Agency, Sector Risk Management Agencies, Congress, and the broader critical infrastructure community as this important program moves from rulemaking to implementation.

Previous
Previous

CXC Insight: Safer Skies Act Interim Final Rule Comments

Next
Next

CXC Insight: An Unprecedented Cyber Incident and What CI Operators Need to Know