CXC Insight: Safer Skies Act Interim Final Rule Comments

‍ ‍

Re: Counter-UAS Authority for State, Local, Tribal, and Territorial Law Enforcement and Correctional Agencies; Interim Final Rule; Docket No. FBI-2026-0001; RIN 1110-AA39 / 1601-AB25; 91 Fed. Reg. 41466

‍ ‍

Dear Sir or Madam:

‍ ‍

The Center for Cross-Sector Coordination (CXC) appreciates the opportunity to comment on the Department of Justice (DOJ) and Department of Homeland Security (DHS) Interim Final Rule (IFR), Counter-UAS Authority for State, Local, Tribal, and Territorial Law Enforcement and Correctional Agencies, implementing the SAFER SKIES Act.

‍ ‍

CXC is an industry-led, multi-sector organization that is focused on strengthening the security and resilience of the Nation’s critical infrastructure through collaboration among infrastructure owners and operators, government, technology providers, associations, researchers, and other stakeholders.  CXC’s membership includes companies that operate large facilities across the chemical, energy and various other critical-infrastructure sectors. 

‍ ‍

CXC strongly supports the objectives of the SAFER SKIES Act and the Departments’ efforts to establish a responsible framework through which qualified State, local, Tribal, and territorial (SLTT) agencies can detect, identify, monitor, track, warn against, and, where appropriate, mitigate credible UAS threats. Federal C-UAS resources cannot be present at every potentially affected site, and carefully expanding capability beyond the Federal government is an important step toward strengthening national security and public safety.

‍ ‍

The IFR appropriately addresses training, aviation safety, spectrum use, privacy, operational authority, regional capabilities, and persistent protection of fixed sites. Its success in protecting critical infrastructure, however, will depend on deliberately connecting these new governmental capabilities to the owners and operators responsible for protecting that infrastructure every day.

‍ ‍

That need is particularly important because the Act requires participating agencies to report critical-infrastructure protection requests, whether they were supported, and why requests could not be fulfilled. The Federal government must then determine whether SLTT agencies can fully protect critical infrastructure from the UAS threat and, if not, develop recommendations concerning possible expansion of C-UAS authorities to critical-infrastructure owners.

‍ ‍

Critical-infrastructure owners and operators are also increasingly investing in lawful UAS detection and airspace-awareness capabilities. Implementation should leverage—not inadvertently disrupt—those existing private-sector capabilities and investments.  Infrastructure owners and operators should therefore be treated not simply as requestors of government assistance, but as active partners in planning, information-sharing, risk-assessment, and evaluation.

‍ ‍

With the above principles in view, CXC respectfully offers the following recommendations:

‍ ‍

Recommendation 1: Establish a Clear Pathway for Critical-Infrastructure Owners and Operators to Request C-UAS Protection

‍ ‍

The IFR anticipates that critical-infrastructure owners and operators will request C-UAS protection from SLTT agencies, yet it does not establish a consistent mechanism for determining whom to contact, how to make a request, how requests will be prioritized, or what happens when the contacted agency lacks capability.

‍ ‍

The Departments should establish a streamlined process that:

‍ ‍

  • identifies appropriate State, regional, or local C-UAS points of contact;

  • provides a simple, standardized request mechanism;

  • identifies the responsible agency contact;

  • establishes risk-based prioritization criteria;

  • provides referral or escalation when the receiving agency lacks capability; and

  • permits standing arrangements for facilities facing persistent risks.

‍ ‍

The Departments should also provide owners and operators reasonable visibility into which SLTT agencies possess certified detection, warning, and mitigation capabilities. A public or appropriately access-controlled directory could identify agency contacts and general geographic coverage without revealing sensitive operational details.

‍ ‍

The Federal C-UAS coordination portal demonstrates the value of a streamlined, single-entry approach. Infrastructure owners and operators should have a similarly straightforward interface rather than having to navigate a rapidly evolving patchwork of State and local capabilities.

‍ ‍

Recommendation 2: Integrate Owner & Operator Expertise into Operational Planning and Credible-Threat Assessments

‍ ‍

When a C-UAS operation is intended to protect critical infrastructure, the owner or operator should ordinarily be part of the planning process.

‍ ‍

Infrastructure operators may possess information unavailable to responding agencies, including legitimate UAS activity, facility hazards, high-consequence assets, emergency procedures, nearby aviation or industrial activity, and potential cascading consequences. Such information can materially inform credible-threat determinations and appropriate mitigation.

‍ ‍

CXC therefore recommends that participating agencies, where practicable, identify a facility security/C-UAS point of contact and consult with the owner or operator when developing an Operations Plan for privately owned or operated critical infrastructure.

‍ ‍

The Departments should also clarify that suspicious hovering, repeated or patterned flyovers, apparent surveillance, and unauthorized activity within or near protected critical infrastructure may appropriately inform a credible-threat determination under the totality of the circumstances. This should include unauthorized activity within an FAA-established Section 2209 UAS Flight Restriction.

‍ ‍

Such activity should not automatically constitute a credible threat or displace the IFR’s requirement for a current, articulable risk. Rather, the framework should ensure that responding personnel can appropriately consider facility-specific context and information available to the owner or operator.

‍ ‍

This would not transfer governmental authority to the facility; however, it would ensure that government decisions benefit from relevant facility expertise.

‍ ‍

Recommendation 3: Encourage Regional and Multi-Jurisdictional C-UAS Capabilities Organized Around Critical-Infrastructure Needs

‍ ‍

CXC strongly supports the IFR’s recognition of regional, county, statewide, and multi-jurisdictional C-UAS programs, including mutual-aid arrangements.This approach is particularly important for critical infrastructure. Ports, petrochemical corridors, transportation hubs, energy systems, communications networks, and water systems often operate as interconnected regional ecosystems crossing jurisdictional boundaries.

‍ ‍

The Departments should encourage States and metropolitan regions to develop C-UAS frameworks incorporating pre-identified infrastructure clusters, standing mutual-aid agreements, designated infrastructure contacts, common communications procedures, and coordinated training and exercises.  Where legally appropriate, Federal grant programs should reinforce interoperable regional capabilities capable of supporting multiple infrastructure sectors rather than fragmented systems with limited reach.

‍ ‍

Recommendation 4: Preserve and Streamline Persistent Protection for Fixed Critical-Infrastructure Sites

‍ ‍

CXC strongly supports § 124.8(h), which permits operational windows of up to 365 days for persistent protection at fixed sites, including critical infrastructure.

‍ ‍

Where the facility, C-UAS system, operating concept, airspace environment, and threat conditions have not materially changed, agencies should be permitted to incorporate previously reviewed information by reference and submit only material updates.

‍ ‍

CXC likewise supports FAA authority to establish categorical determinations for recurring combinations of authorized technologies, locations, and airspace environments. The FAA and the Departments should actively use this authority for fixed critical-infrastructure operations so that mature, proven operations become progressively more efficient.

‍ ‍

Recommendation 5: Establish a Practical, Two-Way Information-Sharing Framework

‍ ‍

Successful C-UAS operations require situational awareness on both sides of the public-private partnership.

‍ ‍

CXC supports the privacy protections in § 124.14 and does not suggest that infrastructure owners should automatically receive intercepted communications or other restricted information. The Departments should, however, provide clear guidance enabling agencies to share sanitized, operationally actionable information with protected facilities to the fullest extent permitted by law.

‍ ‍

Depending on circumstances, this could include detection and track information, general location and direction of travel, threat status, warnings issued, mitigation status, information needed to protect personnel or operations, and an operational “all clear.”

‍ ‍

Agencies should likewise have mechanisms for receiving relevant information from facility security operations centers, lawful facility detection systems, and other owner/operator sources.

‍ ‍

A protected facility should not be left unnecessarily blind during an unfolding UAS event, nor should agencies lack access to relevant information already available to the facility.

‍ ‍

Recommendation 6: Protect Sensitive Critical-Infrastructure Information

‍ ‍

CXC supports § 124.15’s protections for sensitive C-UAS operational information. Comparable attention should be given to sensitive information supplied by infrastructure owners and operators.

‍ ‍

Effective planning may require facilities to provide information concerning vulnerabilities, high-consequence assets, security measures, facility layouts, detection coverage, or operational responses. Protection-request data could also reveal where significant risks or capability gaps exist.

‍ ‍

The Departments should ensure that such information is collected only when materially necessary and protected to the maximum extent permitted by law, including through appropriate Controlled Unclassified Information, law-enforcement-sensitive, Protected Critical Infrastructure Information, or other safeguards.

‍ ‍

Public reporting should likewise avoid identifying facilities that requested protection, locations where requests could not be supported, or the operational characteristics of C-UAS coverage.

‍ ‍

Recommendation 7: Maintain an Innovation-Friendly Technology-Approval Framework and Protect Existing Private-Sector Detection Capabilities

‍ ‍

CXC supports the technology-approval framework established in § 124.7, under which the Departments maintain an Authorized Technologies List identifying approved categories of C-UAS technology and an Authorized Systems List (ASL) identifying specific approved systems. Systems generally must be nominated by an accredited agency and undergo interagency evaluation before being added to the ASL, with systems previously used by Federal agencies potentially receiving expedited consideration.

‍ ‍

As the ASL evolves, the Departments should carefully assess implications for detection technologies already deployed by critical-infrastructure owners and operators. Section 124.7 distinguishes technologies whose operation relies on the legal authorities and statutory relief provided by 6 U.S.C. § 124n from technologies that may be lawfully operated without that authority. The IFR identifies electro-optical and infrared cameras, acoustic sensors, and radar operated under appropriate FCC authorization as examples of detection activities that may not require authority under the Act. Notably, radio frequency (RF) detection is not included among those examples.

‍ ‍

This distinction matters because critical-infrastructure owners and operators are increasingly investing in layered detection capabilities—including RF technologies—to enhance airspace awareness, support incident response, prepare for emerging frameworks such as Section 2209 UAS Flight Restrictions, and coordinate with authorized law-enforcement partners. Decisions affecting whether particular RF or other detection technologies are included within, or otherwise affected by, the ASL could therefore have significant operational, legal, and investment consequences.

‍ ‍

Before adding, reclassifying, or otherwise addressing RF detection technologies—or other technologies already deployed across critical infrastructure—through the ASL in a manner that could affect private-sector use, the Departments should comprehensively assess existing deployments and consult with affected infrastructure owners and operators, technology providers, and other stakeholders. That review should consider how widely systems are deployed, how they are currently used, the legal basis for those deployments, relevant technical characteristics, and potential impacts on security and prior investments.

‍ ‍

The Departments should also provide appropriate transparency regarding material ASL changes and clearly explain their implications for private-sector users. Where a Federal determination identifies legal limitations affecting RF or other detection technologies already in use, affected owners and operators should receive timely guidance regarding continued lawful use, necessary modifications, or transition options. Implementation should avoid unnecessarily stranding lawful capabilities or discouraging further investment in critical-infrastructure domain awareness.

‍ ‍

More broadly, the technology-approval process should remain responsive to innovation. The Departments should establish clear evaluation criteria and predictable timelines, provide pathways for emerging capabilities, distinguish material changes from routine software and firmware updates, encourage interoperability, and regularly engage technology providers, infrastructure operators, and end users.

‍ ‍

The Departments should also provide practical guidance on lawful public-private operating models.  Under existing law, mitigation-authority and credible-threat determination responsibilities remain with qualified government personnel; however, private-sector entities can nonetheless play important roles in detection, technical support, maintenance, training, and integration. Model concepts of operation could demonstrate how certified public personnel can work effectively with facility security teams, technology providers, lawful detection systems, and existing security operations centers.

‍ ‍

Recommendation 8: Measure Whether the Framework Actually Meets Critical-Infrastructure Protection Needs

‍ ‍

The SAFER SKIES Act requires an assessment of whether SLTT agencies are able to fully protect critical infrastructure from the UAS threat and, if not, recommendations concerning possible expansion of authority to critical-infrastructure owners.

‍ ‍

Tallying requests received, supported, and unsupported will not answer that question. A request classified as “supported” could still involve delayed response, partial coverage, or detection without available mitigation.

‍ ‍

The Departments should, therefore, consider measures including:

‍ ‍

  • response time;

  • availability of trained personnel and appropriate systems;

  • geographic distance to available capability;

  • whether protection was episodic or persistent;

  • duration of requested and provided coverage;

  • reasons requests could not be fully supported; and

  • airspace, spectrum, staffing, equipment, training, or legal constraints.

‍ ‍

The evaluation should also include structured input directly from infrastructure owners and operators, rather than relying only on agency reporting. The central question is not merely whether SLTT agencies are successfully establishing C-UAS programs. It is whether the resulting system adequately protects critical infrastructure.

‍ ‍

If implementation reveals continuing gaps, the Departments should use that evidence not only to advise Congress on whether additional authority is warranted, but to develop recommendations for a clear pathway through which qualifying critical-infrastructure owners and operators could obtain specified C-UAS authorities. Any such framework could appropriately include Federal eligibility standards, training and certification requirements, use of approved technologies, airspace and spectrum coordination, privacy protections, reporting, and oversight.

‍ ‍

The present rulemaking need not prejudge whether or how such authority should ultimately be granted. It should, however, ensure that implementation produces the evidence and operational experience necessary to evaluate that option—and that critical-infrastructure owners and operators have a meaningful voice in that evaluation.

‍ ‍

Recommendation 9: Establish an Enduring Critical Infrastructure C-UAS Public-Private Advisory Working Group

‍ ‍

UAS threats, C-UAS technologies, SLTT capabilities, aviation and spectrum requirements, and private-sector detection capabilities are evolving too rapidly for a one-time rulemaking alone to provide a sufficient implementation mechanism.  With this in mind, CXC recommends that DHS and DOJ establish an enduring Critical Infrastructure C-UAS Public-Private Advisory Working Group to support SAFER SKIES implementation and the continuing evaluation Congress has required.

‍ ‍

The group should include appropriate representatives from DHS, DOJ/FBI, DOT/FAA, FCC, participating SLTT agencies, critical-infrastructure owners and operators, sector and cross-sector associations, C-UAS technology providers, aviation and UAS stakeholders, and relevant research, standards, and academic organizations.  Its purpose should be to complement—not duplicate—existing Federal structures by providing a sustained operational public-private interface focused on critical-infrastructure protection.

‍ ‍

Among other responsibilities, the group could:

‍ ‍

  1. identify implementation barriers;

  2. develop model procedures for infrastructure protection requests;

  3. advance regional and cross-jurisdictional operating models;

  4. develop public-private information-sharing practices;

  5. identify protections for sensitive infrastructure information;

  6. provide input on technology and interoperability;

  7. promote training and exercises involving infrastructure operators;

  8. assess supported and unmet protection needs;

  9. identify emerging threats and technologies; and

  10. inform the congressionally required assessment of whether infrastructure owners ultimately require additional C-UAS authority.

‍ ‍

Given Congress’s direction that the Departments assess whether SLTT agencies can fully protect critical infrastructure, that determination should not be made without sustained engagement with the owners and operators whose protection is being evaluated. 

‍ ‍

It bears noting also that, collaborative models such as the one CXC is proposing have proven successful across numerous security initiatives, where sustained engagement between government and industry has consistently produced more practical, effective, and broadly supported outcomes. CXC would welcome the opportunity to participate in such an effort and to help connect Federal government partners with the broader cross-sector critical-infrastructure community.

‍ ‍

Conclusion

‍ ‍

The SAFER SKIES Act is an important step toward closing a longstanding gap in the Nation’s ability to address unauthorized and malicious UAS activity. CXC supports the responsible expansion of C-UAS capabilities to qualified SLTT agencies.

‍ ‍

For critical infrastructure, however, success should not be measured simply by the number of agencies accredited, personnel certified, or systems deployed. The more important question is whether an owner or operator facing a credible UAS threat can access an effective capability when and where it is needed.

‍ ‍

CXC therefore encourages the Departments to build the necessary public-private connective tissue from the outset: establish a workable protection-request process; integrate owners and operators into operational planning; support regional capabilities; streamline persistent protection; facilitate lawful two-way information sharing; protect sensitive infrastructure information; preserve technological innovation; measure the actual protection gap; and establish an enduring public-private advisory mechanism as threats, technologies, and authorities evolve.

‍ ‍

CXC appreciates the opportunity to provide these comments and looks forward to continuing to work with Federal, SLTT, and private-sector partners to strengthen the Nation’s ability to address the evolving UAS threat.

‍ ‍

Respectfully submitted,

‍ ‍

Dave Wulf
President & Chief Executive Officer
Center for Cross-Sector Coordination
5680 King Centre Drive, Suite 600
Alexandria, Virginia 22315
info@cross-sector.org

‍ ‍

 

‍ ‍

Next
Next

CXC Insight: Our FAA 2209 Comments Have Been Submitted!