CXC Insight: Commenting on the FAA Proposed Section 2209 – Unmanned Aircraft Flight Restrictions

What you need to know:  

The FAA has extended the Section 2209 Comment Period until August 5th.  

The proposed rule would establish the process for eligible critical infrastructure facilities to request and maintain restrictions on unmanned aircraft (drone) operations over their sites.

  • CXC is engaging with owners, operators, and industry associations to better understand the proposed rule's potential impacts and is considering submitting comments informed by these discussions.

  • The rule creates two types of UAFRs:

  • o   Standard UAFR: A defined airspace volume (horizontal limits within property lines, default 400 ft AGL) where drone operations are restricted; can be continuous or part‑time (max 290 days/year for seasonal facilities)

  • o   Special UAFR: More restrictive, for facilities with verified credible threats, often tied to national security or homeland security, and lasting up to five years

CXC is in conversations with numerous owners and operators and industry associations on concerns and proposed comments.

Concerns that have been raised and are under consideration for CXC comments:

  1. The requirement for notice and comment to request special UAFR creates an extended process and delayed decision-making for owners and operators and could increase the risk of revealing threat assessments, security vulnerabilities, or operational timing considerations and even creating a target list.

  2. Even once granted, there are extensive exemptions for allowed operations granting access to UAS into the restricted areas creating difficulty in maintaining domain awareness, identifying malicious UAS, and enforcing the restricted area.

  3. There are ongoing concerns over costs to critical infrastructure for detection capabilities without understanding if the detection capability will make a difference in addressing the threat.

  4. Significant burden exists for critical infrastructure on submitting requests, which could be expedited by allowing for batch submissions, vetting by the Sector Risk Management Agency, or other methods.

  5. At a strategic level, the rulemaking supports the development of restricted areas and thus the ability to detect benign vs. malicious UAS, but does not address mitigation.

If you’d like to discuss this with us, please reach out to Kelly.Murray@cross-sector.org

Previous
Previous

CXC Insight: The White House’s National Resilience Strategy

Next
Next

Maritime Transportation System ISAC's Cybersecurity Summit