The Supreme Court’s 2024 decision ending Chevron deference made it harder for federal agencies to rely on ambiguity when defending cybersecurity rules. It did not repeal those rules. Instead, courts must independently decide whether Congress gave an agency the authority it claims—a change that raises litigation risk for some requirements, including CISA incident reporting and the FTC’s data-security enforcement, without deciding their fate in advance.
What did the Chevron ruling change?
On June 28, 2024, the Supreme Court decided Loper Bright Enterprises v. Raimondo and overruled the Chevron framework. Under Chevron, a court could defer to an agency’s reasonable interpretation of an ambiguous statute. The Court held that the Administrative Procedure Act instead requires judges to use their own independent judgment about whether an agency acted within its statutory authority. A statute’s ambiguity alone is no longer a reason to accept the agency’s interpretation.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
Cybersecurity Law | $33.00 | Buy on Amazon |
| 2 |
|
Cybersecurity Law | $77.47 | Buy on Amazon |
| 3 |
|
Cybersecurity Law | $129.00 | Buy on Amazon |
| 4 |
|
THE ENCYCLOPEDIA OF GLOBAL CYBERSECURITY LAW AND DIGITAL GOVERNANCE: A Comprehensive Reference for... | $38.43 | Buy on Amazon |
| 5 |
|
Cybersecurity in Context: Technology, Policy, and Law | $84.95 | Buy on Amazon |
That changes the central legal question for a challenged cybersecurity rule. Rather than asking only whether an agency’s reading is reasonable, a court must decide whether Congress authorized the requirement and whether the agency’s interpretation is the best reading of the statute. Clear statutory instructions give an agency a firmer footing. A rule resting on broad, open-ended language or implied powers may face more room for challenge.
Does Loper Bright invalidate existing cybersecurity rules?
No. The decision did not automatically erase existing regulations, and it did not rule that any particular cybersecurity requirement is unlawful. A rule’s durability depends on the statute it implements, the agency’s authority under that statute, and the arguments and record in a specific legal challenge. The ruling changes how courts assess claims of agency authority; it is not a blanket repeal.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
That distinction matters to organizations and consumers alike. A regulation can remain in force unless and until it is changed, withdrawn, or set aside through the applicable legal process. The ruling increases scrutiny and uncertainty, but it does not by itself tell regulated organizations to stop complying.
What does the decision mean for CISA’s CIRCIA rule?
CIRCIA is the Cyber Incident Reporting for Critical Infrastructure Act, and CISA’s incident-reporting requirements have been identified as an example of a cybersecurity regulation that may face questions about statutory authority. The legal issue is whether the Act authorizes the particular reporting duties CISA adopts, not whether incident reporting is important as a policy matter.
Rank #2
CyberScoop reported analyst Harley Geiger’s view that CISA “may need to revise the pending regulation” because parts of CIRCIA involve “ambiguous and unclear or open-ended” language. That is an assessment of litigation risk, not a court ruling. Loper Bright did not decide whether CIRCIA’s requirements are valid. Their outcome would depend on the statutory text and the arguments in any challenge.
Can the FTC still require reasonable data security?
Loper Bright did not remove the FTC’s authority under Section 5 of the FTC Act. The decision does, however, make it harder for the agency to rely on Chevron deference when defending an interpretation of that broad statute. If a company challenges an FTC action involving allegedly inadequate data security, the court must independently assess whether Section 5 authorizes the agency’s position.
Recommended Free Tools
Rank #3
That means increased judicial scrutiny and greater litigation risk—not an automatic end to FTC data-security enforcement. The decision did not establish that reasonable security practices fall outside the FTC’s authority, nor did it guarantee that every agency interpretation will prevail.
Why cybersecurity rules may face particular uncertainty
Federal cybersecurity authority is divided among agencies and laws, many of which were written before today’s technologies and threat models. Agencies may need to apply older, broadly worded statutes to newer security risks. After Loper Bright, challengers can argue that an agency has crossed the limits of its statute without having to overcome a presumption that the agency’s interpretation deserves deference.
Rank #4
The practical result is likely to be rule-by-rule litigation rather than one uniform answer for cybersecurity regulation. Timing, scope, and outcomes may depend on which statute is involved and which court reviews the dispute. No authoritative figure establishes how many cyber rules will fail, or what share of future challenges will succeed.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What could change for agencies, Congress, and regulated organizations?
Congress and agencies
Congress’s statutory language matters more when courts must resolve ambiguity themselves. Detailed mandates can make the intended scope of an agency’s authority clearer. Agencies, in turn, have stronger incentives to explain how each requirement follows from the statute and to build a clear administrative record. Coordination also matters: overlapping or inconsistent requirements can make compliance harder even when each agency has a legal basis for acting.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchBusinesses and other regulated entities
The Government Accountability Office’s 2025 review described cybersecurity as a government-wide high-risk area and documented industry concerns about overlapping federal requirements. Participants discussed harmonization challenges and whether a single entity should have primary authority over different agencies’ cybersecurity regimes.
For an organization assessing a specific rule, the most useful questions are:
- Statutory clarity: Does Congress expressly require the security measure or reporting duty, or is the agency drawing it from broader wording?
- Agency authority: Is the rule based on a specific delegation or a broad, older statute?
- Litigation: Has the rule been challenged, and which court will review it?
- Operational reach: Which sectors and entities must comply, and where might another regulator’s requirements overlap?
- Harmonization: Can the organization meet multiple agencies’ requirements with one control set, or do the requirements conflict?
These questions help identify legal and compliance uncertainty; they do not predict that a particular rule will be invalidated. Organizations should assess obligations under the rule as it currently applies and monitor relevant legal challenges rather than treating the Supreme Court decision as a compliance exemption.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




