The new proposal would codify provisions from previous directives, a spokesman for the agency said. Under the rules, freight and passenger railroads as well as rail transit and pipeline facilities would have to report cyberattacks to the Cybersecurity and Infrastructure Security Agency within 24 hours after identifying them and do annual cyber evaluations. More bus operators also would fall under the new rules, which have been in development since 2022.