RuleUSRule

Counter-UAS Authority for State, Local, Tribal, and Territorial Law Enforcement and Correctional Agencies

Published by Homeland Security Department on 2026-07-06

Issued by
Homeland Security Department
Jurisdiction
US
Takes effect
2026-07-01
Comments close
Not applicable

In the issuer’s words

Document Headings

Document headings vary by document type but may contain the following:

  1. the agency or agencies that issued and signed a document
  2. the number of the CFR title and the number of each part the document amends, proposes to amend, or is directly related to
  3. the agency docket number / agency internal file number
  4. the RIN which identifies each regulatory action listed in the Unified Agenda of Federal Regulatory and Deregulatory Actions

See the Document Drafting Handbook for more details.

Department of Homeland Security

  1. 6 CFR Part 124
  2. RIN 1601-AB25

Department of Justice

  1. 28 CFR Part 124
  2. [Docket No. FBI-2026-0001]
  3. RIN 1110-AA39
( printed page 41466)

AGENCIES:

Department of Homeland Security; Department of Justice.

ACTION:

Interim final rule; request for comment.

SUMMARY:

In this interim final rule (“IFR”), the Department of Justice (“DOJ”) and the Department of Homeland Security (“DHS”) (collectively, “the Departments”) codify the framework for implementing the SAFER SKIES Act, which authorizes State, local, Tribal, and territorial law enforcement or correctional (“SLTT”) agencies to conduct counter-unmanned aircraft system (“C-UAS”) operations. This framework governs training and certification (including a two-tiered structure for detection and warning operations and for mitigation operations), authorized technologies, spectrum coordination, airspace approval, real-time air traffic control notification, mitigation reporting, privacy protections, and compliance requirements for SLTT agencies in relation to the exercise of C-UAS authority.

DATES:

Effective date: This interim final rule is effective July 1, 2026.

Comment due date: Comments must be received on or before September 4, 2026. The electronic Federal Docket Management System (“FDMS”) at https://www.regulations.gov will accept electronic comments until 11:59 p.m. Eastern Time on that date.

ADDRESSES:

You may submit comments on the entirety of this IFR, identified by FDMS Docket No. FBI-2026-0001, through the Federal eRulemaking Portal: https://www.regulations.gov. Follow the website instructions for submitting comments. The Departments are not accepting mailed, couriered, or hand-delivered comments at this time. If you cannot submit your comment by using https://www.regulations.gov, please use the contact information in the FOR FURTHER INFORMATION CONTACT section for alternate instructions.

FOR FURTHER INFORMATION CONTACT:

For DHS: Steven A. Willoughby, Acting Executive Director, Program Executive Office for Drones and Counter-Unmanned Aircraft Systems, U.S. Department of Homeland Security, drones@dhs.gov.

For DOJ: Micheal J. Torphy, Assistant Section Chief, Unmanned Aviation Section, Critical Incident Response Group, Federal Bureau of Investigation, ncutc@fbi.gov.

SUPPLEMENTARY INFORMATION:

I. Public Participation

The Departments invite all interested parties to participate in this rulemaking by submitting written data, views, comments, and arguments on all aspects of this rule. The Departments also invite comments that relate to the economic, environmental, or federalism effects that might result from this rule. Comments must be submitted in English, or an English translation must be provided. Comments that will provide the most assistance to the Departments in implementing these changes will reference a specific portion of the rule, explain the reason for any recommended change, and include data, information, or authority that supports such recommended change. Comments submitted in a manner other than the one listed above, including emails or letters sent to Department officials, will not be considered comments on the rule and may not receive a response from the Departments.

Instructions: If you submit a comment, you must include the agency name (Federal Bureau of Investigation) and the FDMS Docket No. FBI-2026-0001 for this rulemaking. All submissions will be posted, without change, to the Federal eRulemaking Portal at https://www.regulations.gov, and will include any personal information you provide. Therefore, submitting this information makes it public. You may wish to consider limiting the amount of personal information that you provide in any voluntary public comment submission you make to the Departments. The Departments may withhold information provided in comments from public viewing that they determine may impact the privacy of an individual or is offensive. For additional information, please read the Privacy and Security Notice available at https://www.regulations.gov.

Docket: For access to the docket and to read background documents or comments received, go to https://www.regulations.gov, referencing FDMS Docket No. FBI-2026-0001. You may also sign up for email alerts on the online docket to be notified when comments are posted or a final rule is published.

II. Executive Summary

In 2018, Congress recognized the growing threat of drones (unmanned aircraft) and unmanned aircraft systems (“UAS”) to public safety and national security, including their use by extremists, terrorists, and criminals. See S. Rep. No. 115-332, at 2-3 (2018). Congress recognized that “[t]errorist organizations promote the use of UAS to conduct attacks in the U.S. and surveillance on potential targets.” Id. at 2. In one notable instance, “Al-Qaeda in the Arabian Peninsula used their Inspire magazine in May 2016 to encourage individuals to use UAS to collect information about potential assassination attempts and killings.” Id. And “[i]n September 2011, Rezwan Ferdaus, a U.S. citizen, was arrested for planning to attach explosives to a UAS and attack the Pentagon and U.S. Capitol.” Id. “Another potentially dangerous incident occurred in 2017 when a UAS flew over the San Francisco 49ers and Oakland Raiders National Football League stadiums dropping leaflets and causing panic.” Id.

Congress also recognized that Federal law hampered the ability of law enforcement to respond to these threats. Congress noted that Federal law enforcement agencies were “prohibited from taking actions against UAS due to decades-old statutes,” such as “the Wiretap Act of 1968 and the Computer Fraud and Abuse Act of 1986,” that “were enacted long before UAS were widely available.” Id. Such laws make “it illegal to intercept any wire, oral, or electronic communication, or to access a computer without authorization, respectively, making it imposing to use the electronic transmission to track down the operator of the drone.” Id. Congress also noted that “DHS and DOJ are prevented from taking action against a rogue UAS due to the FAA Modernization and Reform Act of 2012 that define[d] UAS as aircraft” and as a result subjected UAS to “aircraft piracy laws [that] ma[de] it illegal to seize or exercise control of an aircraft.” Id. (citing 49 U.S.C. 331).

In order to remedy this problem, as part of the FAA Reauthorization Act of 2018, Congress passed the Preventing Emerging Threats Act of 2018, which authorized the Secretary of Homeland Security and the Attorney General to designate certain facilities or assets as ( printed page 41467) “covered facilities or assets” and take certain measures necessary to mitigate a credible threat that an unmanned aircraft or UAS poses to the safety or security of a covered facility or asset, notwithstanding certain provisions of Federal criminal law, including prohibitions against aircraft piracy, destruction of an aircraft, computer fraud, interference with the operation of a satellite, the Wiretap Act, and the prohibition on pen register and trap and trace device use. Public Law 115-254, sec. 1602(a), 132 Stat. 3186, 3522-29 (codified at 6 U.S.C. 124n). Generally, the authorized protective measures included, and still include, detection, disruption, seizure, confiscation, and destruction of UAS using reasonable force (if necessary). 6 U.S.C. 124n(b)(1)(F). However, the Act did not authorize SLTT agencies to take such measures.

In testimony before the Senate Judiciary Committee in July 2025, DOJ recommended that all SLTT agencies be authorized to address the continuing threat of UAS (for example, smuggling contraband into prisons, or threatening public safety at sporting events or other outdoor gatherings), again notwithstanding these same Federal criminal laws. Dep't of Justice, Securing the Skies: Law Enforcement, Drones, and Public Safety: Hearing Before the S. Comm. on the Judiciary, 119th Cong. 8-9 (2025), https://www.judiciary.senate.gov/imo/media/doc/94f53245-d172-92ba-152b-06bc9ee00a50/2025-07-22%20-%20Testimony%20-%20Torphy%20&%20Hardee1.pdf [ https://perma.cc/F3J7-NWDG] (statement of Christopher Hardee, Chief, Office of Law & Policy, Nat'l Sec. Div., DOJ, and Micheal Torphy, Unit Chief, Critical Incident Response Grp., FBI). DOJ suggested that State and local law enforcement be authorized to use pre-approved, detection-only equipment, and that certain State and local law enforcement be trained to use all C-UAS capabilities (including mitigation measures such as exercising control of a UAS or destroying a UAS). Id.

In recognition of this continued challenge, Congress passed the SAFER SKIES Act, signed into law by the President on December 18, 2025. National Defense Authorization Act for Fiscal Year 2026, Public Law 119-60, div. H, tit. LXXXVI, §§ 8601-07, 139 Stat. 718, 1938-45 (2025) (“SAFER SKIES Act” or “the Act”) (codified in large part in 6 U.S.C. 124n). The SAFER SKIES Act authorizes SLTT agencies to take certain measures to detect and mitigate credible threats that unmanned aircraft and UAS pose to the safety or security of people, facilities, and assets, a venue or set of venues used for large-scale public gatherings or events, critical infrastructure, or correctional facilities,[1] notwithstanding the same provisions of Federal criminal law (prohibitions against aircraft piracy, destruction of an aircraft, computer fraud, interference with the operation of a satellite, the Wiretap Act, and the prohibition on pen register and trap and trace device use), and notwithstanding the laws of any particular State, local, Tribal, or territorial jurisdiction, but only under certain conditions. 6 U.S.C. 124n(a)(2).

Specifically, the SAFER SKIES Act authorizes SLTT agencies to take the mitigation measures identified in 6 U.S.C. 124n(b)(1)(C), (D), and (F) if they: (1) are trained and certified by the Attorney General, or the Attorney General's designee, through a national schoolhouse, 6 U.S.C. 124n(d)(2)(A)(i); (2) use technologies on authorized technologies and systems lists maintained jointly by DOJ, DHS, the Department of Defense,[2] the Department of Transportation, the Federal Communications Commission (“FCC”), and the National Telecommunications and Information Administration (“NTIA”), 6 U.S.C. 124n(d)(2)(A)(iii); (3) comply with specific compliance, coordination, and audit requirements, 6 U.S.C. 124n(d)(2)(B) (Oversight), (e) (Privacy protection); and (4) report mitigation actions to DOJ and DHS, 6 U.S.C. 124n(d)(2)(C). At the same time, the SAFER SKIES Act authorized SLTT agencies to take measures identified under 6 U.S.C. 124n(b)(1)(A), (B), and (E)—that is to detect, monitor, identify, track, and confiscate UAS, as well as warn the operator of a UAS, including by passive or active, direct or indirect physical, electronic, radio, or electromagnetic means, and through the use of a remote identification broadcast, or by other means—subject to satisfying training and certification procedures; but the training and certification procedures required to take these specific protective measures need not occur at a national schoolhouse. 6 U.S.C. 124n(a)(2) (allowing SLTT agencies to take measures in subsection (b)(1), but only subject to subsection (d)(2)); see also6 U.S.C. 124n(d)(2)(A)(ii) (providing that SLTT agencies must satisfy the training and certification procedures before taking any action in all of subsection (b)(1)).

Finally, the Act directs the Secretary of Homeland Security and the Attorney General, in coordination with the Secretary of Defense, the Secretary of Transportation, and the Administrator of the Federal Aviation Administration (“FAA”), to develop and publish regulations governing C-UAS authority—that is, the authority to conduct protective measures to detect, identify, monitor, track, and, if necessary, mitigate the threat of UAS—for SLTT agencies under section 124n. This IFR implements this statutory authority, to include compliance requirements and procedures for coordination.

III. Background and Purpose

A. Background and Legal Authority

As noted in Section II of this preamble above, the Preventing Emerging Threats Act of 2018 permits the Attorney General and the Secretary of Homeland Security to authorize certain personnel to take certain protective measures (generally, detection, disruption, seizure, confiscation, and disablement, damage, or destruction using reasonable force) necessary to mitigate a credible threat that an unmanned aircraft or UAS poses to the safety or security of a covered facility or asset, notwithstanding certain provisions of Federal criminal law. See6 U.S.C. 124n(b)(1). Specifically, the Attorney General and the Secretary of Homeland Security are authorized to take such measures notwithstanding Federal criminal prohibitions in 49 U.S.C. 46502 (aircraft piracy), 18 U.S.C. 32 (destruction of aircraft), 18 U.S.C. 1030 (computer fraud), and 18 U.S.C. 1367 (interference with the operation of a satellite), as well as chapters 119 (interception of communications) and 206 (pen registers and trap and trace devices) of Title 18. 6 U.S.C. 124n(a)(1). Generally, a “covered facility or asset” must be identified as high risk and a potential target for unlawful unmanned aircraft activity by the Secretary or the Attorney General, in coordination with the Secretary of Transportation with respect to potentially impacted airspace, through a risk-based assessment. 6 U.S.C. 124n(l)(3)(A).

The SAFER SKIES Act amended section 124n in several ways, notably by ( printed page 41468) authorizing SLTT agencies to take certain protective measures to mitigate a credible threat that unmanned aircraft and UAS pose to the safety or security of people, facilities, and assets, a venue or set of venues used for large-scale public gatherings or events, critical infrastructure, or correctional facilities, notwithstanding certain provisions of Federal criminal law, and notwithstanding the laws of any particular State, local, Tribal, or territorial (“SLTT”) jurisdiction, 6 U.S.C. 124n(a)(2), but subject to additional requirements.

Notwithstanding the foregoing statutory changes, the SAFER SKIES Act did not amend or waive the applicability of other Federal statutory provisions that may govern or proscribe SLTT agencies' otherwise authorized activity, including those in the Communications Act or other regulations governing access to spectrum. See, e.g.,47 U.S.C. 301 (licensing and authorization), 47 U.S.C. 302 (interfering devices), 47 U.S.C. 333 (jamming), 47 U.S.C. 605 (unauthorized transmissions). As a result, this regulation requires SLTT agencies to obtain approvals from the FCC before deploying any C-UAS system (whether detection only or mitigation) that involves the emission of radio waves.

1. Detecting, Identifying, Monitoring, Tracking, and Warning

First, the Act authorizes SLTT agencies to “detect, identify, monitor, and track” UAS or unmanned aircraft, without prior consent, including by means of interception of or other access to a wire communication, an oral communication, or an electronic communication used to control the UAS or unmanned aircraft. 6 U.S.C. 124n(b)(1)(A). The Act also authorizes SLTT agencies to warn the operator of a UAS, including by “passive or active, and direct or indirect physical, electronic, radio, electromagnetic means, and through the use of remote identification broadcast or other means.” 6 U.S.C. 124n(b)(1)(B). The Act also allows SLTT agencies to seize or otherwise confiscate a UAS or unmanned aircraft. 6 U.S.C. 124n(b)(1)(E). This rule covers confiscation under section 124n(b)(1)(E) through the Detection and Warning Certification process alongside the detection and warning activities in section 124n(b)(1)(A) and (B) because, like those activities, confiscation does not involve the use of a mitigation technology. The Act authorizes SLTT agencies to take measures under section 124n(b)(1)(A), (B), and (E) subject to the training and certification requirement described in section 124n(d)(2)(A)(ii), which applies to all actions in section 124n(b)(1), only if they:

(1) use “systems or technologies that are included on a list of authorized technologies maintained jointly by the Department of Justice, the Department of Homeland Security, the Department of Defense, the Department of Transportation, the Federal Communications Commission, and the National Telecommunications and Information Administration,” 6 U.S.C. 124n(d)(2)(A)(iii);

(2) comply with specific privacy protections identified in section 124n(e), which include compliance with the First and Fourth Amendments to the Constitution of the United States, data retention limitations, and limits on collecting certain data; and

(3) comply with Federal oversight, audits, coordination, and compliance requirements, including by the Secretary of Homeland Security and Attorney General, in coordination with the Secretary of Transportation and the Administrator of the FAA, over SLTT agencies' compliance with the privacy protections identified in section 124n(e) and the requirements outlined in this regulation consistent with sections 8602, 8605, and 8606 of the SAFER SKIES Act.

2. Disrupting, Disabling, Interfering, Seizing Control, or Using Reasonable Force Under the Totality of the Circumstances To Disable, Damage, or Destroy

Regarding the protective measures identified in section 124n(b)(1)(C), (D), and (F)—that is, mitigation measures generally involving disruption, seizure and control, and destruction using reasonable force—SLTT agencies are only authorized to use these protective measures under a more restrictive set of conditions. Specifically, in order to use the protective measures identified in section 124n(b)(1)(C), (D), and (F), SLTT agencies must:

(1) be trained and certified by the Attorney General, or the Attorney General's designee, in coordination with the Secretary of Homeland Security, through a national schoolhouse, 6 U.S.C. 124n(d)(2)(A)(i);

(2) use technologies that are included on a list of authorized technologies and systems maintained jointly by DOJ, DHS, the Department of Defense, the Department of Transportation, the FCC, and the NTIA, 6 U.S.C. 124n(d)(2)(A)(iii);

(3) comply with specific privacy protections identified in section 124n(e), which include compliance with the First and Fourth Amendments of the Constitution of the United States, data retention limitations, and limits on collecting certain data, and with Federal oversight, audits, coordination, and compliance requirements, including by the Secretary of Homeland Security and the Attorney General, in coordination with the Secretary of Transportation and the Administrator of the FAA, as concerning compliance with the privacy protections identified in section 124n(e), 6 U.S.C. 124n(d)(2)(B); and

(4) notify DHS and DOJ within 48 hours of any mitigation action taken, 6 U.S.C. 124n(d)(2)(C).

The Act also provides for suspension of C-UAS authority and civil fines for SLTT agencies, as well as their personnel, authorized to take C-UAS protective measures who knowingly engage in such action without Federal coordination as required by the Act. Public Law 119-60, sec. 8605(f), 139 Stat. at 1944 (codified at 6 U.S.C. 124n-1(f)) (“Penalties for Unauthorized Counter-UAS Actions”); id. sec. 8605(g) (codified at 6 U.S.C. 124n-1(g)) (“Civil Enforcement”).

The Act also requires the “Attorney General, in coordination with the Secretary of Homeland Security, the Secretary of Defense, and the Secretary of Transportation,” to develop training and certification procedures that SLTT law enforcement and correctional officers must satisfy before engaging in those protective measures requiring training and certification. 6 U.S.C. 124n(d)(2)(A)(ii) (training and certification procedures).

Finally, the Act directs the “Secretary of Homeland Security and the Attorney General, in coordination with the Secretary of Defense and Secretary of Transportation,” and the Administrator of the FAA to publish regulations governing C-UAS authority for SLTT agencies under section 124n. SeePublic Law 119-60, sec. 8606, 139 Stat. 1944-45. This IFR implements the statutory directive to promulgate regulations, to include additional compliance requirements and procedures based on such coordination.

B. Discussion of Interim Rule

This IFR identifies the requirements and procedures for SLTT agencies to become authorized to take C-UAS measures under section 124n. Specifically, for the full range of C-UAS protective measures identified under section 124n(b)(1)(A) and (B) (involving detecting, identifying, monitoring, and tracking UAS, and warning the operator), the mitigation measures under section 124n(b)(1)(C), (D), and (F), and (E) (involving seizure and confiscation of UAS or unmanned ( printed page 41469) aircraft), the IFR identifies how SLTT agencies must (1) use only systems or technologies that are included on a list of authorized technologies, and how to obtain the list; and (2) comply with specific privacy protections identified in section 124n(e) and how they must comply with Federal oversight, audits, coordination, and compliance requirements by the Secretary of Homeland Security and Attorney General as outlined in this rule, consistent with sections 8602, 8605, and 8606 of the SAFER SKIES Act.

Concerning C-UAS protective measures identified under section 124n(b)(1)(C), (D), and (F) (generally involving mitigation—that is, disrupting, disabling, interfering with, seizing control of, or using reasonable force, if necessary, to disable, damage or destroy a UAS), the IFR sets forth the requirements for the use of such measures. Specifically, the IFR explains how SLTT agencies: (1) receive training and certification through the Federal Bureau of Investigation's (“FBI”) national schoolhouse; (2) obtain the list of authorized technologies they may use; (3) comply with the specific privacy protections identified in section 124n(e); and (4) comply with Federal oversight, audits, and compliance requirements established by the Secretary of Homeland Security and the Attorney General, in coordination with the Administrator of the FAA, as outlined in this regulation and as provided in 6 U.S.C. 124n(d)(2)(B), with suspension of authority under sections 8605 and 8606(f) of the SAFER SKIES Act available to the Attorney General or the Secretary.

The rule is organized as follows in parts 124 of titles 6 and 28 of the Code of Federal Regulations: purpose and scope (§ 124.1); definitions (§ 124.2); scope of authority and mitigation standards (§ 124.3); authorized personnel, contractors, and mutual aid (§ 124.4); training and certification (§ 124.5); the agency implementation policy (§ 124.6); authorized technologies (§ 124.7); the C-UAS Operations Plan (§ 124.8); advance coordination, notification, and authorization (§ 124.9); interagency and lead-agency coordination (§ 124.10); real-time air traffic control notification (§ 124.11); detection and warning operations (§ 124.12); post-operation reporting (§ 124.13); privacy and civil liberties (§ 124.14); protection of sensitive operational information (§ 124.15); compliance and enforcement (§ 124.16); confiscation and forfeiture (§ 124.17); activities for evaluation, testing, training, and pre-operational validation (§ 124.18); task force arrangements and Federal support (§ 124.19); rules of construction (§ 124.20); termination (§ 124.21); and severability (§ 124.22).

This rule establishes the framework governing SLTT agency C-UAS operations under 6 U.S.C. 124n(a)(2). This rule provides requirements for training and certification of SLTT agency personnel, the agency implementation policy, the C-UAS Operations Plan, advance coordination, interagency and lead-agency coordination, notification and reporting requirements, and privacy and data handling protections. The Secretary of Transportation and the Administrator of the FAA have coordinated in the development of this rule as required by 6 U.S.C. 124n(d)(3), and the rule was developed in coordination with the Secretary of Defense as required by 6 U.S.C. 124n(d)(2)(A)(ii) and section 8606(a)(1) of the SAFER SKIES Act.

Consistent with the SAFER SKIES Act, the rule does not change the applicability of the Communications Act, see47 U.S.C. 301 et seq., or implementing rules administered by the FCC that relate to spectrum licensing, equipment authorization, and harmful interference to authorized services, among other things. SLTT agencies thus remain subject to applicable provisions that may govern or proscribe activities otherwise authorized by this rule.

The following discussion describes each provision of the regulatory text added by this rule to new parts 124 in both titles 6 and 28 of the Code of Federal Regulations. The two parts are identical.

Section 124.1—Purpose and scope. This section states the purpose and scope of the new part 124 and its relationship to other laws, including the statutory provisions displaced by the notwithstanding clause of 6 U.S.C. 124n(a)(2), provides that this part is the comprehensive framework for SLTT agency C-UAS operations, and identifies for SLTT agencies that conduct only detection and warning operations the provisions of the part principally applicable to them. As used in this rule, the term “notwithstanding clause of 6 U.S.C. 124n(a)(2)” means the provision that permits a certified agency to take the actions described in 6 U.S.C. 124n(b)(1) without violating the Federal criminal laws the clause displaces—49 U.S.C. 46502 (aircraft piracy), 18 U.S.C. 32 (destruction of aircraft), 18 U.S.C. 1030 (computer fraud), 18 U.S.C. 1367 (interference with the operation of a satellite), and chapters 119 (interception of communications) and 206 (pen registers and trap and trace devices) of title 18—as well as “the laws of any particular State, local, Tribal, or territorial jurisdiction.” In plain terms, protective measures described in 124n, such as intercepting the radio link that controls a drone or taking control of a drone away from its operator, are lawful—notwithstanding the laws mentioned above—when a certified SLTT agency performs them in compliance with the Act and the regulations this IFR adopts.

For an agency that conducts only detection and warning operations, the provisions principally applicable are those identified in § 124.1(b): the Detection and Warning Certification requirement of § 124.5(c), the detection and warning policy provisions of § 124.6(g), the authorized technology requirements of § 124.7, the C-UAS Operations Plan requirement of § 124.8, the operational conditions of § 124.12, and the privacy and data handling requirements of § 124.14. The authority to regulate detection and monitoring activity conducted in reliance on the Act rests on the statute itself: the opening text of 6 U.S.C. 124n(a)(2) conditions any action on completion of the training detailed in subsection (d)(2); 6 U.S.C. 124n(d)(2)(A)(ii) requires training and certification before personnel take any action described in subsection (b)(1), including detection; 6 U.S.C. 124n(d)(2)(A)(iii) limits the technologies used for any such action to listed technologies; 6 U.S.C. 124n(e) imposes privacy requirements; and section 8606(a)(1) of the SAFER SKIES Act directs publication of regulations governing the authority.

This section also clarifies that the Departments maintain parallel regulations for ease of use, and that each Department administers and interprets its own regulations with respect to its programs and authorities.

Section 124.2—Definitions. This section defines the terms used in the part, including the two-list technology framework (the Authorized Technologies List and the Authorized Systems List), the two certification tiers (Detection and Warning Certification and Mitigation Certification), the data categories the part regulates (control communications, raw sensor data, and pattern data), the credible threat standard, the Agency Approving Official, and the designated Federal C-UAS coordination portal.

Two definitions reflect policy choices that warrant explanation. First, the Agency Approving Official must hold a rank not below a Senior Executive or Senior Official, or its equivalent. The Departments set the threshold at this level because approving a mitigation operation, which may involve the use of force against an aircraft, is a command ( printed page 41470) decision that in most agencies rests above the line-supervisor level. The same senior official also approves the agency's detection and warning operations, so that authorization of all C-UAS operations under this part rests with one accountable command official. The reference is to the agency's senior command or executive ranks, not to any particular title, and where no equivalent rank exists the agency head or the agency head's designee may serve. Second, the credible threat standard governs agency action on a credible threat to the protected interests the statute enumerates, but the statute does not define the term. The rule's definition adapts the objective, totality-of-the-circumstances standard applied in Federal C-UAS operations under 6 U.S.C. 124n(a)(1) since 2018, reflected in the Attorney General's April 2020 Guidance [3] and the DOJ objective standards for C-UAS operations,[4] and is framed on the reasonable-officer model familiar from use-of-force doctrine, with enumerated indicators drawn from Federal operational experience.

Section 124.3—Scope of authority and mitigation standards. This section states the scope of authority, the credible threat determination, proportionality in the reasonableness of the use of force, the protective purpose limitation, the mitigation operator execution requirement, the independent professional judgment of the certified operator under the totality of the circumstances, and the airspace awareness function.

The credible threat determination requirement implements the statutory condition of 6 U.S.C. 124n(a)(2) and requires that the determination be made and documented before mitigation. The proportionality standard requires that a mitigation action taken be reasonable in relation to the threat presented; it reflects the statute's authorization of actions that are necessary to mitigate the threat and the reasonable force limitation of 6 U.S.C. 124n(b)(1)(F). The protective purpose limitation confines the exercise of the authority to protective ends and forecloses use of the authority as a general investigative tool, consistent with the structure of 6 U.S.C. 124n(e). The mitigation operator execution requirement provides that only personnel holding Mitigation Certification may execute mitigation actions, implementing 6 U.S.C. 124n(d)(2)(A)(i). The independent professional judgment provision preserves the certified operator's discretion to decline an action the operator assesses to be unsafe, a safeguard the Departments adopted from Federal C-UAS practice because the operator of the system has the best real-time awareness of airspace and spectrum conditions. The airspace awareness function requires the operating agency to maintain awareness of manned aircraft in the vicinity of an operation, implementing the aviation safety coordination obligations of 6 U.S.C. 124n(b)(4) and (d)(3).

Section 124.4—Authorized personnel, contractors, and mutual aid. This section limits the exercise of authority to officers and employees of the SLTT agency, prohibits contractor operation of systems requiring the authority of the Act, establishes the conditions for mutual aid, and contains an anti-circumvention provision.

The limitation of operational authority to officers and employees implements the Act rather than a discretionary policy choice. Congress defined the personnel who may exercise SLTT agency authority as the officers and employees of the SLTT agency, 6 U.S.C. 124n(l)(6)(B), in contrast to the broader personnel definition applicable to Federal operations under 6 U.S.C. 124n(l)(6)(A), which extends to certain contractors, detailed personnel, and deputized personnel. The prohibition on contractor operation of mitigation systems, including arrangements described as turnkey or managed C-UAS services, follows from that statutory structure. The rule preserves substantial roles for the private sector: contractors and vendors may design, manufacture, sell, install, and maintain C-UAS systems; provide technical support and system-level operator training; receive operational data for diagnostics under the conditions of § 124.14(j); and provide detection services using systems that do not require the authority of the Act or the relief it provides from certain laws.

Section 124.4 also permits accredited SLTT agencies to provide C-UAS support to non-accredited SLTT agencies through mutual aid or other written arrangement. This approach reflects the Departments' judgment that public safety is better served by strong regional, county, statewide, and multi-jurisdictional C-UAS programs than by requiring every small or resource-limited agency to establish a separate, rarely used capability. The rule therefore allows a non-accredited agency to request and receive C-UAS support, while ensuring that the accredited agency remains the C-UAS operating agency and that all actions requiring 6 U.S.C. 124n authority are performed by properly certified personnel under the requirements of this part. The Departments invite comment on these provisions, including the conditions governing mutual aid.

Section 124.5—Training and certification. This section establishes the training and certification structure required by 6 U.S.C. 124n(d)(2)(A). It implements the statute's two distinct requirements. The national-schoolhouse sole-certifying-authority requirement of 6 U.S.C. 124n(d)(2)(A)(i) applies to mitigation under 6 U.S.C. 124n(b)(1)(C), (D), and (F), and the FBI's National Counter-UAS Training Center (“NCUTC”) is designated as that schoolhouse. The Act separately requires training and certification before personnel take any of the actions it authorizes, including detection. The opening text of 6 U.S.C. 124n(a)(2) permits an agency to act only after completing the training detailed in subsection (d)(2), and 6 U.S.C. 124n(d)(2)(A)(ii) requires the Attorney General to develop training and certification procedures that officers must satisfy before taking any action described in subsection (b)(1). Detection and warning under 6 U.S.C. 124n(b)(1)(A), (B), and (E) are among the actions described in subsection (b)(1), so the training and certification requirement reaches them as well as mitigation. The Departments have accordingly provided for a Detection and Warning Certification requirement for detection and warning operations conducted with systems that require the authority of the Act or the relief it provides from certain laws, but the requirement that training and certification take place “through a national schoolhouse” in clause (i) does not extend to those actions. Thus, the NCUTC delivers the detection and warning curriculum through an online portal that issues the certification automatically on completion, rather than at an in-person resident instruction at the national schoolhouse. Detection activities conducted with systems that do not require the authority of the Act or the relief it provides from certain laws are outside this requirement. Examples of such activities include electro-optical and infrared cameras, acoustic sensors, and radar operated under FCC authorization. Operating those systems does not implicate the prohibitions the Act displaces, because they intercept no communications, so the Act's training requirement does not attach. ( printed page 41471)

Online delivery for the detection tier does not create the public safety risks that warrant resident instruction for mitigation. Detection and warning do not involve disrupting, taking control of, or otherwise affecting an aircraft in flight. Although some detection systems (such as radar) transmit radio frequency energy to sense an aircraft, such systems cannot interfere with an aircraft's operation, and the associated risks are legal and privacy compliance risks, which are knowledge-based and are effectively taught and tested through structured online instruction with a required detection assessment. Resident instruction for the detection tier would impose travel and backfill costs on thousands of agencies without a corresponding safety benefit and would consume schoolhouse capacity needed for mitigation training.

This section also establishes the correctional-specific curriculum and the decertification, suspension, administrative-review, and reinstatement process. Two choices in this section warrant further explanation.

First, training and certification for mitigation occur through a national schoolhouse because Congress required it: 6 U.S.C. 124n(d)(2)(A)(i) conditions the exercise of the mitigation authorities—that is, authorities at 6 U.S.C. 124n(b)(1)(C), (D), and (F)—on certification through a national schoolhouse serving as the sole certifying authority. See6 U.S.C. 124n(d)(2)(A)(i).

Second, the section provides for suspension of certifications and agency accreditations. Suspension is the measure section 8605(f)(2) of the SAFER SKIES Act provides, and the suspension and administrative review process is described in the discussion of the administrative review provisions below. Because the rule provides for suspension of certifications and agency accreditations, the Departments describe the process and its basis here. A suspension decision is communicated in writing and specifies the basis for the action and any available remedial steps. In exigent circumstances that pose a risk to aviation safety, public safety, or national security, the Director or the Director's designee may immediately suspend a certification or accreditation pending administrative review. An individual or agency that receives a suspension notice may request administrative review within 30 calendar days. The Attorney General, acting through the Director, designates a reviewing official from DOJ who did not participate in or supervise the initial decision; that official considers the written submissions of both parties, may hold an informal hearing, and issues a written determination within 60 calendar days stating the factual findings and the basis for the determination. The reviewing official may affirm, modify, condition, or reverse the action, and the determination is final agency action for purposes of this part. The rule contains no separate revocation action. A suspension that is affirmed and not cured remains in effect until reinstatement, and reinstatement of a Mitigation Certification requires completion of the full course. This process affords affected individuals and agencies notice and an opportunity to respond before a neutral reviewing official, while preserving the ability to act immediately when continued exercise of C-UAS authority would pose a safety or security risk.

The Departments are considering whether certifications should expire after a given period of time—such as 36 or 48 months—conditioned upon additional training requirements to ensure continuing proficiency and welcome comment on whether certifications should expire, the length of their validity period, and the requirements for renewal.

Section 124.6—Agency implementation policy. This section establishes the agency implementation policy, the legal counsel review, the portal attestation, and the detection and warning policy for SLTT agencies conducting only detection and warning operations. An agency's implementation policy is not subject to pre-approval by the NCUTC; the agency self-certifies through a portal attestation, and the NCUTC retains audit and suspension authority. The implementation policy is the agency-level governing document for the agency's C-UAS program; it must address command responsibility, integration with the agency's use-of-force policy, operator rostering and certification verification, equipment control and maintenance, the privacy procedures required by § 124.14, and recordkeeping. The legal counsel review requires the agency's counsel to review the policy for compliance with this part and with applicable SLTT law before adoption. The portal attestation is the agency's certification, submitted through the Federal C-UAS coordination portal, that the policy has been adopted and reviewed. The detection and warning policy is an abbreviated policy, based on a model the Departments will publish, for agencies that conduct only detection and warning operations. The Departments chose self-certification with audit, rather than Federal pre-approval of each agency policy, for two reasons. Pre-approval of policies from the thousands of agencies expected to participate would create a Federal bottleneck, which would be inconsistent with the independent authority Congress conferred on certified SLTT agencies, and would add months of delay without a corresponding compliance benefit. Audit with suspension exposure, by contrast, preserves accountability: an agency that attests falsely or maintains a deficient policy is subject to the compliance audit program of § 124.16 and to suspension under § 124.5.

The rule neither directly requires an SLTT agency to notify its State government of the agency's adoption of C-UAS capability or of individual operations, nor prohibits such notification, and nothing in the rule conditions the exercise of authority under 6 U.S.C. 124n(a)(2) on State-level notification, endorsement, or approval; Congress conferred that authority directly on SLTT agencies. The Departments recognize, however, that Governors, State homeland security advisors, and State law enforcement agencies have a legitimate interest in awareness of C-UAS capability within their States, including for purposes of intrastate and interstate deconfliction, mutual aid planning, and security planning for major events, and that the visibility provided through existing channels, such as the State Administrative Agency structure of DHS's C-UAS grant program, does not extend to agencies that participate without grant support through that program. The Departments have therefore included one reference to State notification requirements under § 124.9(b), if otherwise required by State law or policy, and invite comment on whether the rule should provide an additional State-level awareness mechanism and, if so, on its appropriate form, including whether the Federal Government should make available to a State-designated point of contact the roster of attested and accredited agencies within the State, or whether the agency implementation policy should address notification to a State-designated point of contact upon adoption of C-UAS capability, and on how any such mechanism should be structured so that notification does not operate as a condition on, or approval requirement for, the exercise of statutory authority.

Published in the Federal Register. A work of the US federal government, in the public domain.

Read it at Federal Register
Every entry here is reproduced from the body that issued it, under the licence named above it, and links to the original. Whether an obligation applies to your organisation is a question for your counsel, not for a tracker.