# 32 CFR § 2004.28: Cost reports

> Federal · Regulations · In force

URL: https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.28

## Section

- **Citation:** 32 CFR § 2004.28
- **Heading:** Cost reports
- **Jurisdiction:** Federal
- **Kind:** Regulations
- **Status:** In force
- **Text as of:** September 22, 2026
- **Source:** Publisher's official text
- **Location:** Title 32—National Defense > Subtitle B—Other Regulations Relating to National Defense > CHAPTER XX—INFORMATION SECURITY OVERSIGHT OFFICE, NATIONAL ARCHIVES AND RECORDS ADMINISTRATION > PART 2004—NATIONAL INDUSTRIAL SECURITY PROGRAM (NISP) > Subpart B—Administration

## Text

(a) Agencies must annually report to the Director, ISOO, on their NISP implementation costs for the previous year.
(b) CSAs must annually collect information on NISP implementation costs incurred by entities under their cognizance and submit a report to the Director, ISOO.

## Nearby sections

- [32 CFR § 2004.1 § 2004.1 Purpose and scope.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.1.md)
- [32 CFR § 2004.4 § 2004.4 Definitions that apply to this part.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.4.md)
- [32 CFR § 2004.10 § 2004.10 Responsibilities of the Director, Information Security Oversight Office (ISOO).](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.10.md)
- [32 CFR § 2004.11 § 2004.11 CSA and agency implementing regulations, internal rules, or guidelines.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.11.md)
- [32 CFR § 2004.12 § 2004.12 ISOO review of agency NISP implementation.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.12.md)
- [32 CFR § 2004.20 § 2004.20 National Industrial Security Program Executive Agent and Operating Manual.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.20.md)
- [32 CFR § 2004.22 § 2004.22 Agency responsibilities.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.22.md)
- [32 CFR § 2004.24 § 2004.24 Insider threat program.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.24.md)
- [32 CFR § 2004.26 § 2004.26 Reviews of entity NISP implementation.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.26.md)
- [32 CFR § 2004.28 § 2004.28 Cost reports.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.28.md)
- [32 CFR § 2004.30 § 2004.30 Security classification requirements and guidance.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.30.md)
- [32 CFR § 2004.32 § 2004.32 Determining entity eligibility for access to classified information.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.32.md)
- [32 CFR § 2004.34 § 2004.34 Foreign ownership, control, or influence (FOCI).](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.34.md)
- [32 CFR § 2004.36 § 2004.36 Determining entity employee eligibility for access to classified information.](https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.36.md)

---

Source: Frix Law Library, https://www.frixlaw.com/law-library/statutes/ecfr-32-2004.28. Check the current official text before relying on it. Not legal advice.
