Skip to main content
Notice2026-10886

Agency Information Collection Activities: .gov Registrar

Primary source

Metadata and text below are from the Federal Register, a public-domain U.S. government work. Always verify the official published version before relying on it for any legal matter.

Published
June 1, 2026

Issuing agencies

Homeland Security Department

Abstract

The .gov Registry Program within Cybersecurity and Infrastructure Security Agency (CISA) submits the following Information Collection Request (ICR) to the Office of Management and Budget (OMB) for review and clearance.

Full Text

<html>
<head>
<title>Federal Register, Volume 91 Issue 104 (Monday, June 1, 2026)</title>
</head>
<body><pre>
[Federal Register Volume 91, Number 104 (Monday, June 1, 2026)]
[Notices]
[Pages 32412-32413]
From the Federal Register Online via the Government Publishing Office [<a href="http://www.gpo.gov">www.gpo.gov</a>]
[FR Doc No: 2026-10886]


-----------------------------------------------------------------------

DEPARTMENT OF HOMELAND SECURITY

[Docket No. CISA-2026-0001]


Agency Information Collection Activities: .gov Registrar

AGENCY: Cybersecurity and Infrastructure Security Agency (CISA), 
Department of Homeland Security (DHS)

ACTION: 60-Day notice and request for comments; extension of an 
existing collection (1670-0049) that was last approved on 10/03/2023 
with an expiration date of 10/31/2026.

-----------------------------------------------------------------------

[[Page 32413]]

SUMMARY: The .gov Registry Program within Cybersecurity and 
Infrastructure Security Agency (CISA) submits the following Information 
Collection Request (ICR) to the Office of Management and Budget (OMB) 
for review and clearance.

DATES: Comments are encouraged and will be accepted until July 31, 
2026.

ADDRESSES: You may submit comments, identified by docket number Docket 
# CISA-2026-0001, by following the instructions below for submitting 
comment via the Federal eRulemaking Portal at <a href="https://www.regulations.gov">https://www.regulations.gov</a>.
    Instructions: All submissions received must include the agency name 
and docket number Docket # CISA-2026-0001. All comments received will 
be posted without change to <a href="http://www.regulations.gov">http://www.regulations.gov</a>, including any 
personal information provided. Docket: For access to the docket to read 
background documents or comments received, go to <a href="https://www.regulations.gov">https://www.regulations.gov</a>.

FOR FURTHER INFORMATION CONTACT: Cameron Dixon, 888-282-0870, 
<a href="/cdn-cgi/l/email-protection#5139343d21113634257f363e27"><span class="__cf_email__" data-cfemail="d7bfb2bba797b0b2a3f9b0b8a1">[email&#160;protected]</span></a>.

SUPPLEMENTARY INFORMATION: .gov is a `top-level domain' (TLD), similar 
to .com, .org, or .us. Enterprises use a TLD to register a ``domain 
name'' (often simply called a domain) for use in their online services, 
like a website or email. Well-known .gov domains include 
<a href="http://whitehouse.gov">whitehouse.gov</a>, <a href="http://congress.gov">congress.gov</a>, or <a href="http://uscourts.gov">uscourts.gov</a>, but most .gov domains 
are from non-federal governments like <a href="http://ny.gov">ny.gov</a> (State of New York) or 
<a href="http://lacounty.gov">lacounty.gov</a> (LA County).
    .gov is available only to bona fide U.S.-based government 
organizations and publicly controlled entities. When governments use 
.gov, they make it harder for would-be impostors to successfully 
impersonate them online.
    Under the DOTGOV Act of 2020 (6 U.S.C. 665), CISA is responsible 
for the operation and security of the .gov TLD. Pursuant to that law, 
the .gov program at CISA works to ``provide simple and secure 
registration of .gov internet domains'', ``ensure that domains are 
registered and maintained only by authorized individuals'', and 
``minimize the risk of .gov internet domains whose names could mislead 
or confuse users''. In order to provision .gov domains to eligible 
government entities and ensure adherence to the domain requirements 
published by CISA pursuant to 6 U.S.C. 665(c), CISA needs to collect 
information from requestors of .gov domains.
    The information will be collected on an online web portal called 
the ``.gov registrar'', which is built and maintained by CISA. 
Requestors will be asked to provide information on the characteristics 
of their government entity (e.g., name, type, physical location, 
current domain), their preferred .gov domain name (e.g., <a href="http://example.gov">example.gov</a>), 
their rationale for the name, organizational contact information 
(names, phone numbers, email addresses), and nameserver addresses.
    Only U.S.-based government organizations are eligible for .gov 
domains; some of these organizations may be small entities. The 
collection has been developed to request only the information needed to 
confirm eligibility and adjudicate a .gov domain request.
    Without this collection, CISA will be unable to assess the 
eligibility of requestors nor provision .gov domains to government 
organizations. That outcome would decrease cybersecurity for 
governments across the nation and minimize the public's ability to 
identify governments online.
    In accordance with 6 U.S.C. 665(c)(4), CISA will ``limit the 
sharing or use of any information'' obtained through this collection 
``with any other Department component or any other agency for any 
purpose other than the administration of the .gov internet domain, the 
services described in subsection (e), and the requirements for 
establishing a .gov inventory described in subsection (h).'' Certain 
metadata for any approved domains (domain name, organization name, 
nameserver address, city/state information, security contact) will be 
published online.
    This is an extension of an existing collection. Only small, 
stylistic changes, not substantive updates, have been made since the 
previous ICR was approved by OMB.
    The Office of Management and Budget is particularly interested in 
comments which:
    1. Evaluate whether the proposed collection of information is 
necessary for the proper performance of the functions of the agency, 
including whether the information will have practical utility;
    2. Evaluate the accuracy of the agency's estimate of the burden of 
the proposed collection of information, including the validity of the 
methodology and assumptions used;
    3. Enhance the quality, utility, and clarity of the information to 
be collected; and
    4. Minimize the burden of the collection of information on those 
who are to respond, including through the use of appropriate automated, 
electronic, mechanical, or other technological collection techniques or 
other forms of information technology, e.g., permitting electronic 
submissions of responses.

Analysis

    Agency: Cybersecurity and Infrastructure Security Agency (CISA), 
Department of Homeland Security (DHS)
    Title: .gov registrar.
    OMB Number: 1670-0049.
    Frequency: Once per domain registered.
    Affected Public: Employees representing state, local, territorial, 
and tribal governments.
    Number of Respondents: 3,000 per year.
    Estimated Time per Respondent: 20 minutes.
    Total Burden Hours: 1,000 hours.
    Total Annual Burden Cost: $52,622.
    Total Annual Government Burden Cost: $588,600.

Winfield P Werntz,
Acting Chief Information Officer, Cybersecurity and Infrastructure 
Security Agency, Department of Homeland Security.
[FR Doc. 2026-10886 Filed 5-29-26; 8:45 am]
BILLING CODE 9111-LF-P


</pre><script data-cfasync="false" src="/cdn-cgi/scripts/5c5dd728/cloudflare-static/email-decode.min.js"></script></body>
</html>
Indexed from Federal Register on June 1, 2026.

This is legal information, not legal advice. Laws vary by jurisdiction and change frequently. Always verify current law with official sources and consult a licensed attorney in your jurisdiction for advice on your specific situation.