A Line on a Map Is Not an Airspace Security System: Critical Infrastructure Needs Detection, Not Just Designation

Regulation will soon allow critical infrastructure owners to protect their airspace, but true airspace awareness requires radar to fill gaps by actively illuminating airspace. Photo Credit: Echodyne

Nearly ten years after Congress told the Federal Aviation Administration (FAA) to build a process for restricting drones near sensitive facilities, and in the face of a mounting record of drone incursions over power substations, water treatment plants and defense sites, that process finally has a proposed shape. On May 6, 2026, the FAA published a Notice of Proposed Rulemaking to implement Section 2209 of the FAA Extension, Safety, and Security Act of 2016, creating a new regulatory pathway, 14 C.F.R. Part 74. Through it, owners and operators of fixed-site critical infrastructure may be able to petition for an Unmanned Aircraft Flight Restriction, or UAFR. Even though Congress originally set a January 2017 deadline for this rule and it arrived nine years later, it still marks a big milestone for airspace security. 

But the proposed rule contains a catch that deserves far more attention than it has received. Any 2209 restriction, “would not be a physical or electronic barrier.” A UAFR simply defines airspace. It does not defend it in any respect. That distinction provides an important impetus for critical infrastructure operators to think about Section 2209 as the beginning of a security conversation, not the end of one.

What The Proposed Rule Actually Creates

EchoShield deployed at a World Cup location.

Under the NPRM, a facility must first clear a threshold test to even apply. It has to be a fixed site, not mobile or temporary and it must fall within one of 16 critical infrastructure sectors defined in federal law: chemical, commercial facilities, communications, critical manufacturing, dams, defense industrial base, emergency services, energy, financial services, food and agriculture, government facilities, healthcare and public health, information technology, nuclear reactors and materials, transportation systems, and water and wastewater. 

Applicants must also reveal their existing protective security measures, identify critical assets vulnerable to drone-enabled threats and demonstrate that damage or disruption to the site would carry regional or national-level consequences.

If approved, a Standard UAFR limits drone activity to operators meeting defined safety and security standards. A Special UAFR is more restrictive by default, closing the airspace to everyone except those the FAA and the site operator explicitly clear. Restrictions can run full time or part time, up to 290 consecutive days a year. Once granted, a UAFR lasts five years before it must be renewed. Aircraft operating inside a Standard UAFR must broadcast Remote ID, with limited exceptions, and transit through as quickly as practicable.

That last requirement points to the enforcement model built into the rule. If a drone flies into a restricted area, the site operator is expected to contact law enforcement. Remote ID, the rule notes, “helps the FAA, law enforcement, and other federal agencies locate the control station when a drone appears to be flying unsafely or where it is not allowed to fly.” Pilots who violate a UAFR face license suspension, revocation, fines and potentially criminal charges. (See prior AG coverage of Section 2209).

Every part of that chain depends on one capability the rule presupposes: knowing that a drone is there in the first place.

The Gap Between A Boundary And A Defense

Airspace restrictions have existed for years around airports, stadiums and national security sites. The compliance record in those locations is instructive. Cooperative operators, the ones flying Part 107 missions or built-in geofenced consumer drones, generally respect them. Bad actors, by definition, do not. And they generally use drones for reconnaissance, payload delivery or disruption against a facility whose failure would ripple across a region or the country. The lesson learned here is that a restriction enforced only through voluntary compliance and after-the-fact prosecution offers little protection. Yet this is the exact solution that the Section 2209 NPRM proposes. 

Remote ID amplifies this gap rather than closing it. It is a cooperative identity layer. A compliant aircraft broadcasts its location and the location of its control station or takeoff point. That broadcast provides genuine value when it exists by giving law enforcement structured, auditable data to act on. But Remote ID only works when a drone chooses to transmit it correctly. A modified aircraft, a hobbyist who disables the module or an adversary who never intended to comply produces nothing for a Remote ID receiver to catch. The FAA’s enforcement model, as written, assumes an aircraft that wants to be found. The aircraft most worth worrying about is the one whose operator does not.

This is precisely why the counter-UAS conversation has, over the past two years, moved toward layered detection architectures that do not rely on a drone’s cooperation at all. The FBI’s SAFER SKIES Interim Final Rule, released this summer by DOJ and DHS and took effect on July 1, 2026, gives state, local, tribal, and territorial (SLTT) public safety agencies a certified pathway to detect, track, and in some cases mitigate drone threats. Its Detection and Warning tier requires agencies to complete FBI National Counter-UAS Training Center online certification and adopt equipment from an Authorized Technologies List that currently only includes radio frequency detection, RF protocol manipulation and RF disruption. (See prior AG coverage of the SAFER Skies IFR).

SAFER SKIES and Section 2209 are solving different halves of the same problem: one authorizes who can act and with what tools, the other draws the boundary those tools are meant to protect. Neither, on its own, tells a security team what just entered its airspace.

Detection Must Be Persistent And Sensor-Diverse

EchoGuard on a tethered drone.

RF detection listens for a drone’s control link or video downlink, which makes it powerful against cooperative and even many non-cooperative signal-emitting aircraft, but has a blind spot for autonomous or pre-programmed drones that fly without active radio transmission and produce nothing to intercept. 

Optical and acoustic sensors add valuable confirmation and evidence, but they are typically line-of-sight and degrade in darkness, weather or cluttered urban terrain. All of these conditions remain common conditions around substations, water plants, and industrial sites, often with obstructions and RF noise nearby.

Radar closes the gap. It illuminates airspace actively rather than waiting for a drone to announce itself. That means it detects a target regardless of whether that target is broadcasting Remote ID, transmitting RF or flying a route intended to avoid both. 

Echodyne builds compact, software-defined electronically scanned array (ESA) radar using patented metamaterials ESA, or MESA, technology. The company packages this tech into two key systems:

  • EchoShield for large volumetric coverage, fixed or mobile, the ability to handle thousands of aircraft from a single tower, the data precision necessary for secondary sensors and authorized effectors, and the ability to network multiple radars into cohesive virtual instances.
  • EchoGuard for tight spaces and coverage gaps and the ability to integrate into larger MESA radar meshed networks.

This type of continuity provides real operational value. Radar tracks do not depend on a drone’s willingness to cooperate, and they do not blink out when clouds roll in or the sun goes down. That persistence of precision airspace awareness turns a legal boundary into actionable information. It provides a continuous, threat-classified track ID that distinguishes a drone from a bird, a vehicle or clutter. It hands a security operator the kind of specific, time-stamped, high resolution 3D information law enforcement needs to respond to a UAFR violation instead of a vague report that “something was seen.”

Building The Layered Stack A UAFR Requires

None of this is to suggest that Section 2209, as proposed, is hollow. A properly designated UAFR gives a facility a defined legal perimeter, backed by federal enforcement authority and criminal penalties, that did not exist under the patchwork of ad hoc, inconsistently granted restrictions operators previously had to negotiate through a government sponsor. This is real progress. The rule’s alignment with Executive Order 14305 signals that Washington now treats airspace security around critical infrastructure as a priority for homeland security, rather than an afterthought.

EchoShield deployed atop a DHS Mobile Command Center.

The lesson for infrastructure operators preparing for the final rule is that eligibility and enforcement are two different projects. Qualifying for a UAFR under the criteria in 42 U.S.C. 5195c(e) will involve a compliance and documentation exercise. Making that restriction operationally meaningful then becomes a system, sensor, and staffing exercise. That effort should combine Remote ID, RF detection for cooperative and signal-emitting traffic, optical sensors for visual confirmation, acoustic tools for remote areas, and persistent radar coverage for the non-cooperative and RF-silent drones that are more representative of true threats. 

Every sensor, though, relies on the command and control (C2) software layer to optimize system performance and refine the data to prompt appropriate decisions and actions. The right  (C2) integrates these sensors into a cohesive system, the primary objective for any deployment. We recommend working with the counter-UAS system provider to investigate sensor performance as well as overall C2 and system performance.

Finally, video management systems (VMS) are tricky. The current 2D VMS systems are generally too slow to handle drones. Ideally, adding a separate counter-UAS system that uses VMS as  an event recorder (primary security system), would be advisable.

Layering these modalities, rather than picking one, lets a security team say with confidence what entered a restricted volume of airspace, whether it belonged there, and what to tell law enforcement when it did not.

The FAA has drawn a line on a map, nearly a decade after Congress asked it to. That line carries legal weight it never had before. Asset owners across all 16 critical infrastructure sectors should treat this rulemaking as a serious opportunity to formalize their protections. But a line in the sky is just that and only as useful as what a defender can see around it. As detection technology matures alongside SAFER SKIES-authorized response capabilities, the operators who pair regulatory designation with continuous, layered airspace awareness will be the ones who will actually be able to truly hold the line around the facilities they need to protect.