Section 2209 of the FAA Extension, Safety, and Security Act directed the FAA to create a process for designating fixed-site facilities that need protection from drone threats. In May 2026 the FAA issued a Notice of Proposed Rulemaking for a UAS Facility Restriction (UAFR) framework (proposed Part 74). The proposal is about security at fixed sites—critical infrastructure, certain correctional and other sensitive facilities—not about giving every landowner a kill switch.
This page is general information, not legal advice. Read the NPRM and talk to counsel before you file anything.
What changed in 2026
The NPRM frames a path for eligible fixed-site applicants to seek a UAFR: a designation that can restrict or condition UAS operations near a protected facility. Comment periods and effective dates move; treat Federal Register text as authoritative.
For security and procurement teams, the practical takeaway is simpler than the legal text: you will be expected to understand what is broadcasting in your airspace, and to receive and log Remote ID as part of a protective posture—not as a substitute for law-enforcement response.
Receive-and-log is not "detection theater"
Under Part 89, most drones in the National Airspace System must broadcast Remote ID (or use a network alternative where allowed). A Remote ID receiver collects those broadcasts so a facility can:
- See compliant aircraft near the site
- Record time, identity, and (when included) operator location
- Preserve logs for investigations, after-action reviews, and applications that ask what you already observe
That is different from radar-only awareness, and different from mitigation (jamming, spoofing, kinetic, takeover). A UAFR process does not by itself authorize you to jam or disable a drone. Separate authorities (including, for some SLTT agencies, SAFER SKIES certification) govern mitigation.
What a UAFR does not authorize
- It does not turn a private security vendor into a law-enforcement agency.
- It does not automatically approve jamming, takeover, or kinetic defeat.
- It does not replace coordination with FAA, FBI, or local law enforcement when a real threat appears.
If your site needs restricted C-UAS effects, plan that as a separate legal and procurement track. Start with knowing what is already overhead.
How Zing maps to the requirement
Zing builds the identification layer:
- Z-SCAN — fixed or site-scale Remote ID detection and airspace awareness for facilities that need continuous coverage.
- Z-SCAN MINI — portable / deployable Remote ID receiving for trials, events, distributed perimeters, and teams that need to prove the use case in 30 days.
- Zing Airspace Platform — maps, alerts, and org-level device management so receive-and-log is operational, not a USB stick of mystery files.
Zing does not jam or take control of aircraft. That is intentional: it keeps the first step lawful under ordinary receive authorities while you evaluate UAFR paperwork, SAFER SKIES certification, or other C-UAS paths.
Who should care
- Critical infrastructure operators preparing fixed-site security packages
- Correctional and other sensitive facilities evaluating perimeter drone risk
- Public-safety partners supporting a facility's airspace baseline
- Teams writing sole-source or grant justifications that need a documented detection layer
Practical next step
If you are "facilities seeking a Section 2209 UAFR," start by measuring real Remote ID activity on your fence line—not by buying mitigation first.
