Cyber Deterrence and Response Act of 2025
The Cyber Deterrence and Response Act of 2025 establishes a process for designating foreign entities as "critical cyber threat actors" when they engage in state-sponsored cyber activities that threaten U.S. national security, economic stability, or critical infrastructure. It requires the creation of a National Attribution Framework to standardize how the government determines responsibility for cyber attacks, with specific evidence standards and coordination mechanisms for attribution. The bill authorizes a range of sanctions against designated entities, including travel bans, financial restrictions, and export controls on goods and technology. It includes exemptions for U.S. intelligence activities and provisions for case-by-case waivers of sanctions. The law aims to deter foreign cyber threats through a structured, evidence-based approach to attribution and sanctions.
Bill status
in committee
1 of 4 stages cleared
Introduction
Nov 2025
Committee Review
Floor Vote
President
Introduced Nov 25, 2025
Last action Nov 25, 2025
Floor votes
How they voted
No floor votes recorded yet.
Full legislative history
Actions timeline
Total actions
2
Key actions
0
Committee
1
Nov 25, 2025
Committee
Referred to the Committee on Foreign Affairs, and in addition to the Committees on Financial Services, Oversight and Government Reform, and the Judiciary, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.
lower
Nov 25, 2025
Introduced
Introduced in House
lower
1 primary · 0 co-sponsors
Sponsors
Role
Legislator
Party
State
District
P
August Pfluger
RRepublican
Ask Maddy
·
AI policy assistant
Ask Maddy about HR 6309
Scope: US
Hi! I can help you understand HR 6309. What would you like to know?
Try one of these
i
Maddy answers using official bill text and legislative records. Always verify before sharing.
Sources cited inline