The Pipeline Cybersecurity Preparedness Act (HR 7272) establishes a voluntary program under the Department of Energy to improve cybersecurity and physical security for natural gas pipelines, hazardous liquid pipelines, and liquefied natural gas facilities. It requires the Department to create coordination councils, lead incident response planning, develop voluntary cybersecurity tools and training, and run pilot projects with industry partners. The bill directly affects pipeline operators and energy sector stakeholders by providing technical resources to assess and enhance their security capabilities without mandating changes. Key mechanisms include developing workforce training curricula, offering evaluation tools, and facilitating collaboration between federal agencies, states, and the energy sector. The act explicitly states it does not alter existing authority of other federal agencies regarding pipeline security.
This bill strengthens cybersecurity protections for the 9-8-8 National Suicide Prevention Lifeline program. It requires the program’s network administrator (receiving federal funding) and participating local crisis centers to report cybersecurity vulnerabilities or incidents within 24 hours. The program must coordinate with the Department of Health and Human Services’ Chief Information Security Officer to eliminate vulnerabilities. Additionally, the bill mandates a study by the Comptroller General on the hotline’s cybersecurity risks, to be completed within 180 days of enactment.
The Wildfire Grid Resiliency Act establishes a $10 million annual demonstration program (2026-2029) to fund National Laboratories developing innovative technologies that improve electric grid resilience during wildfires. It specifically supports projects focused on better vegetation monitoring near power lines and enhanced safety tools for first responders during grid emergencies. The program directly affects National Laboratories by providing federal funding for these demonstration projects, with the goal of testing new solutions before broader adoption. The bill does not mandate changes to existing grid operations but creates a structured process to evaluate and advance wildfire-resilience technologies.
This bill changes how federal agencies hire cybersecurity staff by restricting educational requirements for certain positions. It prohibits agencies from setting minimum education levels unless required by state or local law where the work occurs, and limits education consideration to directly relevant competencies. The bill applies to specific federal cybersecurity roles (like GS-2210 IT positions and NICE-designated roles) and requires the Office of Personnel Management to publish annual data on education levels for these hires. These changes aim to modernize hiring practices while ensuring education requirements align with actual job needs.
Streamlining Federal Cybersecurity Regulations Act of 2025 This bill establishes an interagency committee to review and align cybersecurity regulations and requirements imposed by executive agencies. The committee, to be led and administered by the Office of the National Cyber Director, must include the heads of each executive agency with statutory authority to enforce mandatory cybersecurity requirements. Agencies must generally consult with the committee before promulgating or amending cybersecurity requirements. The committee must develop a regulatory framework for the harmonization of agencies’ cybersecurity requirements. Under the bill, harmonization means the alignment of cybersecurity requirements to consist of a common set of minimum requirements that are applicable across sectors and sector-specific requirements as necessary. Specifically, the framework must contain processes for (1) establishing a reciprocal compliance mechanism for minimum requirements applicable to entities regulated by more than one agency; and (2) identifying and developing recommendations to address cybersecurity requirements that are overly burdensome, inconsistent, or contradictory. In developing this framework, the committee must seek public comment and consult with industry experts and stakeholders. Once the framework is developed and published, the committee must select agencies to carry out a pilot program to apply the framework to a sampling of their cybersecurity requirements. In consultation with the committee, the Office of Management and Budget must issue guidance to federal agencies on coordinating with the committee and, after the pilot program is complete, on ensuring cybersecurity requirements are consistent with the framework and lessons learned from the pilot program.
HR 4123, the FIT Procurement Act, modernizes federal information and communications technology (ICT) procurement by requiring new training for federal acquisition staff and streamlining processes to boost small business participation. The bill mandates a cross-functional ICT training program covering cloud computing, AI, cybersecurity, and commercial tech adoption, with learning objectives focused on outcome-based contracting and reducing waste. It increases simplified acquisition thresholds ($250,000 to $500,000) and micro-purchase limits ($10,000 to $25,000) to reduce administrative barriers. The Act also directs the Comptroller General to assess small business participation in federal tech contracts and requires agencies to eliminate unnecessary procedural hurdles for small businesses. These changes directly affect federal procurement staff, small businesses competing for contracts, and executive agencies managing ICT acquisitions.
S 1660, the Research Advancing to Market Production for Innovators Act, improves the Small Business Innovation Research (SBIR) and Small Business Technology Transfer (STTR) programs to help small businesses commercialize federally funded research. It requires federal agencies to include commercialization potential in peer reviews (adding specialized reviewers), creates a dedicated Technology Commercialization Official role in each agency, and expands funding for business/technical assistance (including cybersecurity support) for grant recipients. The bill also mandates annual commercialization impact reports tracking metrics like post-award revenue, patents, and Phase III contract success for businesses receiving multiple Phase II awards. These changes directly affect small businesses receiving SBIR/STTR grants and the federal agencies administering these programs.
The Cyber Deterrence and Response Act of 2025 establishes a process for designating foreign entities as "critical cyber threat actors" when they engage in state-sponsored cyber activities that threaten U.S. national security, economic stability, or critical infrastructure. It requires the creation of a National Attribution Framework to standardize how the government determines responsibility for cyber attacks, with specific evidence standards and coordination mechanisms for attribution. The bill authorizes a range of sanctions against designated entities, including travel bans, financial restrictions, and export controls on goods and technology. It includes exemptions for U.S. intelligence activities and provisions for case-by-case waivers of sanctions. The law aims to deter foreign cyber threats through a structured, evidence-based approach to attribution and sanctions.
This bill requires the Secretary of Defense to create a program partnering with eligible colleges and universities (including those conducting DoD research or senior military colleges) to develop standardized cybersecurity education programs. It mandates collaboration with agencies like NSA, CISA, and NIST to establish curriculum standards, workforce competencies, and community outreach, while designating qualifying institutions based on specific criteria like adherence to national cyber workforce frameworks and regional accreditation. The program must report annually to Congress on its cost-effectiveness and benefits to participants and the Department of Defense, without authorizing new funding. It directly affects academic institutions meeting the defined criteria and aims to strengthen the national cyber workforce through coordinated educational standards.
HR 3259, the Post Quantum Cybersecurity Standards Act, requires the National Institute of Standards and Technology (NIST) to promote the voluntary adoption of quantum-resistant encryption standards. It directly affects critical infrastructure operators and digital infrastructure providers deemed high-risk for quantum-related cyber threats. Key provisions include NIST disseminating public guidance, offering technical assistance, and establishing a grant program to help these entities adopt new encryption standards and address vulnerabilities. The bill mandates collaboration with Homeland Security and sector-specific agencies but does not mandate compliance or create new regulatory requirements.