This bill establishes a federal program to improve cybersecurity for rural water and wastewater systems. It directly affects rural water associations by providing technical assistance through "circuit riders" who assess security risks, develop protection protocols, and document cyber readiness. Key mechanisms include rapid threat assessments, developing security plans, and requiring annual reports on program activities. The program is funded at $10 million annually for fiscal years 2025-2029, with circuit riders needing specific cybersecurity certifications. This is a concrete policy change focused on strengthening infrastructure protection for rural communities.
The Smart Cities and Communities Act of 2025 aims to help cities and communities across the United States implement smart technologies that improve services, safety, energy efficiency, and resilience. The bill establishes a federal council to coordinate agency efforts, creates a resource guide with best practices for local governments, and provides $100 million annually for demonstration grants to test smart city technologies in various communities. It also creates a cybersecurity working group to develop evaluation tools, a workforce training program focused on smart city technologies, and a voucher program to connect cities with national laboratories. The act requires a study on innovative financing for smart city projects and promotes international cooperation to expand U.S. exports of smart city technologies while ensuring privacy and security standards.
This bill amends the Federal Cyber Scholarship for Service Program under the Cybersecurity Enhancement Act of 2014. It extends the required post-graduation service period from 3 to 5 years for scholarship recipients. Additionally, it removes restrictions on loan amounts by ensuring full loan coverage regardless of other Higher Education Act limits. The changes directly affect cybersecurity students receiving federal scholarships, altering their service obligations and financial support terms.
The Health Care Cybersecurity and Resiliency Act of 2025 requires the Department of Health and Human Services (HHS) to develop a cybersecurity incident response plan within one year, including strategies for risk assessment, prevention, detection, and recovery. It mandates new cybersecurity standards for healthcare entities, such as multifactor authentication for systems holding protected health information, encryption requirements, and mandatory audit protocols. The bill also updates breach reporting rules to require public disclosure of corrective actions and security practices considered during investigations, while creating grants to help rural healthcare providers adopt cybersecurity best practices. Additionally, it establishes training programs for healthcare cybersecurity staff and requires HHS to issue guidance on recognizing security practices that may reduce fines for covered entities. These provisions directly affect hospitals, clinics, and health organizations handling protected health information.
HR 1258, the Improving Contractor Cybersecurity Act, requires federal information technology contractors to implement standardized vulnerability disclosure policies. These policies must allow anonymous reporting of security flaws, prohibit lawsuits against researchers acting in good faith, and provide clear timelines for responding to reports and fixing issues. Contractors must also report significant new vulnerabilities to the Cybersecurity and Infrastructure Security Agency (CISA) within 7 days, and CISA will submit verified vulnerabilities to national databases like the National Vulnerability Database. The law directly affects companies bidding on federal IT contracts, mandating transparent security reporting processes to protect government and public systems.
The Expanding Cybersecurity Workforce Act of 2025 establishes a new program under CISA to promote cybersecurity careers to underrepresented groups, including racial and ethnic minorities, veterans, formerly incarcerated individuals, people with disabilities, older adults (40+), and those from low-income or nontraditional educational backgrounds (like community colleges or HBCUs). The program requires CISA to tailor outreach to regional needs, partner with schools, unions, and community organizations, and report annually on workforce impact. It authorizes $20 million annually for fiscal years 2026-2031 to support these efforts, aiming to diversify the cybersecurity workforce through targeted recruitment and training.
This bill reauthorizes the State and Local Cybersecurity Grant Program through fiscal year 2026. It sets federal cost-sharing rates at 60% for state governments and 70% for local governments in 2026, and authorizes $300 million in funding for that fiscal year. The program provides grants to state and local governments to improve cybersecurity infrastructure, directly supporting their efforts to protect public systems and data. The bill extends the program’s expiration date from September 30, 2025, to September 30, 2026.
The Cybersecurity Information Sharing Extension Act (S 1337) extends the expiration date of a key provision in the Cybersecurity Act of 2015 from 2025 to 2035. This provision enables private companies and government agencies to share cybersecurity threat information without legal liability. The extension ensures the current information-sharing framework remains active until 2035, providing ongoing legal certainty for participants. It directly affects organizations that rely on this program to enhance their cyber defense capabilities.
HR 6558, the Defense Secure Mobile Phones Act of 2025, requires the Department of Defense (DoD) to provide wireless mobile phones with enhanced cybersecurity protections to senior officials and employees performing sensitive national security functions. The law mandates that all such phones and related telecom services must include encryption for data on devices and communications, capabilities to prevent tracking by rotating device identifiers, and continuous device monitoring. DoD must report to Congress within 180 days detailing the contracts used, criteria for identifying affected personnel, and associated costs. This bill directly affects DoD personnel handling sensitive security work by implementing specific technical security standards for their mobile devices.
HR 2683, the Remote Access Security Act, amends the Export Control Reform Act of 2018 to regulate how foreign entities remotely access U.S.-controlled technology. It defines "remote access" as foreign persons accessing U.S. items (like sensitive technology) via internet or cloud services from outside the item's physical location. The bill updates existing export control rules to include remote access as a regulated activity, requiring oversight similar to physical exports or in-country transfers. This primarily affects foreign companies, cloud providers, and technology firms handling U.S.-jurisdiction items.