HR 6558, the Defense Secure Mobile Phones Act of 2025, requires the Department of Defense (DoD) to provide wireless mobile phones with enhanced cybersecurity protections to senior officials and employees performing sensitive national security functions. The law mandates that all such phones and related telecom services must include encryption for data on devices and communications, capabilities to prevent tracking by rotating device identifiers, and continuous device monitoring. DoD must report to Congress within 180 days detailing the contracts used, criteria for identifying affected personnel, and associated costs. This bill directly affects DoD personnel handling sensitive security work by implementing specific technical security standards for their mobile devices.
HR 2683, the Remote Access Security Act, amends the Export Control Reform Act of 2018 to regulate how foreign entities remotely access U.S.-controlled technology. It defines "remote access" as foreign persons accessing U.S. items (like sensitive technology) via internet or cloud services from outside the item's physical location. The bill updates existing export control rules to include remote access as a regulated activity, requiring oversight similar to physical exports or in-country transfers. This primarily affects foreign companies, cloud providers, and technology firms handling U.S.-jurisdiction items.
This bill establishes an Energy Threat Analysis Center to enhance cybersecurity collaboration between the U.S. government and the energy sector. It creates mechanisms for sharing classified and unclassified threat information, conducting joint threat analysis, and developing technical infrastructure for real-time threat detection and mitigation. The Center’s activities are exempt from public disclosure laws, and the Secretary has sole discretion over providing assistance to energy entities without creating enforceable rights for other entities. The bill directly affects energy sector operators (both private companies and government entities) by enabling structured threat intelligence sharing to improve sector-wide cyberresilience.
This bill requires the National Institute of Standards and Technology (NIST) to develop and maintain workforce frameworks for critical and emerging technologies, including a mandatory artificial intelligence framework published within 540 days of enactment. The frameworks must define skills, roles, and pathways for technical and non-technical fields like ethics, supply chain security, and career transitions for individuals with nontraditional backgrounds. NIST must update frameworks every three years, include professional skills and multilingual resources, and report to Congress on progress. These frameworks aim to guide education, training, and hiring across government, industry, and educational institutions. The bill specifically mandates an AI workforce framework and updates to the existing cybersecurity framework (NICE), with regular congressional reporting.
The AI Training for National Security Act (HR 6530) requires the Department of Defense to update its mandatory annual cybersecurity training for military personnel and DoD civilian employees to include content on the cybersecurity risks unique to artificial intelligence. This revision must be completed within one year of the bill's enactment. The training will specifically address challenges like AI system vulnerabilities and adversarial attacks on AI tools. The bill directly affects all Armed Forces members and DoD civilian employees required to undergo annual cybersecurity training.
The Healthcare Cybersecurity Act of 2025 requires the Cybersecurity and Infrastructure Security Agency (CISA) and the Department of Health and Human Services (HHS) to improve coordination on cybersecurity for healthcare facilities and systems. It mandates a new agency liaison to the HHS, updates a sector-specific risk management plan within one year (focusing on rural and small providers), and establishes a process to identify "high-risk" healthcare assets for prioritized support. The bill also requires CISA to provide cybersecurity training for healthcare owners/operators and report on support efforts to Congress. This directly affects hospitals, clinics, and health systems - especially smaller or rural facilities - by creating new coordination mechanisms and risk assessment requirements to address rising cyber threats.
This bill requires the reinstatement of Cybersecurity and Infrastructure Security Agency (CISA) employees who were involuntarily removed between January 25 and March 1, 2025, with backpay. It also prohibits future involuntary removals or transfers of CISA staff without new congressional authorization, and bans federal funding for Department of Government Efficiency (DOGE) employees working at CISA. The law directly affects CISA employees who were removed during the specified period and prevents DOGE personnel from being funded at CISA. It creates concrete staffing protections for CISA while blocking a specific external agency (DOGE) from staffing CISA roles.
S 3920 (UASI Act) requires local governments applying for Urban Areas Security Initiative (UASI) grants to allocate at least 30% of their total grant funds across specific national priority areas, including cybersecurity, soft target protection, and election security. Crucially, it mandates a minimum 10% allocation for "border crisis response and enforcement," which includes activities like cooperating with ICE on detainers, training law enforcement on immigration law, and developing shared technology systems with ICE. Grantees must also submit detailed justifications for border-related spending and certify compliance with DHS rules, including prohibitions on incentivizing illegal immigration. Failure to meet these allocations could result in funding holds, denial of future grants, or termination of current awards. The requirements apply to all UASI grants awarded for fiscal year 2027 and beyond.
The Deploying American Blockchains Act of 2025 establishes a National Blockchain Deployment Advisory Committee under the Department of Commerce to advance U.S. competitiveness in blockchain technology. The committee, including private sector experts and federal agency representatives, will develop voluntary best practices for secure blockchain use in areas like supply chains, healthcare, and cybersecurity, while assessing federal agency adoption. It requires the Commerce Secretary to report annually to Congress on progress and emerging risks, with the committee dissolving after 7 years. The bill focuses on fostering industry collaboration and standardized guidelines without mandating private sector adoption or requiring companies to share information.
HR 7380, the IRAN Act, aims to improve internet access for Iranian citizens by directing U.S. agencies to support secure connectivity tools. It requires the State Department to coordinate digital freedom efforts, update strategies to evaluate VPNs and Direct-to-Cell (DTC) technology, and ensure sanctions enforcement doesn’t block these tools for Iranians. The bill also mandates the FCC to prevent licensees from geo-blocking Iran’s satellite/DTC coverage (except for network security) and directs the State Department to report on coverage issues. Additionally, it authorizes $15 million annually for cybersecurity training and digital safety tools for Iranian journalists, activists, and civil society. The law explicitly states it does not override existing sanctions or require U.S. companies to sell services in Iran.