The bill increases federal focus on data centers—improving security and infrastructure resilience through critical-infrastructure designation and risk assessments—but does so in a way that will raise compliance costs for private and public operators and may be limited by a tight assessment timeline.
Data center operators, utilities, and communities near large data centers will be formally identified as critical infrastructure and receive federal guidance, enabling prioritized cybersecurity and physical-defense planning to reduce risk of attack or disruption.
Utilities, water suppliers, and government planners will get required assessments of connected power and water supply risks, improving resilience planning for electricity and water services that support data centers and nearby communities.
Federal attention and recommended planning can improve coordination between federal, state, and local agencies and private operators, increasing visibility of vulnerability gaps and helping prioritize resilience investments.
Data center operators and utilities could incur new security and compliance costs if designated critical infrastructure, raising operating expenses that may be passed on to customers.
State and local governments and utilities may face stricter operational requirements or follow-on mandates stemming from federal identification and recommendations, increasing public-sector costs and administrative burdens.
The 180-day timeline for completing technical assessments may be too short to produce deep, actionable analysis, risking incomplete recommendations and the need for additional studies or revisions.
Based on analysis of 2 sections of legislative text.
Directs DHS/CISA (with DoD as appropriate) to identify critical data centers, assess connected power/water risks and community impacts, and deliver a protective strategy to Congress within 180 days.
Official title: To require a strategy for the defense of data centers from external breaches from malefactors and the protection of the communities surrounding data centers, and for other purposes.
Introduced May 7, 2026 by Suhas Subramanyam · Last progress May 7, 2026
Requires the Department of Homeland Security, through CISA and with DoD as appropriate, to identify data centers that should be treated as critical infrastructure, evaluate their connected power and water supply security (with particular focus on above-ground transmission lines and electrical substations), and assess potential impacts on nearby communities. Within 180 days of enactment the Secretary must deliver a strategy and recommendations to Congress to defend those data centers from external breaches and to protect communities located near them.