The bill strengthens nationwide energy‑sector cybersecurity through a centralized analytic center, funding, and faster public‑private contracting, but does so while reducing transparency and external oversight and creating risks that smaller providers may be left behind.
Utilities and energy companies will receive centralized, actionable threat analysis, alerts, and mitigation recommendations through a new Energy Threat Analysis Center, improving real‑time detection and response to cyberattacks.
Federal program authorization and funding are extended ($250M authorized for FY2027–2031), providing sustained support for operational continuity and resilience activities for energy sector cybersecurity.
Utilities, governments, and contractors benefit from faster partnerships and expedited contracting mechanisms, reducing delays in deploying defenses, services, and private‑sector expertise.
Program decisions and assistance are placed at the Secretary's sole, unreviewable discretion and the program is excluded from the Federal Advisory Committee Act, limiting external oversight, accountability, and legal recourse for denied assistance.
Information shared under the program is exempt from FOIA and state/local disclosure laws, meaning taxpayers, local governments, and the public will have reduced transparency into program activities and potential misuse.
Expanded contracting authorities combined with secrecy could concentrate decision‑making and operational control within the Department, risking unequal access to assistance and services for small utilities and rural communities.
Based on analysis of 2 sections of legislative text.
Authorizes an Energy Threat Analysis Center, expands information-sharing and operational authorities for energy-sector cyberdefense, exempts shared data from FOIA, and extends funding authorization through 2031.
Expands and reorganizes the Department of Energy’s energy sector cyberresilience program by authorizing an Energy Threat Analysis Center to collect and share classified and unclassified threat information, provide operational collaboration, and perform threat analytics. It clarifies assistance is discretionary, exempts shared information from public disclosure, allows use of expedited contracting and partnership mechanisms, and extends existing authorization of appropriations through 2031. The bill removes an older provision, reorganizes statutory subsections, makes the program not subject to the Federal Advisory Committee Act, and continues authority for grants, contracts, cooperative agreements, and other transaction authorities to support energy sector cyberdefense activities.
Official title: To amend the Infrastructure Investment and Jobs Act to reauthorize the Department of Energy's Energy Sector Operational Support for Cyberresilience Program to provide operational support for energy sector cybersecurity and resilience.
Introduced February 2, 2026 by Kathy Castor · Last progress July 13, 2026