The bill strengthens cybersecurity and resilience across the food and agriculture sector through aligned definitions, info-sharing, assessments, and exercises, but it raises costs, privacy/authority concerns, and disclosure risks—especially for small businesses and taxpayers.
Farmers, processors, retailers, and consumers will face a lower risk of cyber-driven food system disruptions because the bill requires regular risk assessments, vulnerability identification, and annual preparedness exercises that strengthen detection and response.
Private food and farm businesses will receive actionable best practices, recommendations, and identification of duplicative regulations, helping them prioritize cybersecurity measures and protect supply chains.
Federal, state, and local governments and Congress get clearer, aligned cybersecurity definitions, a designated Food and Agriculture ISAC, and biennial reporting, improving coordinated response, information sharing, and legislative oversight.
Small farms, processors, retailers and other small food businesses will face new regulatory expectations, reporting, and increased scrutiny that could impose significant compliance costs.
Private businesses and consumers could face expanded federal information-sharing obligations and privacy concerns from adopting DHS cybersecurity definitions and sector designation.
Public disclosure or reporting of identified vulnerabilities and exercise findings could expose sensitive operational details, increasing the risk of exploitation and harming companies' reputations or competitive positions.
Based on analysis of 4 sections of legislative text.
Requires biennial agricultural-sector cybersecurity risk assessments and annual cross-sector food crisis exercises, with reports to Congress and $1M/year authorized for exercises (FY2026–FY2030).
Official title: Direct the Secretary of Agriculture to periodically assess cybersecurity threats to, and vulnerabilities in, the agriculture and food critical infrastructure sector and to provide recommendations to enhance their security and resilience, to require the Secretary of Agriculture to conduct an annual cross-sector simulation exercise relating to a food-related emergency or disruption, and for other purposes.
Introduced February 26, 2025 by Thomas Bryant Cotton · Last progress February 26, 2025
Requires the Agriculture Secretary, working with CISA and other federal partners, to run recurring cybersecurity risk assessments and lead annual cross-sector food-related crisis simulation exercises to strengthen defenses and preparedness for the agriculture and food sector. The bill mandates biennial reports to Congress on cyber threats, vulnerabilities, gaps, and recommended federal actions, and funds a five-year exercise program with $1 million per year for FY2026–FY2030. The measures emphasize coordination with the sector-specific ISAC, sector coordinating councils, state/Tribal/local partners, and private-sector participants, and require after-action feedback, lessons learned, and recommendations to improve information sharing, response, supply-chain resilience, and policy alignment.