The bill increases visibility, standardization, and congressional oversight of legacy federal IT—helping prioritize modernization and improve security—but imposes recurring compliance costs, transparency trade-offs for sensitive systems, and planning uncertainty from a six-year sunset.
Federal CIOs, agency IT teams, and taxpayers will get clearer, government-wide inventories and prioritization of legacy IT so agencies can target modernization to reduce outages, improve service reliability, and strengthen cybersecurity.
Congress, GAO, inspectors general, and the public will have better access to cost, inventory, and modernization-plan information, increasing oversight and accountability over IT spending and program performance.
Agencies will be able to withhold legally protected or classified information and are barred from transferring sensitive systems to PRC-controlled entities, helping protect national-security programs and reduce foreign access risk.
Federal agencies and staff (and indirectly taxpayers) will face substantial administrative and compliance costs and workload to compile, update, and publish inventories and detailed modernization plans.
Publishing vendor contacts, cost details, and detailed modernization plans risks exposing procurement or system-vulnerability information that could harm national security or privacy if not properly redacted and protected.
Broad exemptions allowing agencies to withhold information under other laws could be used to hide non-sensitive records, reducing transparency and making it harder for Congress and the public to assess cyber risk and waste.
Based on analysis of 8 sections of legislative text.
Requires federal agencies to inventory legacy IT, produce recurring modernization plans, get OMB guidance, and submit GAO implementation review; no new funding and a six-year sunset.
Official title: To require the reduction of the reliance and expenditures of the Federal Government on legacy information technology systems, and for other purposes.
Introduced April 21, 2026 by Maxwell Frost · Last progress April 21, 2026
Requires federal agencies to inventory legacy information technology systems, develop recurring modernization plans, and submit those plans to OMB and congressional oversight committees. OMB must issue implementation guidance; the GAO must report on implementation within three years. The law exempts classified and national security systems, forbids transfers to the Chinese government, contains no new appropriations, and automatically sunsets after six years. The bill focuses on planning, reporting, and oversight rather than new funding or program creation: agency CIOs must produce inventories within one year and update them at least every five years, agency heads must include multi-year modernization plans in existing strategic planning cycles, and OMB must provide templates and criteria within 180 days.