The bill trades stronger protection of ports and the supply chain from foreign-controlled cyber risks and clearer federal timelines for potentially large compliance and replacement costs, operational disruptions during transitions, and regulatory uncertainty that may unevenly burden smaller ports and businesses.
Ports, transportation workers, and the national supply chain face a lower risk of foreign cyber interference because DHS/CISA must inspect, certify, or remove foreign-connected crane hardware and software before use.
Existing vulnerable foreign-made cranes will be taken offline or remediated until certified safe, reducing immediate operational threats to port operations and supply chains.
Port operators and local/state officials get clearer oversight and implementation timing — Congress receives a formal briefing and operators have a 5-year timeline to plan replacements or software changes — improving planning and accountability.
Port authorities, operators, and taxpayers will face substantial costs to inspect, certify, retrofit, or replace affected cranes and software, which could raise fees or require public funding.
Taking cranes offline for inspection or replacement and procurement delays could slow cargo handling, disrupt supply chains, and increase shipping costs for businesses and consumers, with impacts concentrated where resources are limited.
Smaller or resource-constrained ports risk being disproportionately disadvantaged, as they may struggle more than large ports to afford replacements or meet compliance timelines.
Based on analysis of 3 sections of legislative text.
Requires DHS/CISA inspections of internet-connected foreign-made port cranes, bans certain foreign-controlled crane procurement/operation, and phases out foreign software within five years.
Official title: To require the inspection of certain foreign cranes before use at a United States port, and for other purposes.
Introduced February 10, 2025 by Carlos A. Gimenez · Last progress February 10, 2025
Requires the Department of Homeland Security (through CISA) to inspect internet-connected foreign-made port cranes, assess and take offline cranes judged to pose security risks, ban operation or new procurement of specified foreign-controlled cranes, and phase out certain foreign software within five years. Sets deadlines for threat assessments (180 days), committee briefings (one year), and enforces prohibitions tied to an intelligence-driven definition of “covered foreign country.”