The bill strengthens U.S. defenses against actors who attack critical infrastructure by increasing deterrence, sanctioning foreign perpetrators, and elevating federal focus on cybersecurity — but it also expands severe penalties and executive authority in ways that raise due-process, research-chill, compliance-cost, and diplomatic risks.
All Americans and critical infrastructure operators: authorizes the President to block assets and make foreign actors who target U.S. critical infrastructure inadmissible, disrupting their financing and ability to operate against U.S. systems and improving national security and public safety.
Utilities, hospitals, and other infrastructure owners/operators: stronger statutory emphasis and tougher penalties raise the deterrent threat against attacks on critical infrastructure, which may reduce successful cyberattacks and physical harms to services.
Infrastructure operators and contractors: the prospect of harsher penalties creates an incentive for increased investment in cybersecurity practices and contracts, encouraging better protection of critical systems.
Individuals prosecuted for computer offenses involving critical infrastructure face dramatically longer prison terms (e.g., 30 years to life), raising risks of disproportionately severe punishment for cyber-related conduct.
Broad or vague definitions and executive designation authority could expand exposure to extreme penalties or visa inadmissibility, creating serious due-process and wrongful-designation risks for both domestic and foreign persons with limited appeal options.
Security researchers and good-faith vulnerability reporters may be chilled from testing, researching, or disclosing flaws due to harsher criminalization, potentially reducing defensive innovation and early identification of vulnerabilities.
Based on analysis of 3 sections of legislative text.
Imposes a new 30-year-to-life mandatory sentencing tier for computer crimes involving critical infrastructure and requires sanctions (IEEPA blocking, visa bans) on foreign actors who knowingly target that infrastructure to harm U.S. security or persons.
Official title: To amend title 18, United States Code, to increase penalties for certain computer fraud and related offenses that involve critical infrastructure, and for other purposes.
Introduced May 8, 2025 by Pat Fallon · Last progress May 8, 2025
Makes unauthorized access of U.S. critical infrastructure a much more severe federal crime and creates mandatory sanctions for foreign persons who knowingly target that infrastructure to harm U.S. national security or the safety of U.S. persons. It raises the maximum criminal exposure (including a new penalty tier of at least 30 years or life imprisonment for offenses involving critical infrastructure), and directs the President to use IEEPA-based blocking sanctions, visa ineligibility/mandatory revocation, and civil/criminal penalties against foreign perpetrators, with limited waiver authority and required implementing regulations.