Authorizes law enforcement to use approved private vendors to store and forensically process child pornography/obscenity, limits vendor liability while requiring NIST cybersecurity standards.
Official title: To limit liability for certain entities storing child sexual abuse material for law enforcement agencies, and for other purposes.
Introduced March 5, 2026 by Laurel Lee · Last progress March 5, 2026
The bill authorizes vetted private vendors, with strong cybersecurity and evidence-retention rules, to handle and preserve child sexual abuse evidence—boosting law enforcement capacity and prosecutions—while reducing vendor liability and creating accountability and data-breach risks for victims.
Law enforcement agencies and prosecutors: retain covered evidence through applicable retention periods (or at least through statute of limitations or sentence), preserving material needed for prosecutions and appeals.
Law enforcement agencies and state/local governments: can contract vetted private vendors to securely store and forensically process child sexual abuse material, improving evidence handling and increasing investigators' and prosecutors' access to specialized services.
Government contractors and law enforcement: required NIST cybersecurity standards and annual independent audits raise technical safeguards and reduce the risk of data theft or leakage of sensitive evidence.
Victims: limiting civil and criminal suits against vendors narrows accountability avenues and could make it harder for victims to obtain redress when vendors misuse or mishandle sensitive material outside the bill's exceptions.
Victims and the public: allowing contractors to store child sexual abuse material—even with controls—creates a nonzero risk of data breaches that could retraumatize victims and expose sensitive evidence if safeguards fail.
Law enforcement and state governments: requiring that evidence remain in the United States may complicate multijurisdictional investigations and forensic cooperation with foreign partners, potentially slowing some probes.
Based on analysis of 2 sections of legislative text.
Authorizes federal, state, and local law enforcement and prosecutors to use designated private "approved vendors" to store, maintain, and perform forensic processing of child pornography and defined child obscenity materials, and sets rules for vendor liability and cybersecurity. It creates a limited-liability protection for vendors doing contracted law-enforcement work while preserving liability for intentional misconduct, gross negligence, or acts done for improper purposes. Imposes cybersecurity and access-control requirements for vendors (including following the latest NIST Cybersecurity Framework) and defines covered agencies, vendors, and the criminal material categories the rule applies to. The excerpt does not include new funding or explicit criminal penalties; it primarily changes authorization, civil-liability, and operational standards for handling child sexual abuse material (CSAM) by third-party cloud/forensic providers working with law enforcement.