This bill renews and updates the 2015 federal cybersecurity law. It pushes the government to share cyber threat information faster and more clearly with states, tribes, territories, and the private companies that run critical services like utilities and transportation. It also tells federal officials to keep their guidance up to date and to make it public, so people know how to act on new threats quickly . The bill lets federal experts offer technical help to non‑federal groups and, when needed, give one‑time classified briefings to select staff at critical infrastructure companies to better protect their systems. It broadens what’s covered to include industrial control systems, edge devices, and internet‑connected devices, including those hit by ransomware, and it makes clear that using artificial intelligence for cybersecurity purposes is allowed under the law.
The Department of Homeland Security must set up an outreach plan within 90 days to help especially small or rural critical infrastructure operators understand how to share threat information safely, remove personal data, and know the protections they have. The plan must also gather feedback to fix confusing rules. The bill also aims to speed up alerts across federal agencies when a major cyber threat is found .
Key points
Last progress September 2, 2025 (3 months ago)
Introduced on September 2, 2025 by Andrew R. Garbarino
Referred to the Committee on Homeland Security, and in addition to the Committees on Oversight and Government Reform, Intelligence (Permanent Select), Energy and Commerce, Armed Services, and the Judiciary, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.