HR 5078 United States House · 119th Congress

PILLAR Act

The PILLAR Act reauthorizes the CISA State and local cybersecurity grant program through fiscal year 2035, expanding its scope to cover operational technology systems and systems using artificial intelligence. It requires grant recipients to adopt multi-factor authentication and other cybersecurity best practices, with higher federal funding rates (up to 75% for multi-entity groups) if these measures are implemented by October 2027. The bill also mandates outreach to rural and small local governments to ensure equitable access to cybersecurity resources and includes a requirement for GAO reviews of artificial intelligence adoption across funded programs.
Bill status passed 3 of 5 stages cleared
Introduction
Sep 2025
Committee Review
Nov 2025
House Passage
Nov 2025
Senate Passage
President
Introduced Sep 2, 2025 Last action Nov 18, 2025
Maddy AI version diff · 1 comparison

What changed between versions

Introduced in House Engrossed in House · 4 edits · Nov 17, 2025
MODERATE
The engrossed version of the PILLAR Act makes three substantive changes from the introduced version: it extends the CISA State and Local Cybersecurity Grant Program reauthorization through fiscal year 2033 (previously set to end in 2025), aligns all federal cost-share provisions to that same 2033 date (previously set to 2035, creating an inconsistency), and increases the frequency of GAO oversight reviews from every four years to every three years. The remaining changes are technical corrections to drafting language and formatting.
TIMELINE

The program reauthorization end date was changed from fiscal year 2025 to fiscal year 2033, extending the grant program by eight years.

FISCAL

The federal cost-share provisions (60 percent for eligible entities and 70 percent for multi-entity groups) were shortened from running through fiscal year 2035 to fiscal year 2033, aligning them with the new program end date. The MFA incentive tier (65/75 percent) was similarly adjusted from 2035 to 2033.

ENFORCEMENT

The GAO review of the grant program was changed from occurring every four years to every three years, increasing oversight frequency.

TECHNICAL

Multiple instances of missing 'and' were added in drafting language (e.g., 'by striking information systems owned and inserting'), and a stray 'of' was removed from a funding allocation provision. These are technical corrections with no policy impact.

Floor votes

How they voted

This bill passed the House by voice vote (no roll call recorded).
Full legislative history

Actions timeline

Total actions
15
Key actions
4
Committee
6
Amendments
2
Nov 18, 2025
Committee
Received in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
upper
Nov 17, 2025
Introduced
On motion to suspend the rules and pass the bill, as amended Agreed to by voice vote. (text: CR H4685-4687)
lower
Nov 17, 2025
Lower · Passed
Passed/agreed to in House: On motion to suspend the rules and pass the bill, as amended Agreed to by voice vote. (text: CR H4685-4687)
lower
Nov 17, 2025
Introduced
Mr. Garbarino moved to suspend the rules and pass the bill, as amended.
lower
Nov 12, 2025
Lower · Passed
Reported by the Committee on Homeland Security. H. Rept. 119-377.
lower
Sep 3, 2025
Lower · Passed
Committee Consideration and Mark-up Session Held
lower
Sep 3, 2025
Lower · Passed
Subcommittee on Cybersecurity and Infrastructure Protection Discharged
lower
Sep 2, 2025
Committee
Referred to the Subcommittee on Cybersecurity and Infrastructure Protection.
lower
Sep 2, 2025
Committee
Referred to the House Committee on Homeland Security.
lower
Sep 2, 2025
Introduced
Introduced in House
lower
1 primary · 4 co-sponsors

Sponsors