The Combating Foreign Threats to Main Street Act of 2026 directs the Small Business Administration to create and distribute educational materials that help small businesses identify and protect against harmful activities by foreign adversaries. These materials must cover topics such as intellectual property theft, cybersecurity risks, forced labor in supply chains, and the dangers of specific commercial relationships with foreign-controlled entities. The bill requires the agency to review and update these resources annually starting in 2027 to ensure they reflect current threats and best practices. Additionally, if the agency determines that a specific activity poses a significant risk to national or economic security, it must notify the relevant congressional committees about the finding and its justification.
The Army Quantum Readiness Act requires the Secretary of the Army to establish a new initiative focused on integrating quantum computing and advanced technologies into military operations, intelligence, and logistics. This initiative aims to identify practical applications for these technologies, assess necessary infrastructure upgrades such as power and cybersecurity, and develop strategies for training the required workforce. The bill also authorizes the creation of pilot projects and demonstration activities to test quantum-enabled tools, including artificial intelligence and secure networking. Finally, it mandates that the Secretary submit a detailed report to Congress within 270 days outlining readiness requirements, recommended investments, and necessary legislative changes to accelerate this transition.
The Cybersecurity for Small Businesses Act of 2026 directs the Small Business Administration, in partnership with federal cybersecurity agencies, to create and distribute resources that help small businesses improve their digital security practices. The bill specifically requires the administration to provide guidance on federal cybersecurity compliance standards to small companies seeking government contracts or subcontracting opportunities. This information must be made available through small business development centers, district offices, and the agency's website. Additionally, the Office of Advocacy is required to submit an annual report to Congress detailing how many small businesses have contacted them regarding cybersecurity issues.
The Water Cyber Shield Act of 2026 mandates cybersecurity risk assessments and emergency response plans for community water systems serving more than 3,300 people and large wastewater treatment facilities serving over 10,000 people with a design flow rate of at least one million gallons. The bill requires the Environmental Protection Agency to establish baseline cybersecurity standards in collaboration with federal agencies and industry experts, while authorizing states to assume primary enforcement responsibilities if they demonstrate adequate capacity and security protocols. It allocates $300 million annually for fiscal years 2027 through 2032 to help water systems build cybersecurity resilience, prioritizing assistance for facilities with the greatest need for resources or expertise. Additionally, the legislation expands cyber incident reporting obligations under the Homeland Security Act to include these specific water infrastructure entities and requires that submitted security documentation be protected from public disclosure under federal and state freedom of information laws.
The Water Authority Cybersecurity Protection Act extends the Drinking Water Infrastructure Risk and Resilience Program through fiscal years 2028 and 2029, replacing the previous expiration dates of 2020 and 2021. The bill doubles the authorized funding for technical assistance to $10 million and for grants to small water systems to $20 million. Additionally, it increases the total annual authorization of appropriations for the program from $25 million to $50 million. These changes directly affect public water utilities by providing continued financial support for cybersecurity improvements and risk management.
This bill requires contractors to submit an "artificial intelligence functional bill of materials" before the Department of Defense can enter into, renew, or extend any contract for goods or services that utilize artificial intelligence. This document must provide a detailed, machine-readable inventory of the specific software models, data sources, and hardware infrastructure supporting the AI system to allow the military to assess security risks and vulnerabilities. The legislation also mandates that existing software supply chain rules apply to AI systems and requires the Department of Defense to issue cybersecurity guidelines for securely storing these inventories.
The Rural and Municipal Utility Cybersecurity Act establishes a federal program to provide grants and technical assistance to small electric utilities, including rural cooperatives, municipally owned systems, and smaller investor-owned companies. The program aims to help these entities deploy advanced cybersecurity technologies and participate in threat information sharing networks to better protect against cyberattacks. Funding is prioritized for utilities with limited security resources or those operating critical infrastructure that supports the national power grid. The bill authorizes $250 million in appropriations over five years, from fiscal year 2027 through 2031, and exempts shared cybersecurity information from public disclosure under freedom of information laws.
The Quantum-GUARD Act of 2026 requires the Federal Energy Regulatory Commission to evaluate cybersecurity risks posed by quantum computers and the potential use of post-quantum cryptography when reviewing reliability standards for the bulk-power system. The bill directs the Department of Energy to establish a "PQC sandbox" within one year, bringing together grid operators, technology vendors, and government agencies to test and develop post-quantum security solutions for both information and operational technology systems. Additionally, the Secretary of Energy must conduct a study on the specific vulnerabilities of critical grid infrastructure to quantum threats and submit a report with recommendations to Congress within one year of enactment.
The Small Business Cybersecurity Assistance Evaluation Act of 2026 directs the Government Accountability Office to conduct a comprehensive study of existing federal cybersecurity initiatives, tools, and services designed to support small businesses. The investigation will assess how effectively these resources help owners identify cyber risks, prepare for threats, recover from attacks, and secure funding for security measures. Additionally, the study will evaluate the level of awareness among small business owners regarding these programs and examine how well different federal efforts are coordinated with one another. Upon completion, the findings and recommendations for improving these services will be submitted to the relevant congressional committees without authorizing any new spending.
The RECOVER PII Act expands identity protection coverage for individuals affected by federal agency data breaches, extending the duration of protection for the remainder of their lives and increasing the minimum insurance amount to $5 million. Additionally, the bill allows federal agencies to use appropriated funds to reimburse employees or their contractors for up to 100 percent of the costs associated with privacy-enhancing services, such as software or hardware designed to mitigate data risks. These provisions aim to provide long-term financial support and resources to victims of data breaches while ensuring that reimbursement claims are supported by necessary documentation.