HR 4491, the SBA IT Modernization Reporting Act, requires the Small Business Administration (SBA) to implement specific recommendations from a 2024 GAO report about risks in its newly deployed IT systems. The bill mandates that SBA’s Administrator submit, within 180 days of enactment, a detailed implementation plan to Congress outlining how the agency will manage risks for all IT modernization projects. This plan must include 11 specific requirements, such as documenting risk sources, using GAO’s established guidelines for scheduling (GAO-16-89G) and cost estimation (GAO-20-195G), and involving cybersecurity experts in contractor selection. The SBA must also provide a briefing to congressional committees 30 days after submitting the plan.
The Energy Emergency Leadership Act (HR 7258) assigns new responsibilities to Assistant Secretaries at the Department of Energy (DOE) for managing energy infrastructure security, emergency response, and resilience. It requires them to handle cybersecurity, supply chain issues, and coordinated planning for energy security threats, risks, and incidents. The bill mandates that the DOE provide technical assistance to states, local governments, tribes, or energy companies upon their request, while working with other federal agencies. This change directly affects the DOE’s internal operations and the entities that can seek federal support during energy emergencies.
This bill strengthens SNAP benefit security by requiring all EBT cards to be chip-enabled (replacing magnetic stripes by 2030) and mandating retailers to use chip payment terminals for SNAP transactions. It establishes civil fines of double the stolen benefit value for unauthorized access, and requires states to provide free card replacements within 3 business days for fraud, damage, or loss - eliminating fees for these cases. The bill also expands USDA's fraud investigation authority and sets new cybersecurity standards for digital account management, including mobile-friendly interfaces and transaction alerts. These changes directly affect SNAP recipients, state agencies administering benefits, and participating retailers.
Next Generation 9–1–1 Act This bill establishes a grant program to support implementation of next generation 9-1-1 (NG9-1-1) systems by state, territorial, and tribal governments and requires other related activities. NG9-1-1 means a secure, interoperable, Internet Protocol-based (IP-based) system for receiving 9-1-1 requests for emergency assistance. (IP-based 9-1-1 systems have capabilities that legacy telephone systems do not, including enhanced location-finding and the ability to receive text and multimedia messages.) Under the bill, the National Telecommunications and Information Administration (NTIA) must provide grants to state, territorial, and tribal governments (and entities established by those governments) to support the implementation and maintenance of NG9-1-1 systems. Grant funds may also be used for public outreach on NG9-1-1, implementation of cybersecurity measures, and, subject to certain limits, training and administrative costs. Entities applying for grants must submit a plan for NG9-1-1 coordination and implementation that ensures interoperability and reliability, incorporates cybersecurity tools, and meets other requirements related to technology and procurement. Applicants must also certify that they have established, or will establish within a specified time frame, a sustainable funding mechanism to support NG9-1-1 and effective cybersecurity resources. The NTIA must advise applicants on the preparation of implementation plans and provide technical assistance to grant recipients. Further, the NTIA must establish (1) an advisory board to provide recommendations with respect to the grant program and other topics related to NG9-1-1; and (2) a cybersecurity center to coordinate with state, local, and regional governments on the sharing of cybersecurity information related to NG9-1-1.
The SELF DRIVE Act of 2026 establishes federal safety standards for vehicles with automated driving systems (ADS), requiring manufacturers to develop detailed "safety cases" demonstrating their systems won't present unreasonable risks to road users. It creates a National Automated Vehicle Safety Data Repository to collect crash data from ADS-equipped vehicles, including information about vulnerable road users (pedestrians, bicyclists, etc.) and crash circumstances. The bill preempts state laws that conflict with these federal standards while allowing states to enforce identical requirements, and defines key terms related to automation levels (Level 3-5) and operational design domains. Manufacturers must demonstrate ADS capabilities for handling various driving scenarios, including detecting vulnerable road users and achieving minimal risk conditions during emergencies. The bill also establishes requirements for cybersecurity protections and reporting of crash data to the National Highway Traffic Safety Administration.
This bill expands the types of cybersecurity positions eligible for special recruitment and retention incentives within the Department of Defense. It specifically adds positions in combatant commands, defense agencies supporting U.S. Cyber Command, and up to 500 "hard-to-fill" critical cyber roles to the existing categories. The bill allows the Secretary to pay these employees up to 150% of the highest federal pay level (Executive Schedule Level I) to attract and retain talent. It also shortens the required service period for these positions from five to three years and mandates detailed reporting on position specifics and how pay authorities are used. These changes directly affect cybersecurity personnel in defense-related roles requiring specialized skills.
S 1632 creates pathways for service members medically disqualified from military service to transition into civilian defense jobs within the Department of Defense. It requires the Secretary of Defense to establish a program within one year to connect individuals ineligible for military service with employment opportunities in the defense industrial base, including cybersecurity, defense R&D, and emergency preparedness roles. The bill also directs the Air Force’s DRIVE program as a model for other services and mandates the Navy to provide Military Sealift Command career information during transition assistance. These provisions directly affect medically disqualified service members and defense industry employers seeking qualified workers. The law focuses on concrete job placement mechanisms rather than broader policy changes.
HR 7625, the MTS CYBER Act of 2026, mandates a Government Accountability Office (GAO) review to assess the U.S. Coast Guard's budget and staffing needs for fulfilling its role as a Sector Risk Management Agency (SRMA) for maritime cybersecurity. The bill requires the GAO to evaluate Coast Guard funding for cybersecurity personnel, training, and enforcement; staff capabilities to monitor industry compliance; and guidance provided to maritime businesses against industry best practices. This review, due within 270 days of the bill’s enactment, aims to determine if current resources allow the Coast Guard to effectively protect the marine transportation system (MTS) - which includes ports, vessels, and waterways supporting $2.1 trillion in economic activity - from cyber threats. The findings will be submitted to relevant congressional committees to inform future funding decisions for the Coast Guard’s cybersecurity responsibilities.
The Pipeline Cybersecurity Preparedness Act (HR 7272) establishes a voluntary program under the Department of Energy to improve cybersecurity and physical security for natural gas pipelines, hazardous liquid pipelines, and liquefied natural gas facilities. It requires the Department to create coordination councils, lead incident response planning, develop voluntary cybersecurity tools and training, and run pilot projects with industry partners. The bill directly affects pipeline operators and energy sector stakeholders by providing technical resources to assess and enhance their security capabilities without mandating changes. Key mechanisms include developing workforce training curricula, offering evaluation tools, and facilitating collaboration between federal agencies, states, and the energy sector. The act explicitly states it does not alter existing authority of other federal agencies regarding pipeline security.
This bill strengthens cybersecurity protections for the 9-8-8 National Suicide Prevention Lifeline program. It requires the program’s network administrator (receiving federal funding) and participating local crisis centers to report cybersecurity vulnerabilities or incidents within 24 hours. The program must coordinate with the Department of Health and Human Services’ Chief Information Security Officer to eliminate vulnerabilities. Additionally, the bill mandates a study by the Comptroller General on the hotline’s cybersecurity risks, to be completed within 180 days of enactment.