HouseH.R. 10671119th Congress
Securing Our Critical Infrastructure Act
Full Text
Official text as published. Use Ctrl+F / Cmd+F to search within the document.
[Congressional Bills 119th Congress]
[From the U.S. Government Publishing Office]
[H.R. 10671 Introduced in House (IH)]
<DOC>
119th CONGRESS
2d Session
H. R. 10671
To amend the Cyber Incident Reporting for Critical Infrastructure Act
of 2022 to reauthorize a program of the Cybersecurity and
Infrastructure Security Agency relating to security vulnerability
warnings, and for other purposes.
_______________________________________________________________________
IN THE HOUSE OF REPRESENTATIVES
October 1, 2026
Mr. Gottheimer (for himself, Mr. Bacon, Mr. Nunn of Iowa, Ms. Scholten,
and Mr. Landsman) introduced the following bill; which was referred to
the Committee on Homeland Security
_______________________________________________________________________
A BILL
To amend the Cyber Incident Reporting for Critical Infrastructure Act
of 2022 to reauthorize a program of the Cybersecurity and
Infrastructure Security Agency relating to security vulnerability
warnings, and for other purposes.
Be it enacted by the Senate and House of Representatives of the
United States of America in Congress assembled,
SECTION 1. SHORT TITLE.
This Act may be cited as the ``Securing Our Critical Infrastructure
Act''.
SEC. 2. REAUTHORIZATION OF A PROGRAM OF THE CYBERSECURITY AND
INFRASTRUCTURE SECURITY AGENCY RELATING TO SECURITY
VULNERABILITY WARNINGS.
Section 105 of the Cyber Incident Reporting for Critical
Infrastructure Act of 2022 (6 U.S.C. 652 note) is amended--
(1) in the heading--
(A) by striking ``ransomware'' and inserting
``security''; and
(B) by striking ``pilot'';
(2) in subsection (a)--
(A) by striking ``Not later than 1 year after the
date of enactment of this Act, the Director shall
establish a ransomware vulnerability warning pilot
program'' and inserting ``There is established in the
Cybersecurity and Infrastructure Security Agency a
security vulnerability warning program''; and
(B) by striking ``associated with common ransomware
attacks'';
(3) by striking ``pilot'' each place it appears;
(4) in subsection (b)(1), by striking ``utilized in
ransomware attacks and mitigation techniques'' and inserting
``for information systems, and mitigation techniques relating
thereto'';
(5) in subsection (d), by striking ``covered entities'' and
inserting ``covered utilities'';
(6) in subsection (e)--
(A) by striking ``No procedure'' and inserting the
following:
``(1) In general.--No procedure''; and
(B) by adding at the end the following new
paragraphs:
``(2) Exemption from disclosure.--Information shared by a
covered entity with respect to the program established under
subsection (a) is exempt from disclosure under section
552(b)(3) of title 5, United States Code, and any provision of
State, local, or Tribal freedom of information law, open
government law, open meetings law, open records law, sunshine
law, or similar law requiring disclosure of information or
records.
``(3) Prohibited activity.--The Director may not disclose,
retain, or use information shared by a covered entity with
respect to the program established under subsection (a) unless
such disclosure, retention, or use, as the case may be, is for
a purpose specified in subsection (d)(5)(A) of section 105 of
the Cybersecurity Information Sharing Act of 2015 (6 U.S.C.
1504).
``(4) Privacy.--The Director shall retain information
shared by a covered entity with respect to the program
established under subsection (a) in a manner that protects from
unauthorized use or disclosure any of the following:
``(A) Any personal information that is of a
specific individual and included in such retained
information.
``(B) Any information that identifies a specific
individual and is included in such retained
information.''; and
(7) by striking subsection (g) and inserting the following
new subsections:
``(g) Cyber Hygiene Services.--
``(1) Automatic enrollment.--As part of the program
established under subsection (a), the Director shall
automatically enroll in the applicable cyber hygiene services
of the Cybersecurity and Infrastructure Security Agency each
covered utility.
``(2) Disenrollment.--A covered utility enrolled in a cyber
hygiene service pursuant to paragraph (1) may disenroll from
such service by submitting to the Director notice of such
disenrollment.
``(h) Incident Response.--As part of the program established under
subsection (a), if the Director determines that a covered utility has
been affected by a cyber incident, the Director shall utilize the
incident response capabilities of the Cybersecurity and Infrastructure
Security Agency to carry out on behalf of such utility a response to
such incident, as appropriate.
``(i) Coordination.--In carrying out the program established under
subsection (a), the Director shall coordinate with the Administrator of
the Environmental Protection Agency.
``(j) Termination.--The program established under subsection (a)
shall terminate on the date that is five years after the date of the
enactment of this subsection.
``(k) Covered Utility Defined.--In this section, the term `covered
utility' means an entity that is any of the following:
``(1) A water or wastewater utility that serves not more
than 100,000 individuals.
``(2) An eligible entity (as such term is defined in
section 40124 of the Infrastructure Investment and Jobs Act (42
U.S.C. 18723)).
``(3) An operator of any of the following:
``(A) A public water system (as such term is
defined in section 1401 of the Safe Drinking Water Act
(42 U.S.C. 300f)).
``(B) Treatment works (as such term is defined in
section 212 of the Federal Water Pollution Control Act
(33 U.S.C. 1292)).''.
<all>