Congressional Legislation · bill 119hr2659 · built from our database

Only the right has signed this so far (Bill Ranking)

Strengthening Cyber Resilience Against State-Sponsored Threats Act

H.R. 2659 · 119th Congress (2025-2026)

H.R. 2659119TH CONGRESSINTRODUCED 04/07/2025REP. OGLESR-TN · SPONSORLeft: no (Sponsor Ranking)Lean left: no (Sponsor Ranking)Center: no (Sponsor Ranking)Lean right: no (Sponsor Ranking)Right: DW-NOMINATE +0.75 (Sponsor Ranking)RIGHT(SPONSOR RANKING)SCIENCE, TECHNOLOGY, COMMUNICATIONS

5 members · Left 0 · Center 1 · Right 4 (Bill Ranking)

SponsorRep. Ogles, Andrew (R-TN) (Introduced 04/07/2025)
Sponsor Voting RecordRight · DW-NOMINATE +0.75 · measured from every roll-call vote this member has cast (voteview.com) (Sponsor Ranking)
Support
LLLCLRR

support across the spectrum: 5 members signed on (Bill Ranking) this bill: sponsor + current cosponsors, each once

CommitteesSenate - Homeland Security and Governmental Affairs Committee; House - Homeland Security Committee; House - Homeland Security Committee; House - Homeland Security Committee; House - Homeland Security Committee
Latest Action11/18/2025 Received in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
Roll Call Votes1
Sourceview on congress.gov →
IntroducedPassed HousePassed SenateResolving DifferencesTo PresidentBecame Law

Summary (1)

Reported to House (08/15/2025)

Strengthening Cyber Resilience Against State-Sponsored Threats Act

The bill creates a joint interagency task force to facilitate agency collaboration on efforts to respond to Chinese state-sponsored cyber actors, including Volt Typhoon. 

The task force must be established and led by the Cybersecurity and Infrastructure Security Agency (CISA), an agency within the Department of Homeland Security (DHS). The task force must facilitate collaboration and coordination among the Sector Risk Management Agencies (SRMAs) specified in the President's National Security Memorandum- 22 (e.g., the Department of Defense, the Department of Energy, and the Department of Agriculture) to detect, analyze, and respond to Chinese state-sponsored cyber actors by ensuring that such agencies’ actions are aligned and mutually reinforcing.

The bill directs DHS, CISA, the Department of Justice, the Federal Bureau of Investigation, and specified SRMAs to provide the task force with analysis, inspections, audits, and other relevant information necessary for the task force to carry out its responsibilities. The production and use of information must comply with all applicable statutes, regulations, and executive orders, and task force members must have appropriate security clearances to access classified information.

The task force must provide annual reports and briefings to Congress detailing its assessment of cyber threats and recommendations to improve the detection and mitigation of the cybersecurity threat posed by Chinese state-sponsored cyber actors.

The first report must be provided no later than 540 days after the establishment of the task force, and additional reports must be provided annually thereafter for six years.   

Text (4)

Engrossed in House (EH)

119 HR 2659 EH: Strengthening Cyber Resilience Against State-Sponsored Threats Act U.S. House of Representatives text/xml EN Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain. IB 119th CONGRESS1st Session H. R. 2659

IN THE HOUSE OF REPRESENTATIVES AN ACT To ensure the security and integrity of United States critical infrastructure by establishing an interagency task force and requiring a comprehensive report on the targeting of United States critical infrastructure by People’s Republic of China state-sponsored cyber actors, and for other purposes.

1.Short titleThis Act may be cited as the Strengthening Cyber Resilience Against State-Sponsored Threats Act.

2.Interagency task force and report on the targeting of United States critical infrastructure by People’s Republic of China state-sponsored cyber actors (a)Interagency task forceNot later than 120 days after the date of the enactment of this Act, the Secretary of Homeland Security, acting through the Director of the Cybersecurity and Infrastructure Security Agency (CISA) of the Department of Homeland Security, in consultation with the Attorney General, the Director of the Federal Bureau of Investigation, and the heads of appropriate Sector Risk Management Agencies as determined by the Director of CISA, shall establish a joint interagency task force (in this section referred to as the task force) to facilitate collaboration and coordination among the Sector Risk Management Agencies assigned a Federal role or responsibility in National Security Memorandum–22, issued April 30, 2024 (relating to critical infrastructure security and resilience), or any successor document, to detect, analyze, and respond to the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China by ensuring that such agencies’ actions are aligned and mutually reinforcing. (b)Chairs (1)ChairpersonThe Director of CISA (or the Director of CISA’s designee) shall serve as the chairperson of the task force. (2)Vice chairpersonThe Director of the Federal Bureau of Investigation (or such Director’s designee) shall serve as the vice chairperson of the task force. (c)Composition (1)In generalThe task force shall consist of appropriate representatives of the departments and agencies specified in subsection (a). (2)QualificationsTo materially assist in the activities of the task force, representatives under paragraph (1) should be subject matter experts who have familiarity and technical expertise regarding cybersecurity, digital forensics, or threat intelligence analysis, or in-depth knowledge of the tactics, techniques, and procedures (TTPs) commonly used by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China. (d)VacancyAny vacancy occurring in the membership of the task force shall be filled in the same manner in which the original appointment was made. (e)Establishment flexibilityTo avoid redundancy, the task force may coordinate with any preexisting task force, working group, or cross-intelligence effort within the Homeland Security Enterprise or the intelligence community that has examined or responded to the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China. (f)Task force reports; briefing (1)Initial reportNot later than 540 days after the establishment of the task force, the task force shall submit to the appropriate congressional committees the first report containing the initial findings, conclusions, and recommendations of the task force. (2)Annual reportNot later than one year after the date of the submission of the initial report under paragraph (1) and annually thereafter for five years, the task force shall submit to the appropriate congressional committees an annual report containing the findings, conclusions, and recommendations of the task force. (3)ContentsThe reports under this subsection shall include the following: (A)An assessment at the lowest classification feasible of the sector-specific risks, trends relating to incidents impacting sectors, and tactics, techniques, and procedures utilized by or relating to State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China. (B)An assessment of additional resources and authorities needed by Federal departments and agencies to better counter the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China. (C)A classified assessment of the extent of potential destruction, compromise, or disruption to United States critical infrastructure by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China in the event of a major crisis or future conflict between the People’s Republic of China and the United States. (D)A classified assessment of the ability of the United States to counter the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China in the event of a major crisis or future conflict between the People’s Republic of China and the United States, including with respect to different cybersecurity measures and recommendations that could mitigate such a threat. (E)A classified assessment of the ability of State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China to disrupt operations of the United States Armed Forces by hindering mobility across critical infrastructure such as rail, aviation, and ports, including how such would impair the ability of the United States Armed Forces to deploy and maneuver forces effectively. (F)A classified assessment of the economic and social ramifications of a disruption to one or multiple United States critical infrastructure sectors by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China in the event of a major crisis or future conflict between the People’s Republic of China and the United States. (G)Such recommendations as the task force may have for the Homeland Security Enterprise, the intelligence community, or critical infrastructure owners and operators to improve the detection and mitigation of the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China. (H)A one-time plan for an awareness campaign to familiarize critical infrastructure owners and operators with security resources and support offered by Federal departments and agencies to mitigate the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China. (4)BriefingNot later than 30 days after the date of the submission of each report under this subsection, the task force shall provide to the appropriate congressional committees a classified briefing on the findings, conclusions, and recommendations of the task force. (5)FormEach report under this subsection shall be submitted in classified form, consistent with the protection of intelligence sources and methods, but may include an unclassified executive summary. (6)PublicationThe unclassified executive summary of each report required under this subsection shall be published on a publicly accessible website of the Department of Homeland Security. (g)Access to information (1)In generalThe Secretary of Homeland Security, the Director of CISA, the Attorney General, the Director of the Federal Bureau of Investigation, and the heads of appropriate Sector Risk Management Agencies, as determined by the Director of CISA, shall provide to the task force such information, documents, analysis, assessments, findings, evaluations, inspections, audits, or reviews relating to efforts to counter the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China as the task force considers necessary to carry out this section. (2)Receipt, handling, storage, and disseminationInformation, documents, analysis, assessments, findings, evaluations, inspections, audits, and reviews described in this subsection shall be received, handled, stored, and disseminated only by members of the task force consistent with all applicable statutes, regulations, and Executive orders. (3)Security clearances for task force membersNo member of the task force may be provided with access to classified information under this section without the appropriate security clearances. (h)TerminationThe task force, and all the authorities of this section, shall terminate on the date that is 60 days after the final briefing required under subsection (h)(4). (i)Exemption from FACAChapter 10 of title 5, United States Code (commonly referred to as the Federal Advisory Committee Act), shall not apply to the task force. (j)Exemption from paperwork reduction actChapter 35 of title 44, United States Code (commonly known as the Paperwork Reduction Act), shall not apply to the task force. (k)DefinitionsIn this section: (1)Appropriate congressional committeesThe term appropriate congressional committees means— (A)the Committee on Homeland Security, the Committee on Judiciary, and the Select Committee on Intelligence of the House of Representatives; and (B)the Committee on Homeland Security and Governmental Affairs, the Committee on Judiciary, and the Select Committee on Intelligence of the Senate. (2)AssetsThe term assets means a person, structure, facility, information, material, equipment, network, or process, whether physical or virtual, that enables an organization’s services, functions, or capabilities. (3)Critical infrastructureThe term critical infrastructure has the meaning given such term in section 1016(e) of Public Law 107–56 (42 U.S.C. 5195c(e)). (4)Cybersecurity threatThe term cybersecurity threat has the meaning given such term in section 2200 of the Homeland Security Act of 2002 (6 U.S.C. 650). (5)Homeland security enterpriseThe term Homeland Security Enterprise has the meaning given such term in section 2200 of the Homeland Security Act of 2002 (6 U.S.C. 650). (6)IncidentThe term incident has the meaning given such term in section 2200 of the Homeland Security Act of 2002 (6 U.S.C. 650). (7)Information sharingThe term information sharing means the bidirectional sharing of timely and relevant information concerning a cybersecurity threat posed by a State-sponsored cyber actor of the People’s Republic of China to United States critical infrastructure. (8)Intelligence communityThe term intelligence community has the meaning given such term in section 3(4) of the National Security Act of 1947 (50 U.S.C. 3003(4)). (9)LocalityThe term locality means any local government authority or agency or component thereof within a State having jurisdiction over matters at a county, municipal, or other local government level. (10)SectorThe term sector means a collection of assets, systems, networks, entities, or organizations that provide or enable a common function for national security (including national defense and continuity of Government), national economic security, national public health or safety, or any combination thereof. (11)Sector risk management agencyThe term Sector Risk Management Agency has the meaning given such term in section 2200 of the Homeland Security Act of 2002 (6 U.S.C. 650). (12)StateThe term State means any State of the United States, the District of Columbia, the Commonwealth of Puerto Rico, the Northern Mariana Islands, the United States Virgin Islands, Guam, American Samoa, and any other territory or possession of the United States. (13)SystemsThe term systems means a combination of personnel, structures, facilities, information, materials, equipment, networks, or processes, whether physical or virtual, integrated or interconnected for a specific purpose that enables an organization’s services, functions, or capabilities. (14)United statesThe term United States, when used in a geographic sense, means any State of the United States. (15)Volt typhoonThe term Volt Typhoon means the People’s Republic of China State-sponsored cyber actor described in the Cybersecurity and Infrastructure Security Agency cybersecurity advisory entitled PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure, issued on February 07, 2024, or any successor advisory. Passed the House of Representatives November 17, 2025.Kevin F. McCumber,Clerk.

Introduced in House (IH)

107 HR 2659 IH: Strengthening Cyber Resilience Against State-Sponsored Threats Act U.S. House of Representatives 2025-04-07 text/xml EN Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain. I119th CONGRESS1st SessionH. R. 2659IN THE HOUSE OF REPRESENTATIVESApril 7, 2025Mr. Ogles (for himself, Mr. Green of Tennessee, Ms. Lee of Florida, Mr. Moolenaar, and Mr. Garbarino) introduced the following bill; which was referred to the Committee on Homeland SecurityA BILLTo ensure the security and integrity of United States critical infrastructure by establishing an interagency task force and requiring a comprehensive report on the targeting of United States critical infrastructure by People’s Republic of China state-sponsored cyber actors, and for other purposes.1.Short titleThis Act may be cited as the Strengthening Cyber Resilience Against State-Sponsored Threats Act.2.Interagency task force and report on the targeting of United States critical infrastructure by People’s Republic of China state-sponsored cyber actors(a)Interagency task forceNot later than 120 days after the date of the enactment of this Act, the Secretary of Homeland Security, acting through the Director of the Cybersecurity and Infrastructure Security Agency (CISA) of the Department of Homeland Security, in consultation with the Attorney General, the Director of the Federal Bureau of Investigation, and the heads of appropriate Sector Risk Management Agencies as determined by the Director of CISA, shall establish a joint interagency task force (in this section referred to as the task force) to facilitate collaboration and coordination among the Sector Risk Management Agencies assigned a Federal role or responsibility in National Security Memorandum–22, issued April 30, 2024 (relating to critical infrastructure security and resilience), or any successor document, to detect, analyze, and respond to the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China by ensuring that such agencies’ actions are aligned and mutually reinforcing.(b)Chairs(1)ChairpersonThe Director of CISA (or the Director of CISA’s designee) shall serve as the chairperson of the task force.(2)Vice chairpersonThe Director of the Federal Bureau of Investigation (or such Director’s designee) shall serve as the vice chairperson of the task force.(c)Composition(1)In generalThe task force shall consist of appropriate representatives of the departments and agencies specified in subsection (a).(2)QualificationsTo materially assist in the activities of the task force, representatives under paragraph (1) should be subject matter experts who have familiarity and technical expertise regarding cybersecurity, digital forensics, or threat intelligence analysis, or in-depth knowledge of the tactics, techniques, and procedures (TTPs) commonly used by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China.(d)VacancyAny vacancy occurring in the membership of the task force shall be filled in the same manner in which the original appointment was made.(e)Establishment flexibilityTo avoid redundancy, the task force may coordinate with any preexisting task force, working group, or cross-intelligence effort within the Homeland Security Enterprise or the intelligence community that has examined or responded to the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China.(f)Task force reports; briefing(1)Initial reportNot later than 540 days after the establishment of the task force, the task force shall submit to the appropriate congressional committees the first report containing the initial findings, conclusions, and recommendations of the task force.(2)Annual reportNot later than one year after the date of the submission of the initial report under paragraph (1) and annually thereafter for five years, the task force shall submit to the appropriate congressional committees an annual report containing the findings, conclusions, and recommendations of the task force.(3)ContentsThe reports under this subsection shall include the following:(A)An assessment at the lowest classification feasible of the sector-specific risks, trends relating to incidents impacting sectors, and tactics, techniques, and procedures utilized by or relating to State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China.(B)An assessment of additional resources and authorities needed by Federal departments and agencies to better counter the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China.(C)A classified assessment of the extent of potential destruction, compromise, or disruption to United States critical infrastructure by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China in the event of a major crisis or future conflict between the People’s Republic of China and the United States.(D)A classified assessment of the ability of the United States to counter the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China in the event of a major crisis or future conflict between the People’s Republic of China and the United States, including with respect to different cybersecurity measures and recommendations that could mitigate such a threat.(E)A classified assessment of the ability of State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China to disrupt operations of the United States Armed Forces by hindering mobility across critical infrastructure such as rail, aviation, and ports, including how such would impair the ability of the United States Armed Forces to deploy and maneuver forces effectively.(F)A classified assessment of the economic and social ramifications of a disruption to one or multiple United States critical infrastructure sectors by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China in the event of a major crisis or future conflict between the People’s Republic of China and the United States.(G)Such recommendations as the task force may have for the Homeland Security Enterprise, the intelligence community, or critical infrastructure owners and operators to improve the detection and mitigation of the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China.(H)A one-time plan for an awareness campaign to familiarize critical infrastructure owners and operators with security resources and support offered by Federal departments and agencies to mitigate the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China.(4)BriefingNot later than 30 days after the date of the submission of each report under this subsection, the task force shall provide to the appropriate congressional committees a classified briefing on the findings, conclusions, and recommendations of the task force.(5)FormEach report under this subsection shall be submitted in classified form, consistent with the protection of intelligence sources and methods, but may include an unclassified executive summary.(6)PublicationThe unclassified executive summary of each report required under this subsection shall be published on a publicly accessible website of the Department of Homeland Security.(g)Access to information(1)In generalThe Secretary of Homeland Security, the Director of CISA, the Attorney General, the Director of the Federal Bureau of Investigation, and the heads of appropriate Sector Risk Management Agencies, as determined by the Director of CISA, shall provide to the task force such information, documents, analysis, assessments, findings, evaluations, inspections, audits, or reviews relating to efforts to counter the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China as the task force considers necessary to carry out this section.(2)Receipt, handling, storage, and disseminationInformation, documents, analysis, assessments, findings, evaluations, inspections, audits, and reviews described in this subsection shall be received, handled, stored, and disseminated only by members of the task force consistent with all applicable statutes, regulations, and Executive orders.(3)Security clearances for task force membersNo member of the task force may be provided with access to classified information under this section without the appropriate security clearances.(h)TerminationThe task force, and all the authorities of this section, shall terminate on the date that is 60 days after the final briefing required under subsection (h)(4).(i)Exemption from FACAChapter 10 of title 5, United States Code (commonly referred to as the Federal Advisory Committee Act), shall not apply to the task force.(j)Exemption from paperwork reduction actChapter 35 of title 44, United States Code (commonly known as the Paperwork Reduction Act), shall not apply to the task force.(k)DefinitionsIn this section:(1)Appropriate congressional committeesThe term appropriate congressional committees means—(A)the Committee on Homeland Security, the Committee on Judiciary, and the Select Committee on Intelligence of the House of Representatives; and(B)the Committee on Homeland Security and Governmental Affairs, the Committee on Judiciary, and the Select Committee on Intelligence of the Senate.(2)AssetsThe term assets means a person, structure, facility, information, material, equipment, network, or process, whether physical or virtual, that enables an organization’s services, functions, or capabilities.(3)Critical infrastructureThe term critical infrastructure has the meaning given such term in section 1016(e) of Public Law 107–56 (42 U.S.C. 5195c(e)).(4)Cybersecurity threatThe term cybersecurity threat has the meaning given such term in section 2200 of the Homeland Security Act of 2002 (6 U.S.C. 650).(5)Homeland security enterpriseThe term Homeland Security Enterprise has the meaning given such term in section 2200 of the Homeland Security Act of 2002 (6 U.S.C. 650).(6)IncidentThe term incident has the meaning given such term in section 2200 of the Homeland Security Act of 2002 (6 U.S.C. 650).(7)Information sharingThe term information sharing means the bidirectional sharing of timely and relevant information concerning a cybersecurity threat posed by a State-sponsored cyber actor of the People’s Republic of China to United States critical infrastructure.(8)Intelligence communityThe term intelligence community has the meaning given such term in section 3(4) of the National Security Act of 1947 (50 U.S.C. 3003(4)).(9)LocalityThe term locality means any local government authority or agency or component thereof within a State having jurisdiction over matters at a county, municipal, or other local government level.(10)SectorThe term sector means a collection of assets, systems, networks, entities, or organizations that provide or enable a common function for national security (including national defense and continuity of Government), national economic security, national public health or safety, or any combination thereof.(11)Sector risk management agencyThe term Sector Risk Management Agency has the meaning given such term in section 2200 of the Homeland Security Act of 2002 (6 U.S.C. 650).(12)StateThe term State means any State of the United States, the District of Columbia, the Commonwealth of Puerto Rico, the Northern Mariana Islands, the United States Virgin Islands, Guam, American Samoa, and any other territory or possession of the United States.(13)SystemsThe term systems means a combination of personnel, structures, facilities, information, materials, equipment, networks, or processes, whether physical or virtual, integrated or interconnected for a specific purpose that enables an organization’s services, functions, or capabilities.(14)United statesThe term United States, when used in a geographic sense, means any State of the United States.(15)Volt typhoonThe term Volt Typhoon means the People’s Republic of China State-sponsored cyber actor described in the Cybersecurity and Infrastructure Security Agency cybersecurity advisory entitled PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure, issued on February 07, 2024, or any successor advisory.

Referred in Senate (RFS)

107 HR 2659 : Strengthening Cyber Resilience Against State-Sponsored Threats Act U.S. House of Representatives 2025-11-18 text/xml EN Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain. IIB119th CONGRESS1st SessionH. R. 2659IN THE SENATE OF THE UNITED STATESNovember 18, 2025 Received; read twice and referred to the Committee on Homeland Security and Governmental AffairsAN ACTTo ensure the security and integrity of United States critical infrastructure by establishing an interagency task force and requiring a comprehensive report on the targeting of United States critical infrastructure by People’s Republic of China state-sponsored cyber actors, and for other purposes.1.Short titleThis Act may be cited as the Strengthening Cyber Resilience Against State-Sponsored Threats Act.2.Interagency task force and report on the targeting of United States critical infrastructure by People’s Republic of China state-sponsored cyber actors(a)Interagency task forceNot later than 120 days after the date of the enactment of this Act, the Secretary of Homeland Security, acting through the Director of the Cybersecurity and Infrastructure Security Agency (CISA) of the Department of Homeland Security, in consultation with the Attorney General, the Director of the Federal Bureau of Investigation, and the heads of appropriate Sector Risk Management Agencies as determined by the Director of CISA, shall establish a joint interagency task force (in this section referred to as the task force) to facilitate collaboration and coordination among the Sector Risk Management Agencies assigned a Federal role or responsibility in National Security Memorandum–22, issued April 30, 2024 (relating to critical infrastructure security and resilience), or any successor document, to detect, analyze, and respond to the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China by ensuring that such agencies’ actions are aligned and mutually reinforcing.(b)Chairs(1)ChairpersonThe Director of CISA (or the Director of CISA’s designee) shall serve as the chairperson of the task force.(2)Vice chairpersonThe Director of the Federal Bureau of Investigation (or such Director’s designee) shall serve as the vice chairperson of the task force.(c)Composition(1)In generalThe task force shall consist of appropriate representatives of the departments and agencies specified in subsection (a).(2)QualificationsTo materially assist in the activities of the task force, representatives under paragraph (1) should be subject matter experts who have familiarity and technical expertise regarding cybersecurity, digital forensics, or threat intelligence analysis, or in-depth knowledge of the tactics, techniques, and procedures (TTPs) commonly used by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China.(d)VacancyAny vacancy occurring in the membership of the task force shall be filled in the same manner in which the original appointment was made.(e)Establishment flexibilityTo avoid redundancy, the task force may coordinate with any preexisting task force, working group, or cross-intelligence effort within the Homeland Security Enterprise or the intelligence community that has examined or responded to the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China.(f)Task force reports; briefing(1)Initial reportNot later than 540 days after the establishment of the task force, the task force shall submit to the appropriate congressional committees the first report containing the initial findings, conclusions, and recommendations of the task force.(2)Annual reportNot later than one year after the date of the submission of the initial report under paragraph (1) and annually thereafter for five years, the task force shall submit to the appropriate congressional committees an annual report containing the findings, conclusions, and recommendations of the task force.(3)ContentsThe reports under this subsection shall include the following:(A)An assessment at the lowest classification feasible of the sector-specific risks, trends relating to incidents impacting sectors, and tactics, techniques, and procedures utilized by or relating to State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China.(B)An assessment of additional resources and authorities needed by Federal departments and agencies to better counter the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China.(C)A classified assessment of the extent of potential destruction, compromise, or disruption to United States critical infrastructure by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China in the event of a major crisis or future conflict between the People’s Republic of China and the United States.(D)A classified assessment of the ability of the United States to counter the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China in the event of a major crisis or future conflict between the People’s Republic of China and the United States, including with respect to different cybersecurity measures and recommendations that could mitigate such a threat.(E)A classified assessment of the ability of State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China to disrupt operations of the United States Armed Forces by hindering mobility across critical infrastructure such as rail, aviation, and ports, including how such would impair the ability of the United States Armed Forces to deploy and maneuver forces effectively.(F)A classified assessment of the economic and social ramifications of a disruption to one or multiple United States critical infrastructure sectors by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China in the event of a major crisis or future conflict between the People’s Republic of China and the United States.(G)Such recommendations as the task force may have for the Homeland Security Enterprise, the intelligence community, or critical infrastructure owners and operators to improve the detection and mitigation of the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China.(H)A one-time plan for an awareness campaign to familiarize critical infrastructure owners and operators with security resources and support offered by Federal departments and agencies to mitigate the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China.(4)BriefingNot later than 30 days after the date of the submission of each report under this subsection, the task force shall provide to the appropriate congressional committees a classified briefing on the findings, conclusions, and recommendations of the task force.(5)FormEach report under this subsection shall be submitted in classified form, consistent with the protection of intelligence sources and methods, but may include an unclassified executive summary.(6)PublicationThe unclassified executive summary of each report required under this subsection shall be published on a publicly accessible website of the Department of Homeland Security.(g)Access to information(1)In generalThe Secretary of Homeland Security, the Director of CISA, the Attorney General, the Director of the Federal Bureau of Investigation, and the heads of appropriate Sector Risk Management Agencies, as determined by the Director of CISA, shall provide to the task force such information, documents, analysis, assessments, findings, evaluations, inspections, audits, or reviews relating to efforts to counter the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China as the task force considers necessary to carry out this section.(2)Receipt, handling, storage, and disseminationInformation, documents, analysis, assessments, findings, evaluations, inspections, audits, and reviews described in this subsection shall be received, handled, stored, and disseminated only by members of the task force consistent with all applicable statutes, regulations, and Executive orders.(3)Security clearances for task force membersNo member of the task force may be provided with access to classified information under this section without the appropriate security clearances.(h)TerminationThe task force, and all the authorities of this section, shall terminate on the date that is 60 days after the final briefing required under subsection (h)(4).(i)Exemption from FACAChapter 10 of title 5, United States Code (commonly referred to as the Federal Advisory Committee Act), shall not apply to the task force.(j)Exemption from paperwork reduction actChapter 35 of title 44, United States Code (commonly known as the Paperwork Reduction Act), shall not apply to the task force.(k)DefinitionsIn this section:(1)Appropriate congressional committeesThe term appropriate congressional committees means—(A)the Committee on Homeland Security, the Committee on Judiciary, and the Select Committee on Intelligence of the House of Representatives; and(B)the Committee on Homeland Security and Governmental Affairs, the Committee on Judiciary, and the Select Committee on Intelligence of the Senate.(2)AssetsThe term assets means a person, structure, facility, information, material, equipment, network, or process, whether physical or virtual, that enables an organization’s services, functions, or capabilities.(3)Critical infrastructureThe term critical infrastructure has the meaning given such term in section 1016(e) of Public Law 107–56 (42 U.S.C. 5195c(e)).(4)Cybersecurity threatThe term cybersecurity threat has the meaning given such term in section 2200 of the Homeland Security Act of 2002 (6 U.S.C. 650).(5)Homeland security enterpriseThe term Homeland Security Enterprise has the meaning given such term in section 2200 of the Homeland Security Act of 2002 (6 U.S.C. 650).(6)IncidentThe term incident has the meaning given such term in section 2200 of the Homeland Security Act of 2002 (6 U.S.C. 650).(7)Information sharingThe term information sharing means the bidirectional sharing of timely and relevant information concerning a cybersecurity threat posed by a State-sponsored cyber actor of the People’s Republic of China to United States critical infrastructure.(8)Intelligence communityThe term intelligence community has the meaning given such term in section 3(4) of the National Security Act of 1947 (50 U.S.C. 3003(4)).(9)LocalityThe term locality means any local government authority or agency or component thereof within a State having jurisdiction over matters at a county, municipal, or other local government level.(10)SectorThe term sector means a collection of assets, systems, networks, entities, or organizations that provide or enable a common function for national security (including national defense and continuity of Government), national economic security, national public health or safety, or any combination thereof.(11)Sector risk management agencyThe term Sector Risk Management Agency has the meaning given such term in section 2200 of the Homeland Security Act of 2002 (6 U.S.C. 650).(12)StateThe term State means any State of the United States, the District of Columbia, the Commonwealth of Puerto Rico, the Northern Mariana Islands, the United States Virgin Islands, Guam, American Samoa, and any other territory or possession of the United States.(13)SystemsThe term systems means a combination of personnel, structures, facilities, information, materials, equipment, networks, or processes, whether physical or virtual, integrated or interconnected for a specific purpose that enables an organization’s services, functions, or capabilities.(14)United statesThe term United States, when used in a geographic sense, means any State of the United States.(15)Volt typhoonThe term Volt Typhoon means the People’s Republic of China State-sponsored cyber actor described in the Cybersecurity and Infrastructure Security Agency cybersecurity advisory entitled PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure, issued on February 07, 2024, or any successor advisory.Passed the House of Representatives November 17, 2025.Kevin F. McCumber,Clerk.

Reported in House (RH)

107 HR 2659 RH: Strengthening Cyber Resilience Against State-Sponsored Threats Act U.S. House of Representatives 2025-08-15 text/xml EN Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain. IBUnion Calendar No. 188119th CONGRESS1st SessionH. R. 2659[Report No. 119–230]IN THE HOUSE OF REPRESENTATIVESApril 7, 2025Mr. Ogles (for himself, Mr. Green of Tennessee, Ms. Lee of Florida, Mr. Moolenaar, and Mr. Garbarino) introduced the following bill; which was referred to the Committee on Homeland SecurityAugust 15, 2025Committed to the Committee of the Whole House on the State of the Union and ordered to be printedA BILLTo ensure the security and integrity of United States critical infrastructure by establishing an interagency task force and requiring a comprehensive report on the targeting of United States critical infrastructure by People’s Republic of China state-sponsored cyber actors, and for other purposes.1.Short titleThis Act may be cited as the Strengthening Cyber Resilience Against State-Sponsored Threats Act.2.Interagency task force and report on the targeting of United States critical infrastructure by People’s Republic of China state-sponsored cyber actors(a)Interagency task forceNot later than 120 days after the date of the enactment of this Act, the Secretary of Homeland Security, acting through the Director of the Cybersecurity and Infrastructure Security Agency (CISA) of the Department of Homeland Security, in consultation with the Attorney General, the Director of the Federal Bureau of Investigation, and the heads of appropriate Sector Risk Management Agencies as determined by the Director of CISA, shall establish a joint interagency task force (in this section referred to as the task force) to facilitate collaboration and coordination among the Sector Risk Management Agencies assigned a Federal role or responsibility in National Security Memorandum–22, issued April 30, 2024 (relating to critical infrastructure security and resilience), or any successor document, to detect, analyze, and respond to the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China by ensuring that such agencies’ actions are aligned and mutually reinforcing.(b)Chairs(1)ChairpersonThe Director of CISA (or the Director of CISA’s designee) shall serve as the chairperson of the task force.(2)Vice chairpersonThe Director of the Federal Bureau of Investigation (or such Director’s designee) shall serve as the vice chairperson of the task force.(c)Composition(1)In generalThe task force shall consist of appropriate representatives of the departments and agencies specified in subsection (a).(2)QualificationsTo materially assist in the activities of the task force, representatives under paragraph (1) should be subject matter experts who have familiarity and technical expertise regarding cybersecurity, digital forensics, or threat intelligence analysis, or in-depth knowledge of the tactics, techniques, and procedures (TTPs) commonly used by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China.(d)VacancyAny vacancy occurring in the membership of the task force shall be filled in the same manner in which the original appointment was made.(e)Establishment flexibilityTo avoid redundancy, the task force may coordinate with any preexisting task force, working group, or cross-intelligence effort within the Homeland Security Enterprise or the intelligence community that has examined or responded to the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China.(f)Task force reports; briefing(1)Initial reportNot later than 540 days after the establishment of the task force, the task force shall submit to the appropriate congressional committees the first report containing the initial findings, conclusions, and recommendations of the task force.(2)Annual reportNot later than one year after the date of the submission of the initial report under paragraph (1) and annually thereafter for five years, the task force shall submit to the appropriate congressional committees an annual report containing the findings, conclusions, and recommendations of the task force.(3)ContentsThe reports under this subsection shall include the following:(A)An assessment at the lowest classification feasible of the sector-specific risks, trends relating to incidents impacting sectors, and tactics, techniques, and procedures utilized by or relating to State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China.(B)An assessment of additional resources and authorities needed by Federal departments and agencies to better counter the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China.(C)A classified assessment of the extent of potential destruction, compromise, or disruption to United States critical infrastructure by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China in the event of a major crisis or future conflict between the People’s Republic of China and the United States.(D)A classified assessment of the ability of the United States to counter the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China in the event of a major crisis or future conflict between the People’s Republic of China and the United States, including with respect to different cybersecurity measures and recommendations that could mitigate such a threat.(E)A classified assessment of the ability of State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China to disrupt operations of the United States Armed Forces by hindering mobility across critical infrastructure such as rail, aviation, and ports, including how such would impair the ability of the United States Armed Forces to deploy and maneuver forces effectively.(F)A classified assessment of the economic and social ramifications of a disruption to one or multiple United States critical infrastructure sectors by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China in the event of a major crisis or future conflict between the People’s Republic of China and the United States.(G)Such recommendations as the task force may have for the Homeland Security Enterprise, the intelligence community, or critical infrastructure owners and operators to improve the detection and mitigation of the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China.(H)A one-time plan for an awareness campaign to familiarize critical infrastructure owners and operators with security resources and support offered by Federal departments and agencies to mitigate the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China.(4)BriefingNot later than 30 days after the date of the submission of each report under this subsection, the task force shall provide to the appropriate congressional committees a classified briefing on the findings, conclusions, and recommendations of the task force.(5)FormEach report under this subsection shall be submitted in classified form, consistent with the protection of intelligence sources and methods, but may include an unclassified executive summary.(6)PublicationThe unclassified executive summary of each report required under this subsection shall be published on a publicly accessible website of the Department of Homeland Security.(g)Access to information(1)In generalThe Secretary of Homeland Security, the Director of CISA, the Attorney General, the Director of the Federal Bureau of Investigation, and the heads of appropriate Sector Risk Management Agencies, as determined by the Director of CISA, shall provide to the task force such information, documents, analysis, assessments, findings, evaluations, inspections, audits, or reviews relating to efforts to counter the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China as the task force considers necessary to carry out this section.(2)Receipt, handling, storage, and disseminationInformation, documents, analysis, assessments, findings, evaluations, inspections, audits, and reviews described in this subsection shall be received, handled, stored, and disseminated only by members of the task force consistent with all applicable statutes, regulations, and Executive orders.(3)Security clearances for task force membersNo member of the task force may be provided with access to classified information under this section without the appropriate security clearances.(h)TerminationThe task force, and all the authorities of this section, shall terminate on the date that is 60 days after the final briefing required under subsection (h)(4).(i)Exemption from FACAChapter 10 of title 5, United States Code (commonly referred to as the Federal Advisory Committee Act), shall not apply to the task force.(j)Exemption from paperwork reduction actChapter 35 of title 44, United States Code (commonly known as the Paperwork Reduction Act), shall not apply to the task force.(k)DefinitionsIn this section:(1)Appropriate congressional committeesThe term appropriate congressional committees means—(A)the Committee on Homeland Security, the Committee on Judiciary, and the Select Committee on Intelligence of the House of Representatives; and(B)the Committee on Homeland Security and Governmental Affairs, the Committee on Judiciary, and the Select Committee on Intelligence of the Senate.(2)AssetsThe term assets means a person, structure, facility, information, material, equipment, network, or process, whether physical or virtual, that enables an organization’s services, functions, or capabilities.(3)Critical infrastructureThe term critical infrastructure has the meaning given such term in section 1016(e) of Public Law 107–56 (42 U.S.C. 5195c(e)).(4)Cybersecurity threatThe term cybersecurity threat has the meaning given such term in section 2200 of the Homeland Security Act of 2002 (6 U.S.C. 650).(5)Homeland security enterpriseThe term Homeland Security Enterprise has the meaning given such term in section 2200 of the Homeland Security Act of 2002 (6 U.S.C. 650).(6)IncidentThe term incident has the meaning given such term in section 2200 of the Homeland Security Act of 2002 (6 U.S.C. 650).(7)Information sharingThe term information sharing means the bidirectional sharing of timely and relevant information concerning a cybersecurity threat posed by a State-sponsored cyber actor of the People’s Republic of China to United States critical infrastructure.(8)Intelligence communityThe term intelligence community has the meaning given such term in section 3(4) of the National Security Act of 1947 (50 U.S.C. 3003(4)).(9)LocalityThe term locality means any local government authority or agency or component thereof within a State having jurisdiction over matters at a county, municipal, or other local government level.(10)SectorThe term sector means a collection of assets, systems, networks, entities, or organizations that provide or enable a common function for national security (including national defense and continuity of Government), national economic security, national public health or safety, or any combination thereof.(11)Sector risk management agencyThe term Sector Risk Management Agency has the meaning given such term in section 2200 of the Homeland Security Act of 2002 (6 U.S.C. 650).(12)StateThe term State means any State of the United States, the District of Columbia, the Commonwealth of Puerto Rico, the Northern Mariana Islands, the United States Virgin Islands, Guam, American Samoa, and any other territory or possession of the United States.(13)SystemsThe term systems means a combination of personnel, structures, facilities, information, materials, equipment, networks, or processes, whether physical or virtual, integrated or interconnected for a specific purpose that enables an organization’s services, functions, or capabilities.(14)United statesThe term United States, when used in a geographic sense, means any State of the United States.(15)Volt typhoonThe term Volt Typhoon means the People’s Republic of China State-sponsored cyber actor described in the Cybersecurity and Infrastructure Security Agency cybersecurity advisory entitled PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure, issued on February 07, 2024, or any successor advisory.August 15, 2025Committed to the Committee of the Whole House on the State of the Union and ordered to be printed

The bill's own words, from our database (synced from the GPO BILLS XML); paragraph breaks added at the bill's section boundaries, nothing else changed.

All Actions (19)

DateChamberAll Actions
04/07/2025Library of CongressIntroduced in House
04/07/2025Library of CongressIntroduced in House
04/07/2025House floor actionsReferred to the House Committee on Homeland Security.
04/07/2025House committee actionsReferred to the Subcommittee on Cybersecurity and Infrastructure Protection.
04/09/2025House committee actionsSubcommittee on Cybersecurity and Infrastructure Protection Discharged
04/09/2025House committee actionsCommittee Consideration and Mark-up Session Held
04/09/2025House committee actionsOrdered to be Reported by Voice Vote.
08/15/2025Library of CongressReported by the Committee on Homeland Security. H. Rept. 119-230.
08/15/2025House floor actionsReported by the Committee on Homeland Security. H. Rept. 119-230.
08/15/2025House floor actionsPlaced on the Union Calendar, Calendar No. 188.
11/17/2025House floor actionsMr. Garbarino moved to suspend the rules and pass the bill.
11/17/2025House floor actionsConsidered under suspension of the rules. (consideration: CR H4682-4685)
11/17/2025House floor actionsDEBATE - The House proceeded with forty minutes of debate on H.R. 2659.
11/17/2025House floor actionsAt the conclusion of debate, the Yeas and Nays were demanded and ordered. Pursuant to the provisions of clause 8, rule XX, the Chair announced that further proceedings on the motion would be postponed.
11/17/2025House floor actionsConsidered as unfinished business. (consideration: CR H4692)
11/17/2025Library of CongressPassed/agreed to in House: On motion to suspend the rules and pass the bill Agreed to by the Yeas and Nays: (2/3 required): 402 - 8 (Roll no. 287). (text: CR H4682-4684)
11/17/2025House floor actionsOn motion to suspend the rules and pass the bill Agreed to by the Yeas and Nays: (2/3 required): 402 - 8 (Roll no. 287). (text: CR H4682-4684)
11/17/2025House floor actionsMotion to reconsider laid on the table Agreed to without objection.
11/18/2025SenateReceived in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs.

Titles (7)

Title TypeTitle
Short Titles from RFS (Referred to Senate) bill textStrengthening Cyber Resilience Against State-Sponsored Threats Act
Short Title(s) as Passed HouseStrengthening Cyber Resilience Against State-Sponsored Threats Act
Official Titles from EH (Engrossed in House) bill textTo ensure the security and integrity of United States critical infrastructure by establishing an interagency task force and requiring a comprehensive report on the targeting of United States critical infrastructure by People’s Republic of China state-sponsored cyber actors, and for other purposes.
Short Title(s) as Reported to HouseStrengthening Cyber Resilience Against State-Sponsored Threats Act
Display TitleStrengthening Cyber Resilience Against State-Sponsored Threats Act
Short Title(s) as IntroducedStrengthening Cyber Resilience Against State-Sponsored Threats Act
Official Title as IntroducedTo ensure the security and integrity of United States critical infrastructure by establishing an interagency task force and requiring a comprehensive report on the targeting of United States critical infrastructure by People's Republic of China state-sponsored cyber actors, and for other purposes.

Amendments (0)

There are no amendments to this bill.

Cosponsors (4)

* = Original cosponsor

Committees (5)

CommitteeActivity
Senate - Homeland Security and Governmental Affairs Committee11/18/2025 Referred To
House - Homeland Security Committee08/15/2025 Reported By
House - Homeland Security Committee04/09/2025 Markup By
House - Homeland Security Committee04/09/2025 Discharged from
House - Homeland Security Committee04/07/2025 Referred To

Related Bills (1)

Subjects (6)

Policy Area: Science, Technology, Communications

All data on this page comes from our own database (legislation.congress_* tables), synced daily from the GPO govinfo BILLSTATUS and BILLS collections. Formatted after congress.gov; nothing is generated. Member placement is their DW-NOMINATE score (voteview.com, Lewis et al.) - a measurement of roll-call voting behavior, not our judgement. Buckets: Left below −0.50 · Lean Left to −0.25 · Center to +0.25 · Lean Right to +0.50 · Right above +0.50. The bill's Support meter aggregates the people who signed the bill - sponsor and current cosponsors, each counted once - nothing else.