ANCHOR Act
Click any stage to learn more about the legislative process.
Would require the National Science Foundation to develop a comprehensive plan — within 18 months of enactment — to upgrade the cybersecurity and telecommunications infrastructure of the U.S. Academic Research Fleet, the network of federally supported oceanographic research vessels operated by universities and laboratories.
The bill addresses longstanding gaps in satellite connectivity, data security, and remote-work capabilities aboard research ships, and would require a coordinated spending plan shared among NSF, the Navy, and non-federal vessel owners.
What this bill would do
What it would do
The bill would direct the NSF Director, in consultation with federal agency vessel owners and the heads of universities and laboratories that operate vessels, to submit a plan to two congressional committees within 18 months of enactment. The plan must assess the telecommunications and networking needs of each vessel class, evaluate cybersecurity needs in line with guidance from the Cybersecurity and Infrastructure Security Agency and NIST, estimate the costs and timelines for required upgrades under varying budget scenarios, and identify opportunities for shared solutions or centralized data management. It must also include a spending plan detailing how NSF, the Office of Naval Research, non-federal vessel owners, and users would share the costs.
The bill does not itself fund any upgrades or mandate that upgrades be carried out — it authorizes NSF to support upgrades consistent with the plan but does not appropriate money for them. The NSF Director would then be required to submit a follow-on progress report to Congress no later than two years after the plan is delivered.
Key provisions
- 1Would require the NSF Director to submit a cybersecurity and telecommunications improvement plan for the Academic Research Fleet to Congress within 18 months of enactment.
- 2Would require the plan to assess telecom and networking needs, cybersecurity needs aligned with CISA and NIST guidance, upgrade costs (equipment, personnel, charter-rate impacts), and implementation timelines under varying budgets.
- 3Would require the plan to assess opportunities for shared or consortial solutions, or for centralizing cybersecurity, telecom, or data management at a single facility.
- 4Would require the plan to include a multi-party spending plan allocating identified costs among NSF, the Office of Naval Research, non-federal vessel owners, and users.
- 5Would direct the NSF Director to consider network capabilities for telemedicine, real-time streaming of research activities, remote expert support, and K-12 educational outreach when preparing the plan.
- 6Would require the NSF Director to submit a report to Congress on progress in implementing the plan no later than two years after the plan's submission.
Who would be affected
The NSF Director and the Office of Naval Research bear the primary planning responsibilities. Universities and laboratories that own or operate vessels in the U.S. Academic Research Fleet — and the oceanographic scientists, students, and support personnel who sail on those vessels — are the intended beneficiaries. The Cybersecurity and Infrastructure Security Agency and NIST would be consulted during plan development.
Why it matters
Oceanographic research vessels operate in remote environments where reliable connectivity and strong cybersecurity directly affect scientific data collection, crew safety (including telemedicine access), and protection of sensitive research information. Without a coordinated plan and cost-sharing framework, universities and labs face a patchwork of aging systems and no clear path to modernization funded across responsible parties.
What would change
Agencies directed to act
Effective dates
- Deadline for NSF Director to submit the cybersecurity and telecommunications improvement plan to Congress
- Deadline for NSF Director to submit progress report on plan implementation to Congress
How implementation would work
The NSF Director would lead plan development in consultation with federal co-owners, university and laboratory operators, CISA, and NIST. The plan must address telecom bandwidth and speed targets by vessel class, align with the JASON cybersecurity advisory report (JSR-21-10E), and include a multi-party spending framework. After the plan is submitted to Congress, NSF may coordinate voluntary upgrades with ONR and non-federal owners. A progress report back to Congress is due two years after the plan is delivered, creating a built-in accountability checkpoint.
Legislative status & sources
Latest action
Received in the Senate and Read twice and referred to the Committee on Commerce, Science, and Transportation.
Official CRS summary
Show the CRS summaryHide the CRS summary
This bill requires the National Science Foundation (NSF) to develop a plan to improve the cybersecurity and telecommunications capabilities of the U.S. Academic Research Fleet (ARF).
ARF is comprised of U.S.-flagged vessels that provide at-sea laboratories where oceanographic scientists, educators, and students research and learn about marine science.
The bill requires the plan to include assessments of
- telecommunications and networking needs of ARF, consistent with typical scientific missions;
- cybersecurity needs appropriate for the operation of ARF vessels and their specific research functions;
- the costs necessary to meet these needs;
- the time required to implement necessary upgrades; and
- opportunities for the adoption of common solutions or consortial licensing agreements, or for the centralization of cybersecurity, telecommunications, or data management at a single facility.
The plan must also include a spending plan for the NSF, the Office of Naval Research, nonfederal owners of ARF vessels, and users of the vessels to cover identified costs.
Among other factors specified in the bill, the NSF must consider, as appropriate, the network capabilities necessary to meet mission needs (e.g., to upload data to cloud-based or shoreside servers), international standards and guidance for information security, and requirements for controlled unclassified or classified information.
The plan must be provided to Congress within 18 months of the bill's enactment, and the NSF must later report to Congress on the plan's implementation.
Legislative subjects
Advanced technology and technological innovations; Computer security and identity theft; Computers and information technology; National Science Foundation; Research and development; Science, Technology, Communications