Strengthening Cyber Resilience Against State-Sponsored Threats Act
Click any stage to learn more about the legislative process.
The bill would require the Department of Homeland Security to create an interagency task force, led by the Cybersecurity and Infrastructure Security Agency, to coordinate the federal response to Chinese state-sponsored hackers such as Volt Typhoon targeting U.S. critical infrastructure.
It would also require the task force to deliver classified reports and briefings to Congress assessing how vulnerable sectors like power, water, rail, and ports are to disruption in a potential crisis or conflict with China.
What this bill would do
What it would do
The bill would direct the Secretary of Homeland Security, acting through the Director of the Cybersecurity and Infrastructure Security Agency (CISA), to establish within 120 days a joint interagency task force to coordinate Sector Risk Management Agencies designated under National Security Memorandum-22 in detecting and responding to Chinese state-sponsored cyber actors, including the group known as Volt Typhoon. CISA would chair the task force and the FBI would serve as vice chair, with agencies required to share relevant analysis, inspections, and audits with it. The task force would have to submit an initial classified report to Congress within 540 days of its establishment, followed by annual reports for five more years and classified briefings after each report, with unclassified executive summaries posted online. The task force would be exempt from the Federal Advisory Committee Act and Paperwork Reduction Act, and would terminate 60 days after its final briefing.
Key provisions
- 1Would require DHS, through CISA, to establish an interagency task force within 120 days of enactment to coordinate response to Chinese state-sponsored cyber actors
- 2Would designate the CISA Director as chairperson and the FBI Director as vice chairperson of the task force
- 3Would require agencies to provide the task force with analysis, inspections, audits, and other relevant information, subject to security clearance requirements
- 4Would require an initial classified report to Congress within 540 days of the task force's establishment, then annual reports for five more years, plus classified briefings after each report
- 5Would require reports to assess sector-specific risks, resource needs, and potential wartime disruption to critical infrastructure and military mobility from Chinese cyber actors
- 6Would exempt the task force from the Federal Advisory Committee Act and the Paperwork Reduction Act
- 7Would terminate the task force and its authorities 60 days after its final required briefing
Who would be affected
The Department of Homeland Security, CISA, the FBI, the Department of Justice, and Sector Risk Management Agencies such as the Departments of Defense, Energy, and Agriculture would be directed to participate. Congressional committees on homeland security, judiciary, and intelligence would receive the reports, and critical infrastructure owners and operators would receive resulting security guidance.
Why it matters
Coordinated federal action could improve detection and response to intrusions like Volt Typhoon that have targeted power, water, and transportation systems. Congress would gain regular classified assessments of infrastructure vulnerabilities and potential wartime disruption, informing future funding and policy decisions, though the task force itself is temporary and advisory in nature.
What would change
Changes to existing law
Amends Federal Advisory Committee Act (5 U.S.C. ch. 10) (Sec. 2(i))
Exempts the new interagency task force from the Act's usual public transparency requirements for advisory committees
Amends Paperwork Reduction Act (44 U.S.C. ch. 35) (Sec. 2(j))
Exempts the task force from the Act's information-collection review requirements
Agencies directed to act
Effective dates
- Establishment of the interagency task force
- Submission of the task force's initial report to Congress
- Task force termination
Funding and costs
Congressional Budget Office estimate
CBO estimates H.R. 2659 would cost approximately $5 million over the 2025–2030 period in discretionary spending, with no effect on direct spending, revenues, or the deficit.
CBO estimates that H.R. 2659 would have no effect on direct (mandatory) spending or revenues, and would not increase the deficit over the 2025–2035 period. The bill's costs—roughly $5 million over 2025–2030—are discretionary (subject to appropriated funds) and would cover staff salaries, travel, and administrative expenses to operate a new interagency task force on state-sponsored cybersecurity threats, plus less than $500,000 for annual reporting to Congress. The costs fall within budget function 050 (national defense). CBO identified no intergovernmental or private-sector mandates in the bill.
How implementation would work
CISA would stand up the task force within 120 days, pulling subject-matter experts with security clearances from DHS, DOJ, FBI, and relevant Sector Risk Management Agencies. Those agencies would be obligated to share analysis, audits, and inspections with the task force. The task force would produce a classified initial report 540 days after formation, followed by five annual classified reports and post-report classified briefings to designated House and Senate committees, with unclassified executive summaries published on a DHS website. The task force would dissolve 60 days after its last briefing, and is exempted from standard advisory-committee and paperwork-review laws to streamline its operation.
Legislative status & sources
Latest action
Received in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
Official CRS summary
Show the CRS summaryHide the CRS summary
The bill creates a joint interagency task force to facilitate agency collaboration on efforts to respond to Chinese state-sponsored cyber actors, including Volt Typhoon.
The task force must be established and led by the Cybersecurity and Infrastructure Security Agency (CISA), an agency within the Department of Homeland Security (DHS). The task force must facilitate collaboration and coordination among the Sector Risk Management Agencies (SRMAs) specified in the President's National Security Memorandum- 22 (e.g., the Department of Defense, the Department of Energy, and the Department of Agriculture) to detect, analyze, and respond to Chinese state-sponsored cyber actors by ensuring that such agencies’ actions are aligned and mutually reinforcing.
The bill directs DHS, CISA, the Department of Justice, the Federal Bureau of Investigation, and specified SRMAs to provide the task force with analysis, inspections, audits, and other relevant information necessary for the task force to carry out its responsibilities. The production and use of information must comply with all applicable statutes, regulations, and executive orders, and task force members must have appropriate security clearances to access classified information.
The task force must provide annual reports and briefings to Congress detailing its assessment of cyber threats and recommendations to improve the detection and mitigation of the cybersecurity threat posed by Chinese state-sponsored cyber actors.
The first report must be provided no later than 540 days after the establishment of the task force, and additional reports must be provided annually thereafter for six years.
Legislative subjects
Asia; China; Computer security and identity theft; Congressional oversight; Federal officials; Government information and archives; Science, Technology, Communications
Committee report
H. Rept. 119-230