HR 5062 · 119th Congress

Pipeline Security Act

pipeline securitycybersecuritytransportation securitycritical infrastructurehomeland security
Share

Last action 2025-11-12

Sponsored by Rep. Johnson, Julie [D-TX-32] (D) — TX

Click any stage to learn more about the legislative process.

Would formally codify in statute the Transportation Security Administration's authority and responsibility for securing pipeline transportation and facilities against cybersecurity threats, terrorism, and other security threats — providing a legal foundation that currently rests on administrative practice rather than explicit law.

The bill would also require TSA to develop a pipeline-specific personnel and cybersecurity expertise strategy, report to Congress biennially on its pipeline security activities, and prompt a Government Accountability Office review of the law's implementation.

What this bill would do

What it would do

The bill would add a new section to the Implementing Recommendations of the 9/11 Commission Act of 2007, formally establishing TSA as the agency responsible for securing pipeline transportation and pipeline facilities against cybersecurity threats, acts of terrorism, and other security threats. TSA would be required to develop and update security guidelines consistent with the NIST Cybersecurity Framework, promulgate additional security directives or regulations as needed, share threat intelligence with relevant federal, state, local, tribal, and territorial partners, inspect critical pipeline facilities, and rank pipeline security risks. TSA would also be required to convene at least one industry stakeholder day within a year of enactment.

The bill does not itself appropriate funding. It would require TSA to submit a personnel strategy to Congress within 180 days — assessing the cybersecurity expertise and resources needed to carry out pipeline security responsibilities — and would direct the Government Accountability Office to review the law's implementation within two years. Biennial reports to designated House and Senate committees on TSA's pipeline security activities would also be required.

Key provisions

  1. 1Would formally codify TSA's statutory responsibility for securing pipeline transportation and pipeline facilities against cybersecurity threats, terrorism, and other security threats, in consultation with CISA.Sec. 2(a)
  2. 2Would require TSA to develop and update pipeline security guidelines consistent with the NIST Cybersecurity Framework and share them with relevant federal, state, local, tribal, and private-sector stakeholders.Sec. 2(a)
  3. 3Would authorize TSA to promulgate additional security directives or regulations as it determines necessary to secure pipeline transportation and facilities.Sec. 2(a)
  4. 4Would require TSA to inspect pipeline transportation and facilities, including those designated as critical by owners and operators, and rank relative security risks.Sec. 2(a)
  5. 5Would require TSA to convene at least one industry day within one year of enactment to engage pipeline stakeholders on security matters.Sec. 2(a)
  6. 6Would require TSA to develop, within 180 days, a personnel strategy assessing cybersecurity expertise needs and resources for pipeline security, and submit it to Congress.Sec. 2(c)
  7. 7Would direct the Government Accountability Office to review the implementation of the Act within two years of enactment and require biennial congressional reporting by TSA.Sec. 2(b), 2(d)

Who would be affected

The Transportation Security Administration, which would gain explicit statutory authority and new reporting and planning obligations. Owners and operators of pipeline transportation and pipeline facilities — including those designated as critical — would be subject to TSA inspection and compliance requirements. State, local, tribal, and territorial governments, as well as private-sector pipeline stakeholders, would be engaged through guidelines and industry days.

Why it matters

Pipeline operators currently face TSA security directives issued under administrative authority rather than a clear statutory mandate. Codifying TSA's role would give its security directives a firmer legal footing, potentially strengthening enforcement and creating more predictable compliance expectations. The personnel strategy requirement signals congressional intent that TSA build dedicated cybersecurity capacity for pipeline oversight — a gap critics have noted following high-profile pipeline attacks.

What would change

Changes to existing law

Amends Implementing Recommendations of the 9/11 Commission Act of 2007 (Sec. 2(a))

Adds a new Section 1559 codifying TSA's authority and specific responsibilities for pipeline security, including guidelines, inspections, directives, and stakeholder engagement.

Agencies directed to act

Transportation Security AdministrationCybersecurity and Infrastructure Security AgencyGovernment Accountability Office

Effective dates

  • TSA must convene at least one pipeline industry stakeholder daySec. 2(a)Within one year of enactment
  • TSA must develop and submit pipeline personnel strategy to CongressSec. 2(c)Within 180 days of enactment
  • GAO must complete review of the Act's implementationSec. 2(d)Within two years of enactment

Funding and costs

Congressional Budget Office estimate

CBO estimates H.R. 5062 would cost approximately $1 million in discretionary spending over the 2026–2030 period, with no effect on direct spending, revenues, or the deficit.

CBO estimates that H.R. 5062, the Pipeline Security Act, would have no effect on direct (mandatory) spending or revenues over the 2026–2035 period, leaving no change to the deficit. The bill's modest budgetary impact — about $1 million over 2026–2030 — stems from new reporting requirements for the Transportation Security Administration (TSA) and a mandated Government Accountability Office review; that spending would depend on future appropriations. CBO found no intergovernmental mandates, but identified a potential private-sector mandate: if TSA issues new pipeline security regulations under the bill, those rules would impose costs on pipeline operators, though CBO could not determine whether those costs would exceed UMRA's annual private-sector mandate threshold ($206 million in 2025).

View the full CBO cost estimate

How implementation would work

TSA would develop pipeline security guidelines in consultation with federal, state, local, tribal, and territorial partners and industry stakeholders, consistent with the NIST Cybersecurity Framework. It would inspect critical facilities, promulgate directives or regulations as needed, and share intelligence with partners. Within 180 days of enactment, TSA must submit a personnel strategy — assessing cybersecurity staffing needs and resource requirements — to relevant congressional committees. TSA would report to Congress at least biennially on its pipeline security activities. The GAO would independently review implementation within two years.

Legislative status & sources

Latest action

Placed on the Union Calendar, Calendar No. 327.

2025-11-12

Official CRS summary

Show the CRS summary

This bill provides statutory authority for the Transportation Security Administration's (TSA's) role as the agency responsible for securing pipeline transportation and pipeline facilities against cybersecurity threats, acts of terrorism, and other security threats.

The bill specifies that, among other things, the TSA must (1) develop and update pipeline security guidelines; (2) promulgate additional related security directives or regulations, as necessary; and (3) inspect pipeline transportation and pipeline facilities that are designated as critical by the owners and operators.

Under the bill, the TSA must convene at least one industry day to engage with relevant pipeline stakeholders on security-related matters.

The TSA must report to Congress biennially on its efforts to secure pipelines.

Further, the TSA must develop a personnel strategy to carry out the TSA's responsibilities for securing pipelines. The strategy must include an assessment of (1) the cybersecurity expertise necessary to secure pipelines and a plan for expanding the TSA's expertise, and (2) the resources necessary to carry out the personnel strategy.

Finally, the Government Accountability Office must conduct a review of the implementation of this bill.

From the Congressional Research Service.

Legislative subjects

Administrative law and regulatory procedures; Computer security and identity theft; Congressional oversight; Department of Transportation; Government studies and investigations; Pipelines; Transportation and Public Works; Transportation safety and security

Committee report

H. Rept. 119-376

Congressional Bill

Ask GovernmentReporter about this bill

Ask anything about this bill. The AI can look up referenced laws and statutes to provide context.

HR 5062: Pipeline Security Act | Legislation Reporter