HR 5078 · 119th Congress

PILLAR Act

cybersecuritystate and local governmentartificial intelligencecritical infrastructurefederal grants
Share

Last action 2025-11-18

Sponsored by Rep. Ogles, Andrew [R-TN-5] (R) — TN

Click any stage to learn more about the legislative process.

Would reauthorize and expand the State and Local Cybersecurity Grant Program — which funds state, tribal, and local government cybersecurity improvements — through 2033, while broadening eligible uses to cover operational technology and artificial intelligence systems.

It would also restrict purchases of technology that conflicts with federal cybersecurity guidance or comes from foreign entities of concern, and would reward governments that adopt multifactor authentication early with a higher federal cost share.

What this bill would do

What it would do

The bill would reauthorize the State and Local Cybersecurity Grant Program through fiscal year 2033 and expand the types of systems that grant funds can protect to include operational technology systems and systems using artificial intelligence, in addition to the existing information technology systems. It would bar grant recipients from using funds to purchase software or hardware that does not align with CISA guidance — including "Secure by Design" guidance — or that is designed or sold by a foreign entity of concern. It would increase the federal cost share to 65 percent (or 75 percent for multi-entity groups) for entities that implement multifactor authentication and identity and access management tools for critical infrastructure by October 1, 2027. It would also require CISA to develop an outreach plan to inform local governments — including rural and small-population jurisdictions — about no-cost cybersecurity services.

The bill would not appropriate a specific dollar amount; all activities remain subject to available appropriations. It would also require the Government Accountability Office to review the program every three years, including reviewing artificial intelligence adoption across a sample of grants, and would require grant recipients' annual reports to describe plans for sustaining cybersecurity programs after grant funding is exhausted.

Key provisions

  1. 1Would reauthorize the State and Local Cybersecurity Grant Program through fiscal year 2033 and extend the planning period from two to three years.Sec. 2
  2. 2Would expand eligible uses of grant funds to include securing operational technology systems and systems using artificial intelligence, in addition to information technology systems.Sec. 2
  3. 3Would prohibit use of grant funds to purchase software or hardware not aligned with CISA guidance or produced by a foreign entity of concern.Sec. 2
  4. 4Would increase the federal cost share to 65 percent (75 percent for multi-entity groups) for eligible entities that implement multifactor authentication and identity and access management tools for critical infrastructure by October 1, 2027.Sec. 2
  5. 5Would require GAO to review the program every three years, including a review of artificial intelligence adoption across a sample of grants.Sec. 2
  6. 6Would require CISA to implement an outreach plan informing local governments — including rural and small-population jurisdictions — about no-cost cybersecurity service offerings.Sec. 2
  7. 7Would require annual reports from grant recipients to describe progress toward assuming the cost of continuing cybersecurity programs after grant funds are fully expended.Sec. 2

Who would be affected

State governments, Indian tribes, and local governments that receive or seek federal cybersecurity grants; rural and small-population local governments that would gain targeted outreach about no-cost CISA services; technology vendors whose products must align with CISA guidance to be purchasable with grant funds; and CISA and the Government Accountability Office, which would carry out new administrative, outreach, and oversight duties.

Why it matters

State and local governments often manage critical infrastructure — water systems, emergency services, election systems — on tight budgets and aging technology. Extending the grant program through 2033 and covering operational technology and AI systems broadens protection for those assets. The new purchasing restrictions would limit use of technology from foreign adversary-linked vendors, while the MFA incentive bonus is designed to push governments toward stronger credential security before a 2027 deadline.

What would change

Changes to existing law

Amends Homeland Security Act of 2002, Section 2220A (6 U.S.C. 665g) (Sec. 2)

Reauthorizes, expands scope, adds AI and OT systems, restricts purchases from foreign entities of concern, adjusts cost-share rules, adds GAO review, and extends authorization through 2033.

Agencies directed to act

Cybersecurity and Infrastructure Security AgencyDepartment of Homeland SecurityGovernment Accountability Office

Effective dates

  • Deadline for implementing MFA and identity management tools to qualify for increased federal cost shareSec. 22027-10-01
  • Program authorization period endsSec. 2Fiscal year 2033
  • First GAO review of the program dueSec. 2Within 3 years of enactment

Funding and costs

Congressional Budget Office estimate

CBO estimates that implementing H.R. 5078 (the PILLAR Act) would cost $869 million over the 2025–2030 period in discretionary spending subject to appropriation, with no effect on direct spending, revenues, or the deficit.

CBO estimates that H.R. 5078 would require $869 million in discretionary spending (funding that Congress must separately appropriate) over the 2025–2030 period, with zero effect on direct (mandatory) spending, revenues, or the deficit. The main cost drivers are continuing DHS cybersecurity grants to state and local governments at roughly $250 million per year ($766 million in outlays over the period) and approximately $103 million for DHS management, oversight, and administrative functions; a required Comptroller General review would cost less than $500,000. CBO found no intergovernmental or private-sector mandates in the bill.

View the full CBO cost estimate

How implementation would work

CISA would administer the reauthorized grant program, accepting applications from states and tribes that develop cybersecurity plans meeting updated requirements. Grant recipients must submit annual reports — now including a description of how they plan to absorb program costs after federal funds run out. States must distribute funds to local governments within 60 days; if they fail to do so, local governments may petition the Secretary of Homeland Security for direct disbursement. The GAO would conduct a full program review within three years of enactment and every three years thereafter. CISA must also implement a dedicated outreach plan to reach rural and small-population local governments about no-cost federal cybersecurity offerings.

Legislative status & sources

Latest action

Received in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs.

2025-11-18

Official CRS summary

Show the CRS summary

This bill extends the State and Local Cybersecurity Grant Program through FY2035, expands the scope of the program, and imposes certain limits on the use of grant funds. (The program provides grants to states and Indian tribes to address cybersecurity risks to government information systems.)

The bill expands the scope of systems that may be secured using grant funds to include operational technology systems and specifies that systems using artificial intelligence are included. Such systems must be maintained, owned, or operated by or on behalf of state, local, or tribal governments.

The bill also specifies that grant funds may not be used to purchase software, hardware, or related products or services that do not align with relevant guidance provided by the Cybersecurity and Infrastructure Security Agency (CISA).

Further, the bill increases the federal share of costs available to entities that implement or enable multifactor authentication and identity and access management tools for critical infrastructure by a specified date.

The bill requires annual reports by grant recipients to include a description of recipients’ progress in assuming the cost of continuing cybersecurity programs after grant funds are fully expended.

The Government Accountability Office must periodically review the program. This effort must include a review of artificial intelligence adoption across a sample of grants.

Finally, CISA must implement an outreach plan to inform local governments, including governments in rural areas or areas with small populations, about CISA’s no-cost cybersecurity offerings.

From the Congressional Research Service.

Legislative subjects

Advanced technology and technological innovations; Computer security and identity theft; Computers and information technology; Congressional oversight; Government information and archives; Government lending and loan guarantees; Government studies and investigations; Internet, web applications, social media; Science, Technology, Communications; State and local government operations

Committee report

H. Rept. 119-377

Congressional Bill

Ask GovernmentReporter about this bill

Ask anything about this bill. The AI can look up referenced laws and statutes to provide context.

HR 5078: PILLAR Act | Legislation Reporter