ANCHOR Act
Click any stage to learn more about the legislative process.
Would require the National Science Foundation to develop and submit to Congress, within one year, a comprehensive plan to upgrade the cybersecurity and telecommunications infrastructure of the U.S. Academic Research Fleet — the network of university-operated oceanographic vessels that support federally funded marine science.
What this bill would do
What it would do
The bill would direct the NSF Director, in consultation with relevant federal agencies, universities, and laboratories, to produce a detailed plan for improving the cybersecurity and telecommunications capabilities of the U.S. Academic Research Fleet (ARF) — U.S.-flagged research vessels operated by universities and national laboratories under the University-National Oceanographic Laboratory System. The plan would have to assess telecom and networking needs, cybersecurity needs (developed with CISA and NIST), estimated costs including equipment and personnel, and the time required to implement upgrades under varying funding scenarios. It would also need to propose common or consortial technology solutions, and include a spending plan distributing costs among NSF, the Office of Naval Research, non-federal vessel owners, and fleet users.
The bill would not itself fund any upgrades or mandate any specific technology purchases. Its sole operative requirement is the production and congressional submission of the planning document; whether and how agencies act on the plan's recommendations would be left to future action.
Key provisions
- 1Would require the NSF Director to submit a cybersecurity and telecommunications improvement plan for the U.S. Academic Research Fleet to relevant congressional committees within one year of enactment.
- 2Would require the plan to assess telecom and networking needs for the fleet's scientific missions, including speed and bandwidth targets for data upload, telemedicine, and remote expert participation.
- 3Would require the plan to include, in consultation with CISA and NIST, an assessment of cybersecurity needs appropriate to vessel ownership and scientific missions.
- 4Would require the plan to assess equipment, software, and personnel costs — including training and logistics — needed to meet identified telecom and cybersecurity needs.
- 5Would require the plan to include a spending plan allocating identified costs among NSF, the Office of Naval Research, non-federal vessel owners, and fleet users.
- 6Would require the Director to consider the 2021 JASON advisory report on NSF facility cybersecurity, international information security standards, and requirements for controlled unclassified or classified information.
Who would be affected
The NSF Director and NSF staff who must produce the plan; CISA and NIST officials who must be consulted; the Office of Naval Research; universities and national laboratories that own or operate ARF vessels; and the oceanographic scientists, educators, and students who use those vessels for federally funded marine research.
Why it matters
If the plan is completed and acted upon, research vessel operators could receive clearer guidance and a coordinated funding framework for modernizing shipboard communications, data management, and cybersecurity — capabilities that affect both the safety of crews and the scientific value of at-sea missions. Until the plan is produced, the bill itself changes nothing operationally.
What would change
Agencies directed to act
Effective dates
- Deadline for NSF Director to submit the cybersecurity and telecommunications plan to Congress
Funding and costs
Congressional Budget Office estimate
CBO estimates that S. 318, the ANCHOR Act, would cost less than $500,000 over the 2025–2030 period, with no effect on direct spending, revenues, or the deficit.
CBO estimates that enacting the ANCHOR Act would have no effect on direct (mandatory) spending, revenues, or the deficit over the 2025–2030 and 2025–2035 scoring windows. The bill would require the National Science Foundation (NSF) to develop a cybersecurity and telecommunications improvement plan for the 17 vessels of the U.S. Academic Research Fleet and report to Congress within one year of enactment; CBO estimates this would cost less than $500,000 over 2025–2030, subject to the availability of appropriated (discretionary) funds. CBO identified no intergovernmental or private-sector mandates in the bill.
How implementation would work
The NSF Director must consult with federal agency heads, universities, and labs that own or operate ARF vessels while preparing the plan. Cybersecurity assessments must be developed with CISA and NIST and must consider the JASON advisory group's 2021 report on NSF facility cybersecurity. The spending-plan element requires additional consultation with non-federal vessel owners. The completed plan must be submitted to the Senate Committee on Commerce, Science, and Transportation and the House Committee on Science, Space, and Technology within one year of enactment. No rulemaking, grant cycle, or enforcement mechanism is established by the bill itself.
Legislative status & sources
Latest action
Held at the desk.
Official CRS summary
Show the CRS summaryHide the CRS summary
This bill requires the National Science Foundation (NSF) to develop a plan to improve the cybersecurity and telecommunications capabilities of the U.S. Academic Research Fleet (ARF).
ARF is comprised of U.S.-flagged vessels that provide at-sea laboratories where oceanographic scientists, educators, and students research and learn about marine science.
The bill requires the plan to include assessments of
- telecommunications and networking needs of ARF, consistent with typical scientific missions;
- cybersecurity needs appropriate for the ownership of ARF vessels and their typical research functions;
- the costs necessary to meet these needs; and
- the time required to implement necessary upgrades.
The plan must also include (1) a spending plan for the NSF, the Office of Naval Research, nonfederal owners of ARF vessels, and users of the vessels to cover identified costs; and (2) a proposal regarding the adoption of common solutions or consortial licensing agreements, or the centralization of cybersecurity, telecommunications, or data management at a single facility.
Among other factors specified in the bill, the NSF must consider the network capabilities necessary to meet mission needs (e.g., to upload data to shoreside servers), international standards and guidance for information security, and requirements for controlled unclassified or classified information.
The plan must be provided to Congress within one year of the bill's enactment.
Legislative subjects
Advanced technology and technological innovations; Computer security and identity theft; Computers and information technology; National Science Foundation; Research and development; Science, Technology, Communications
Committee report
S. Rept. 119-64