{"check":null,"uid":"4da29729c2a14099","title":"Strengthening Cyber Resilience Against State-Sponsored Threats Act","title_generated":false,"country":"США","organ":"Конгресс США","kind":"law","kind_name":"Законодательство","lang":"en","date":"2026-06-17","summary":"В течение 120 дней после вступления закона в силу Министерство внутренней безопасности через CISA создаёт межведомственную рабочую группу по противодействию поддерживаемым государством киберакторам КНР, включая Volt Typhoon. Председательствует директор CISA, заместителем идёт директор ФБР; в состав входят представители отраслевых агентств по управлению рисками из меморандума NSM-22. Ведомства обязаны передавать группе аналитику, проверки и аудиты; к секретным сведениям допускают только при наличии допуска. Первый доклад Конгрессу — через 540 дней, далее ежегодно пять лет, с закрытым брифингом в течение 30 дней; несекретное резюме публикуется на сайте министерства.","snippet":"","topics":["Кибербезопасность"],"status":"ok","error":"","text_len":14820,"versions":2,"url":"https://www.congress.gov/bill/119-congress/hr/2659","first_seen":"2026-08-19","last_checked":"2026-09-17 01:59","relevance":"hit","score":20,"query":"","source_key":"congress_us","verdict":{"relevance":"hit","score":20,"topics":["Кибербезопасность"],"need_body":3,"authorities":[{"kind":"орган","name":"Cybersecurity and Infrastructure Security Agency","topic":"Кибербезопасность"},{"kind":"орган","name":"CISA","topic":"Кибербезопасность"}],"evidence":[{"topic":"Кибербезопасность","term":"cybersecurity","weak":false,"pos":295,"ctx":"d cyber actors, including volt typhoon. the task force must be established and led by the cybersecurity and infrastructure security agency (cisa), an agency within the department of homeland se","zone":"текст","weight":1},{"topic":"Кибербезопасность","term":"cybersecurity","weak":false,"pos":1492,"ctx":"sment of cyber threats and recommendations to improve the detection and mitigation of the cybersecurity threat posed by chinese state-sponsored cyber actors. the first report must be provided n","zone":"текст","weight":1},{"topic":"Кибербезопасность","term":"critical infrastructure","weak":true,"pos":2272,"ctx":"__________________________  an act  to ensure the security and integrity of united states critical infrastructure by establishing an interagency task force and requiring a comprehensive report on the tar","zone":"текст","weight":0},{"topic":"Кибербезопасность","term":"critical infrastructure","weak":true,"pos":2409,"ctx":"ragency task force and requiring a comprehensive report on the targeting of united states critical infrastructure by people's republic of china state-sponsored cyber actors, and for other purposes.  be i","zone":"текст","weight":0},{"topic":"Кибербезопасность","term":"critical infrastructure","weak":true,"pos":2834,"ctx":"reats act''.  sec. 2. interagency task force and report on the targeting of united states critical infrastructure by people's republic of china state-sponsored cyber actors.  (a) interagency task force.-","zone":"текст","weight":0},{"topic":"Кибербезопасность","term":"cybersecurity","weak":false,"pos":3088,"ctx":"tment of this act, the secretary of homeland security, acting through the director of the cybersecurity and infrastructure security agency (cisa) of the department of homeland security, in cons","zone":"текст","weight":1},{"topic":"Кибербезопасность","term":"Cybersecurity and Infrastructure Security Agency","weak":false,"pos":1035,"ctx":"d cyber actors, including Volt Typhoon. The task force must be established and led by the Cybersecurity and Infrastructure Security Agency (CISA), an agency within the Department of Homeland Security (DHS). The task force must f","zone":"орган","weight":3},{"topic":"Кибербезопасность","term":"CISA","weak":false,"pos":160,"ctx":"ечение 120 дней после вступления закона в силу Министерство внутренней безопасности через CISA создаёт межведомственную рабочую группу по противодействию поддерживаемым государством ки","zone":"орган","weight":0}],"dropped":[]},"last_changed":"2026-09-11","meta":{"congress":"119","billType":"HR","number":"2659","policyArea":"Science, Technology, Communications","subjects":["Asia","China","Computer security and identity theft","Congressional oversight","Federal officials","Government information and archives"],"latestAction":"2026-05-19 Read twice and referred to the Committee on Homeland Security and Governmental Affairs.","textVersion":"rfs"},"source_url":"https://www.congress.gov/bill/119-congress/hr/2659","text":"SUMMARY\nStrengthening Cyber Resilience Against State-Sponsored Threats Act\nThe bill creates a joint interagency task force to facilitate agency collaboration on efforts to respond to Chinese state-sponsored cyber actors, including Volt Typhoon.\nThe task force must be established and led by the Cybersecurity and Infrastructure Security Agency (CISA), an agency within the Department of Homeland Security (DHS). The task force must facilitate collaboration and coordination among the Sector Risk Management Agencies (SRMAs) specified in the President's National Security Memorandum- 22 (e.g., the Department of Defense, the Department of Energy, and the Department of Agriculture) to detect, analyze, and respond to Chinese state-sponsored cyber actors by ensuring that such agencies’ actions are aligned and mutually reinforcing.\nThe bill directs DHS, CISA, the Department of Justice, the Federal Bureau of Investigation, and specified SRMAs to provide the task force with analysis, inspections, audits, and other relevant information necessary for the task force to carry out its responsibilities. The production and use of information must comply with all applicable statutes, regulations, and executive orders, and task force members must have appropriate security clearances to access classified information.\nThe task force must provide annual reports and briefings to Congress detailing its assessment of cyber threats and recommendations to improve the detection and mitigation of the cybersecurity threat posed by Chinese state-sponsored cyber actors.\nThe first report must be provided no later than 540 days after the establishment of the task force, and additional reports must be provided annually thereafter for six years.\n\nFULL TEXT\n[Congressional Bills 119th Congress]\n[From the U.S. Government Publishing Office]\n[H.R. 2659 Referred in Senate (RFS)]\n\n<DOC>\n119th CONGRESS\n1st Session\nH. R. 2659\n\n_______________________________________________________________________\n\nIN THE SENATE OF THE UNITED STATES\n\nNovember 18, 2025\n\nReceived; read twice and referred to the Committee on Homeland\nSecurity and Governmental Affairs\n\n_______________________________________________________________________\n\nAN ACT\n\nTo ensure the security and integrity of United States critical\ninfrastructure by establishing an interagency task force and requiring\na comprehensive report on the targeting of United States critical\ninfrastructure by People's Republic of China state-sponsored cyber\nactors, and for other purposes.\n\nBe it enacted by the Senate and House of Representatives of the\nUnited States of America in Congress assembled,\n\nSECTION 1. SHORT TITLE.\n\nThis Act may be cited as the ``Strengthening Cyber Resilience\nAgainst State-Sponsored Threats Act''.\n\nSEC. 2. INTERAGENCY TASK FORCE AND REPORT ON THE TARGETING OF UNITED\nSTATES CRITICAL INFRASTRUCTURE BY PEOPLE'S REPUBLIC OF\nCHINA STATE-SPONSORED CYBER ACTORS.\n\n(a) Interagency Task Force.--Not later than 120 days after the date\nof the enactment of this Act, the Secretary of Homeland Security,\nacting through the Director of the Cybersecurity and Infrastructure\nSecurity Agency (CISA) of the Department of Homeland Security, in\nconsultation with the Attorney General, the Director of the Federal\nBureau of Investigation, and the heads of appropriate Sector Risk\nManagement Agencies as determined by the Director of CISA, shall\nestablish a joint interagency task force (in this section referred to\nas the ``task force'') to facilitate collaboration and coordination\namong the Sector Risk Management Agencies assigned a Federal role or\nresponsibility in National Security Memorandum-22, issued April 30,\n2024 (relating to critical infrastructure security and resilience), or\nany successor document, to detect, analyze, and respond to the\ncybersecurity threat posed by State-sponsored cyber actors, including\nVolt Typhoon, of the People's Republic of China by ensuring that such\nagencies' actions are aligned and mutually reinforcing.\n(b) Chairs.--\n(1) Chairperson.--The Director of CISA (or the Director of\nCISA's designee) shall serve as the chairperson of the task\nforce.\n(2) Vice chairperson.--The Director of the Federal Bureau\nof Investigation (or such Director's designee) shall serve as\nthe vice chairperson of the task force.\n(c) Composition.--\n(1) In general.--The task force shall consist of\nappropriate representatives of the departments and agencies\nspecified in subsection (a).\n(2) Qualifications.--To materially assist in the activities\nof the task force, representatives under paragraph (1) should\nbe subject matter experts who have familiarity and technical\nexpertise regarding cybersecurity, digital forensics, or threat\nintelligence analysis, or in-depth knowledge of the tactics,\ntechniques, and procedures (TTPs) commonly used by State-\nsponsored cyber actors, including Volt Typhoon, of the People's\nRepublic of China.\n(d) Vacancy.--Any vacancy occurring in the membership of the task\nforce shall be filled in the same manner in which the original\nappointment was made.\n(e) Establishment Flexibility.--To avoid redundancy, the task force\nmay coordinate with any preexisting task force, working group, or\ncross-intelligence effort within the Homeland Security Enterprise or\nthe intelligence community that has examined or responded to the\ncybersecurity threat posed by State-sponsored cyber actors, including\nVolt Typhoon, of the People's Republic of China.\n(f) Task Force Reports; Briefing.--\n(1) Initial report.--Not later than 540 days after the\nestablishment of the task force, the task force shall submit to\nthe appropriate congressional committees the first report\ncontaining the initial findings, conclusions, and\nrecommendations of the task force.\n(2) Annual report.--Not later than one year after the date\nof the submission of the initial report under paragraph (1) and\nannually thereafter for five years, the task force shall submit\nto the appropriate congressional committees an annual report\ncontaining the findings, conclusions, and recommendations of\nthe task force.\n(3) Contents.--The reports under this subsection shall\ninclude the following:\n(A) An assessment at the lowest classification\nfeasible of the sector-specific risks, trends relating\nto incidents impacting sectors, and tactics,\ntechniques, and procedures utilized by or relating to\nState-sponsored cyber actors, including Volt Typhoon,\nof the People's Republic of China.\n(B) An assessment of additional resources and\nauthorities needed by Federal departments and agencies\nto better counter the cybersecurity threat posed by\nState-sponsored cyber actors, including Volt Typhoon,\nof the People's Republic of China.\n(C) A classified assessment of the extent of\npotential destruction, compromise, or disruption to\nUnited States critical infrastructure by State-\nsponsored cyber actors, including Volt Typhoon, of the\nPeople's Republic of China in the event of a major\ncrisis or future conflict between the People's Republic\nof China and the United States.\n(D) A classified assessment of the ability of the\nUnited States to counter the cybersecurity threat posed\nby State-sponsored cyber actors, including Volt\nTyphoon, of the People's Republic of China in the event\nof a major crisis or future conflict between the\nPeople's Republic of China and the United States,\nincluding with respect to different cybersecurity\nmeasures and recommendations that could mitigate such a\nthreat.\n(E) A classified assessment of the ability of\nState-sponsored cyber actors, including Volt Typhoon,\nof the People's Republic of China to disrupt operations\nof the United States Armed Forces by hindering mobility\nacross critical infrastructure such as rail, aviation,\nand ports, including how such would impair the ability\nof the United States Armed Forces to deploy and\nmaneuver forces effectively.\n(F) A classified assessment of the economic and\nsocial ramifications of a disruption to one or multiple\nUnited States critical infrastructure sectors by State-\nsponsored cyber actors, including Volt Typhoon, of the\nPeople's Republic of China in the event of a major\ncrisis or future conflict between the People's Republic\nof China and the United States.\n(G) Such recommendations as the task force may have\nfor the Homeland Security Enterprise, the intelligence\ncommunity, or critical infrastructure owners and\noperators to improve the detection and mitigation of\nthe cybersecurity threat posed by State-sponsored cyber\nactors, including Volt Typhoon, of the People's\nRepublic of China.\n(H) A one-time plan for an awareness campaign to\nfamiliarize critical infrastructure owners and\noperators with security resources and support offered\nby Federal departments and agencies to mitigate the\ncybersecurity threat posed by State-sponsored cyber\nactors, including Volt Typhoon, of the People's\nRepublic of China.\n(4) Briefing.--Not later than 30 days after the date of the\nsubmission of each report under this subsection, the task force\nshall provide to the appropriate congressional committees a\nclassified briefing on the findings, conclusions, and\nrecommendations of the task force.\n(5) Form.--Each report under this subsection shall be\nsubmitted in classified form, consistent with the protection of\nintelligence sources and methods, but may include an\nunclassified executive summary.\n(6) Publication.--The unclassified executive summary of\neach report required under this subsection shall be published\non a publicly accessible website of the Department of Homeland\nSecurity.\n(g) Access to Information.--\n(1) In general.--The Secretary of Homeland Security, the\nDirector of CISA, the Attorney General, the Director of the\nFederal Bureau of Investigation, and the heads of appropriate\nSector Risk Management Agencies, as determined by the Director\nof CISA, shall provide to the task force such information,\ndocuments, analysis, assessments, findings, evaluations,\ninspections, audits, or reviews relating to efforts to counter\nthe cybersecurity threat posed by State-sponsored cyber actors,\nincluding Volt Typhoon, of the People's Republic of China as\nthe task force considers necessary to carry out this section.\n(2) Receipt, handling, storage, and dissemination.--\nInformation, documents, analysis, assessments, findings,\nevaluations, inspections, audits, and reviews described in this\nsubsection shall be received, handled, stored, and disseminated\nonly by members of the task force consistent with all\napplicable statutes, regulations, and Executive orders.\n(3) Security clearances for task force members.--No member\nof the task force may be provided with access to classified\ninformation under this section without the appropriate security\nclearances.\n(h) Termination.--The task force, and all the authorities of this\nsection, shall terminate on the date that is 60 days after the final\nbriefing required under subsection (h)(4).\n(i) Exemption From FACA.--Chapter 10 of title 5, United States Code\n(commonly referred to as the ``Federal Advisory Committee Act''), shall\nnot apply to the task force.\n(j) Exemption From Paperwork Reduction Act.--Chapter 35 of title\n44, United States Code (commonly known as the ``Paperwork Reduction\nAct''), shall not apply to the task force.\n(k) Definitions.--In this section:\n(1) Appropriate congressional committees.--The term\n``appropriate congressional committees'' means--\n(A) the Committee on Homeland Security, the\nCommittee on Judiciary, and the Select Committee on\nIntelligence of the House of Representatives; and\n(B) the Committee on Homeland Security and\nGovernmental Affairs, the Committee on Judiciary, and\nthe Select Committee on Intelligence of the Senate.\n(2) Assets.--The term ``assets'' means a person, structure,\nfacility, information, material, equipment, network, or\nprocess, whether physical or virtual, that enables an\norganization's services, functions, or capabilities.\n(3) Critical infrastructure.--The term ``critical\ninfrastructure'' has the meaning given such term in section\n1016(e) of Public Law 107-56 (42 U.S.C. 5195c(e)).\n(4) Cybersecurity threat.--The term ``cybersecurity\nthreat'' has the meaning given such term in section 2200 of the\nHomeland Security Act of 2002 (6 U.S.C. 650).\n(5) Homeland security enterprise.--The term ``Homeland\nSecurity Enterprise'' has the meaning given such term in\nsection 2200 of the Homeland Security Act of 2002 (6 U.S.C.\n650).\n(6) Incident.--The term ``incident'' has the meaning given\nsuch term in section 2200 of the Homeland Security Act of 2002\n(6 U.S.C. 650).\n(7) Information sharing.--The term ``information sharing''\nmeans the bidirectional sharing of timely and relevant\ninformation concerning a cybersecurity threat posed by a State-\nsponsored cyber actor of the People's Republic of China to\nUnited States critical infrastructure.\n(8) Intelligence community.--The term ``intelligence\ncommunity'' has the meaning given such term in section 3(4) of\nthe National Security Act of 1947 (50 U.S.C. 3003(4)).\n(9) Locality.--The term ``locality'' means any local\ngovernment authority or agency or component thereof within a\nState having jurisdiction over matters at a county, municipal,\nor other local government level.\n(10) Sector.--The term ``sector'' means a collection of\nassets, systems, networks, entities, or organizations that\nprovide or enable a common function for national security\n(including national defense and continuity of Government),\nnational economic security, national public health or safety,\nor any combination thereof.\n(11) Sector risk management agency.--The term ``Sector Risk\nManagement Agency'' has the meaning given such term in section\n2200 of the Homeland Security Act of 2002 (6 U.S.C. 650).\n(12) State.--The term ``State'' means any State of the\nUnited States, the District of Columbia, the Commonwealth of\nPuerto Rico, the Northern Mariana Islands, the United States\nVirgin Islands, Guam, American Samoa, and any other territory\nor possession of the United States.\n(13) Systems.--The term ``systems'' means a combination of\npersonnel, structures, facilities, information, materials,\nequipment, networks, or processes, whether physical or virtual,\nintegrated or interconnected for a specific purpose that\nenables an organization's services, functions, or capabilities.\n(14) United states.--The term ``United States'', when used\nin a geographic sense, means any State of the United States.\n(15) Volt typhoon.--The term ``Volt Typhoon'' means the\nPeople's Republic of China State-sponsored cyber actor\ndescribed in the Cybersecurity and Infrastructure Security\nAgency cybersecurity advisory entitled ``PRC State-Sponsored\nActors Compromise and Maintain Persistent Access to U.S.\nCritical Infrastructure'', issued on February 07, 2024, or any\nsuccessor advisory.\n\nPassed the House of Representatives November 17, 2025.\n\nAttest:\n\nKEVIN F. MCCUMBER,\n\nClerk.","changes":[{"id":597,"doc_id":97,"v_from":335,"v_to":13681,"detected_at":"2026-09-11 02:52:08","added":16,"removed":17,"summary":"--- \n+++ \n-[H.R. 2659 Introduced in House (IH)]\n+[H.R. 2659 Referred in Senate (RFS)]\n-\n-To ensure the security and integrity of United States critical\n-infrastructure by establishing an interagency task force and requiring\n-a comprehensive report on the targeting of United States critical\n-infrastructure by People's Republic of China state-sponsored cyber\n-actors, and for other purposes.\n-\n-IN THE HOUSE OF REPRESENTATIVES\n-\n-April 7, 2025\n-\n-Mr. Ogles (for himself, Mr. Green of Tennessee, Ms. Lee of Florida, Mr.\n-Moolenaar, and Mr. Garbarino) introduced the following bill; which was\n-referred to the Committee on Homeland Security\n+IN THE SENATE OF THE UNITED STATES\n+\n+November 18, 2025\n+\n+Received; read twice and referred to the Committee on Homeland\n+Security and Governmental Affairs\n-A BILL\n+AN ACT\n-<all>\n+\n+Passed the House of Representatives November 17, 2025.\n+\n+Attest:\n+\n+KEVIN F. MCCUMBER,\n+\n+Clerk."}],"passport":{"data":{"act":{"jurisdiction":"США","title_official":"Strengthening Cyber Resilience Against State-Sponsored Threats Act","title_short":"","level":"Закон","date_adopted":"2025-11-17","date_in_force":"120 дней после принятия","date_version":"последняя","phased":"","status":"действует","sunset":"","regulator":"Министерство внутренней безопасности через CISA","related":""},"goal":{"problem":"обеспечение безопасности критической инфраструктуры США от угроз со стороны поддерживаемых государством киберопераций Китая","goal":"создание межведомственной рабочей группы для координации действий федеральных ведомств по выявлению и реагированию на угрозы со стороны китайских киберугроз","targets":"отсутствуют","scope":"федеральные ведомства, ответственные за управление рисками критической инфраструктуры","exclusions":"отсутствует"},"subjects_note":{"protected":"отсутствует"},"subjects":[{"role":"госорган","who":"Министерство внутренней безопасности, CISA, DOJ, FBI, SRMAs","criteria":"указанные прямо в акте","count":"нет данных"}],"norms":[{"address":"секция 2 п. g","addressee":"госорган","essence":"предоставить информацию и документы, необходимые для работы межведомственной рабочей группы","type":"обязанность","mechanism":"предоставление информации и документов","cost_channel":"административный","cost_kind":"разовый","trigger":"запрос группы","sanction":"отсутствует","refs":"","form":"цифровая","in_force":"одновременно с созданием группы","ru_analog":"отсутствует"}]},"made_by":"GigaChat-2","made_at":"2026-09-16 07:25:38","edited_at":null,"edited_by":null}}