Пульс · Документы · США · Конгресс США
H.R. 2659, Закон об укреплении киберустойчивости к угрозам, спонсируемым государством
Strengthening Cyber Resilience Against State-Sponsored Threats Act
SUMMARY
Strengthening Cyber Resilience Against State-Sponsored Threats Act
The bill creates a joint interagency task force to facilitate agency collaboration on efforts to respond to Chinese state-sponsored cyber actors, including Volt Typhoon.
The task force must be established and led by the Cybersecurity and Infrastructure Security Agency (CISA), an agency within the Department of Homeland Security (DHS). The task force must facilitate collaboration and coordination among the Sector Risk Management Agencies (SRMAs) specified in the President's National Security Memorandum- 22 (e.g., the Department of Defense, the Department of Energy, and the Department of Agriculture) to detect, analyze, and respond to Chinese state-sponsored cyber actors by ensuring that such agencies’ actions are aligned and mutually reinforcing.
The bill directs DHS, CISA, the Department of Justice, the Federal Bureau of Investigation, and specified SRMAs to provide the task force with analysis, inspections, audits, and other relevant information necessary for the task force to carry out its responsibilities. The production and use of information must comply with all applicable statutes, regulations, and executive orders, and task force members must have appropriate security clearances to access classified information.
The task force must provide annual reports and briefings to Congress detailing its assessment of cyber threats and recommendations to improve the detection and mitigation of the cybersecurity threat posed by Chinese state-sponsored cyber actors.
The first report must be provided no later than 540 days after the establishment of the task force, and additional reports must be provided annually thereafter for six years.
FULL TEXT
[Congressional Bills 119th Congress] [From the U.S. Government Publishing Office] [H.R. 2659 Referred in Senate (RFS)]
<DOC> 119th CONGRESS 1st Session H. R. 2659
IN THE SENATE OF THE UNITED STATES
November 18, 2025
Received; read twice and referred to the Committee on Homeland Security and Governmental Affairs
AN ACT
To ensure the security and integrity of United States critical infrastructure by establishing an interagency task force and requiring a comprehensive report on the targeting of United States critical infrastructure by People's Republic of China state-sponsored cyber actors, and for other purposes.
Be it enacted by the Senate and House of Representatives of the United States of America in Congress assembled,
SECTION 1. SHORT TITLE.
This Act may be cited as the ``Strengthening Cyber Resilience Against State-Sponsored Threats Act''.
SEC. 2. INTERAGENCY TASK FORCE AND REPORT ON THE TARGETING OF UNITED STATES CRITICAL INFRASTRUCTURE BY PEOPLE'S REPUBLIC OF CHINA STATE-SPONSORED CYBER ACTORS.
(a) Interagency Task Force.--Not later than 120 days after the date of the enactment of this Act, the Secretary of Homeland Security, acting through the Director of the Cybersecurity and Infrastructure
Security Agency (CISA) of the Department of Homeland Security, in consultation with the Attorney General, the Director of the Federal
Bureau of Investigation, and the heads of appropriate Sector Risk
Management Agencies as determined by the Director of CISA, shall establish a joint interagency task force (in this section referred to as the ``task force'') to facilitate collaboration and coordination among the Sector Risk Management Agencies assigned a Federal role or responsibility in National Security Memorandum-22, issued April 30, 2024 (relating to critical infrastructure security and resilience), or any successor document, to detect, analyze, and respond to the cybersecurity threat posed by State-sponsored cyber actors, including
Volt Typhoon, of the People's Republic of China by ensuring that such agencies' actions are aligned and mutually reinforcing.
(b) Chairs.--
(1) Chairperson.--The Director of CISA (or the Director of CISA's designee) shall serve as the chairperson of the task force.
(2) Vice chairperson.--The Director of the Federal Bureau of Investigation (or such Director's designee) shall serve as the vice chairperson of the task force.
(c) Composition.--
(1) In general.--The task force shall consist of appropriate representatives of the departments and agencies specified in subsection (a).
(2) Qualifications.--To materially assist in the activities of the task force, representatives under paragraph (1) should be subject matter experts who have familiarity and technical expertise regarding cybersecurity, digital forensics, or threat intelligence analysis, or in-depth knowledge of the tactics, techniques, and procedures (TTPs) commonly used by Statesponsored cyber actors, including Volt Typhoon, of the People's Republic of China.
(d) Vacancy.--Any vacancy occurring in the membership of the task force shall be filled in the same manner in which the original appointment was made.
(e) Establishment Flexibility.--To avoid redundancy, the task force may coordinate with any preexisting task force, working group, or cross-intelligence effort within the Homeland Security Enterprise or the intelligence community that has examined or responded to the cybersecurity threat posed by State-sponsored cyber actors, including
Volt Typhoon, of the People's Republic of China.
(f) Task Force Reports; Briefing.--
(1) Initial report.--Not later than 540 days after the establishment of the task force, the task force shall submit to the appropriate congressional committees the first report containing the initial findings, conclusions, and recommendations of the task force.
(2) Annual report.--Not later than one year after the date of the submission of the initial report under paragraph (1) and annually thereafter for five years, the task force shall submit to the appropriate congressional committees an annual report containing the findings, conclusions, and recommendations of the task force.
(3) Contents.--The reports under this subsection shall include the following:
(A) An assessment at the lowest classification feasible of the sector-specific risks, trends relating to incidents impacting sectors, and tactics, techniques, and procedures utilized by or relating to State-sponsored cyber actors, including Volt Typhoon, of the People's Republic of China.
(B) An assessment of additional resources and authorities needed by Federal departments and agencies to better counter the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People's Republic of China.
(C) A classified assessment of the extent of potential destruction, compromise, or disruption to United States critical infrastructure by Statesponsored cyber actors, including Volt Typhoon, of the People's Republic of China in the event of a major crisis or future conflict between the People's Republic of China and the United States.
(D) A classified assessment of the ability of the United States to counter the cybersecurity threat posed by State-sponsored cyber actors, including Volt
Typhoon, of the People's Republic of China in the event of a major crisis or future conflict between the People's Republic of China and the United States, including with respect to different cybersecurity measures and recommendations that could mitigate such a threat.
(E) A classified assessment of the ability of State-sponsored cyber actors, including Volt Typhoon, of the People's Republic of China to disrupt operations of the United States Armed Forces by hindering mobility across critical infrastructure such as rail, aviation, and ports, including how such would impair the ability of the United States Armed Forces to deploy and maneuver forces effectively.
(F) A classified assessment of the economic and social ramifications of a disruption to one or multiple
United States critical infrastructure sectors by Statesponsored cyber actors, including Volt Typhoon, of the People's Republic of China in the event of a major crisis or future conflict between the People's Republic of China and the United States.
(G) Such recommendations as the task force may have for the Homeland Security Enterprise, the intelligence community, or critical infrastructure owners and operators to improve the detection and mitigation of the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People's Republic of China.
(H) A one-time plan for an awareness campaign to familiarize critical infrastructure owners and operators with security resources and support offered by Federal departments and agencies to mitigate the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People's Republic of China.
(4) Briefing.--Not later than 30 days after the date of the submission of each report under this subsection, the task force shall provide to the appropriate congressional committees a classified briefing on the findings, conclusions, and recommendations of the task force.
(5) Form.--Each report under this subsection shall be submitted in classified form, consistent with the protection of intelligence sources and methods, but may include an unclassified executive summary.
(6) Publication.--The unclassified executive summary of each report required under this subsection shall be published on a publicly accessible website of the Department of Homeland
Security.
(g) Access to Information.--
(1) In general.--The Secretary of Homeland Security, the Director of CISA, the Attorney General, the Director of the Federal Bureau of Investigation, and the heads of appropriate
Sector Risk Management Agencies, as determined by the Director of CISA, shall provide to the task force such information, documents, analysis, assessments, findings, evaluations, inspections, audits, or reviews relating to efforts to counter the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People's Republic of China as the task force considers necessary to carry out this section.
(2) Receipt, handling, storage, and dissemination.-- Information, documents, analysis, assessments, findings, evaluations, inspections, audits, and reviews described in this subsection shall be received, handled, stored, and disseminated only by members of the task force consistent with all applicable statutes, regulations, and Executive orders.
(3) Security clearances for task force members.--No member of the task force may be provided with access to classified information under this section without the appropriate security clearances.
(h) Termination.--The task force, and all the authorities of this section, shall terminate on the date that is 60 days after the final briefing required under subsection (h)(4).
(i) Exemption From FACA.--Chapter 10 of title 5, United States Code (commonly referred to as the ``Federal Advisory Committee Act''), shall not apply to the task force.
(j) Exemption From Paperwork Reduction Act.--Chapter 35 of title
44, United States Code (commonly known as the ``Paperwork Reduction
Act''), shall not apply to the task force.
(k) Definitions.--In this section:
(1) Appropriate congressional committees.--The term
``appropriate congressional committees'' means--
(A) the Committee on Homeland Security, the Committee on Judiciary, and the Select Committee on Intelligence of the House of Representatives; and
(B) the Committee on Homeland Security and Governmental Affairs, the Committee on Judiciary, and the Select Committee on Intelligence of the Senate.
(2) Assets.--The term ``assets'' means a person, structure, facility, information, material, equipment, network, or process, whether physical or virtual, that enables an organization's services, functions, or capabilities.
(3) Critical infrastructure.--The term ``critical infrastructure'' has the meaning given such term in section
1016(e) of Public Law 107-56 (42 U.S.C. 5195c(e)).
(4) Cybersecurity threat.--The term ``cybersecurity threat'' has the meaning given such term in section 2200 of the Homeland Security Act of 2002 (6 U.S.C. 650).
(5) Homeland security enterprise.--The term ``Homeland
Security Enterprise'' has the meaning given such term in
section 2200 of the Homeland Security Act of 2002 (6 U.S.C.
650).
(6) Incident.--The term ``incident'' has the meaning given such term in section 2200 of the Homeland Security Act of 2002
(6 U.S.C. 650).
(7) Information sharing.--The term ``information sharing''
means the bidirectional sharing of timely and relevant information concerning a cybersecurity threat posed by a Statesponsored cyber actor of the People's Republic of China to United States critical infrastructure.
(8) Intelligence community.--The term ``intelligence community'' has the meaning given such term in section 3(4) of the National Security Act of 1947 (50 U.S.C. 3003(4)).
(9) Locality.--The term ``locality'' means any local government authority or agency or component thereof within a State having jurisdiction over matters at a county, municipal, or other local government level.
(10) Sector.--The term ``sector'' means a collection of assets, systems, networks, entities, or organizations that provide or enable a common function for national security (including national defense and continuity of Government), national economic security, national public health or safety, or any combination thereof.
(11) Sector risk management agency.--The term ``Sector Risk
Management Agency'' has the meaning given such term in section
2200 of the Homeland Security Act of 2002 (6 U.S.C. 650).
(12) State.--The term ``State'' means any State of the United States, the District of Columbia, the Commonwealth of Puerto Rico, the Northern Mariana Islands, the United States
Virgin Islands, Guam, American Samoa, and any other territory or possession of the United States.
(13) Systems.--The term ``systems'' means a combination of personnel, structures, facilities, information, materials, equipment, networks, or processes, whether physical or virtual, integrated or interconnected for a specific purpose that enables an organization's services, functions, or capabilities.
(14) United states.--The term ``United States'', when used in a geographic sense, means any State of the United States.
(15) Volt typhoon.--The term ``Volt Typhoon'' means the People's Republic of China State-sponsored cyber actor described in the Cybersecurity and Infrastructure Security
Agency cybersecurity advisory entitled ``PRC State-Sponsored
Actors Compromise and Maintain Persistent Access to U.S.
Critical Infrastructure'', issued on February 07, 2024, or any successor advisory.
Passed the House of Representatives November 17, 2025.
Attest:
KEVIN F. MCCUMBER, Clerk.
Перевод на русский: GigaChat-3-Ultra, 16.09.2026. Машинный перевод, вычитывается редакцией.
Машинный черновик — GigaChat-2, 16.09.2026. Экспертом ещё не проверен: даты, адреса норм и санкции сверяйте с текстом.
Паспорт акта
- Юрисдикция
- США
- Официальное наименование
- Strengthening Cyber Resilience Against State-Sponsored Threats Act
- Вид и уровень акта
- Закон
- Дата принятия
- 2025-11-17
- Вступление в силу
- 120 дней после принятия
- Действующая редакция
- последняя
- Статус
- действует
- Регулятор
- Министерство внутренней безопасности через CISA
Предмет и цель
- Проблема
- обеспечение безопасности критической инфраструктуры США от угроз со стороны поддерживаемых государством киберопераций Китая
- Цель
- создание межведомственной рабочей группы для координации действий федеральных ведомств по выявлению и реагированию на угрозы со стороны китайских киберугроз
- Целевые показатели
- отсутствуют
- Сфера действия
- федеральные ведомства, ответственные за управление рисками критической инфраструктуры
- Исключения
- отсутствует
Субъекты
| Роль | Кто именно | Критерии отнесения | Оценка числа адресатов |
|---|---|---|---|
| госорган | Министерство внутренней безопасности, CISA, DOJ, FBI, SRMAs | указанные прямо в акте | нет данных |
- Группы особой защиты
- отсутствует
Нормы 1
Каждая строка — одна норма: кто что должен, через что она меняет поведение, во что обходится и чем подкреплена.
-
секция 2 п. g обязанность госорган
предоставить информацию и документы, необходимые для работы межведомственной рабочей группы
- Механизм воздействия
- предоставление информации и документов
- Издержки: канал
- административный
- Издержки: характер
- разовый
- Событие-триггер
- запрос группы
- Санкция
- отсутствует
- Форма исполнения
- цифровая
- Вступление в силу
- одновременно с созданием группы
- Российский аналог
- отсутствует
Реквизиты
| Страна | США |
| Орган | Конгресс США |
| Вид | закон / законопроект |
| Язык | en |
| Дата документа | 2026-06-17 |
| Объём | 14 820 знаков |
| Редакций | 2 |
| Впервые увидели | 2026-08-19 |
| Проверен | 2026-09-17 01:59 |
| congress | 119 |
| billType | HR |
| number | 2659 |
| policyArea | Science, Technology, Communications |
| subjects | ['Asia', 'China', 'Computer security and identity theft', 'Congressional oversight', 'Federal officials', 'Government information and archives'] |
| latestAction | 2026-05-19 Read twice and referred to the Committee on Homeland Security and Governmental Affairs. |
| textVersion | rfs |
Темы
Почему документ в базе
Отбор сработал на этих совпадениях, суммарный вес 20.
-
cybersecurity
текст
Кибербезопасность
…d cyber actors, including volt typhoon. the task force must be established and led by the cybersecurity and infrastructure security agency (cisa), an agency within the department of homeland se…
-
cybersecurity
текст
Кибербезопасность
…sment of cyber threats and recommendations to improve the detection and mitigation of the cybersecurity threat posed by chinese state-sponsored cyber actors. the first report must be provided n…
-
critical infrastructure
текст
Кибербезопасность
…__________________________ an act to ensure the security and integrity of united states critical infrastructure by establishing an interagency task force and requiring a comprehensive report on the tar…
-
critical infrastructure
текст
Кибербезопасность
…ragency task force and requiring a comprehensive report on the targeting of united states critical infrastructure by people's republic of china state-sponsored cyber actors, and for other purposes. be i…
-
critical infrastructure
текст
Кибербезопасность
…reats act''. sec. 2. interagency task force and report on the targeting of united states critical infrastructure by people's republic of china state-sponsored cyber actors. (a) interagency task force.-…
-
cybersecurity
текст
Кибербезопасность
…tment of this act, the secretary of homeland security, acting through the director of the cybersecurity and infrastructure security agency (cisa) of the department of homeland security, in cons…
-
Cybersecurity and Infrastructure Security Agency
орган
Кибербезопасность
…d cyber actors, including Volt Typhoon. The task force must be established and led by the Cybersecurity and Infrastructure Security Agency (CISA), an agency within the Department of Homeland...…
-
CISA
орган
Кибербезопасность
…ечение 120 дней после вступления закона в силу Министерство внутренней безопасности через CISA создаёт межведомственную рабочую группу по противодействию поддерживаемым государством ки…
Аннотация
В течение 120 дней после вступления закона в силу Министерство внутренней безопасности через CISA создаёт межведомственную рабочую группу по противодействию поддерживаемым государством киберакторам КНР, включая Volt Typhoon. Председательствует директор CISA, заместителем идёт директор ФБР; в состав входят представители отраслевых агентств по управлению рисками из меморандума NSM-22. Ведомства обязаны передавать группе аналитику, проверки и аудиты; к секретным сведениям допускают только при наличии допуска. Первый доклад Конгрессу — через 540 дней, далее ежегодно пять лет, с закрытым брифингом в течение 30 дней; несекретное резюме публикуется на сайте министерства.
Редакции документа
Отметьте две редакции и нажмите «Сравнить» — покажем построчные отличия.
| выбор | Редакция | Загружена | Формат | Объём | |
|---|---|---|---|---|---|
| Редакция 2 открыта | 2026-09-11 02:52 | html | 14 820 зн. | txt | |
| Редакция 1 | 2026-08-19 12:18 | html | 15 120 зн. | txt |
Выбрано: 0 из 2
Зафиксированные изменения
| Дата | Редакции | Строк | |
|---|---|---|---|
| 2026-09-11 | 335 → 13681 | +16 −17 | Построчное сравнение → |