<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" dms-id="HAC3D092A1E68441A90F8E946ECF86191" public-private="public" key="H" bill-type="olc"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>118 HR 1148 IH: Critical Electric Infrastructure Cybersecurity Incident Reporting Act</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2023-02-21</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress display="yes">118th CONGRESS</congress><session display="yes">1st Session</session><legis-num display="yes">H. R. 1148</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20230221">February 21, 2023</action-date><action-desc><sponsor name-id="W000798">Mr. Walberg</sponsor> introduced the following bill; which was referred to the <committee-name committee-id="HIF00">Committee on Energy and Commerce</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To direct the Secretary of Energy to promulgate regulations to facilitate the timely submission of notifications regarding cybersecurity incidents and potential cybersecurity incidents with respect to critical electric infrastructure, and for other purposes.</official-title></form><legis-body id="H296D764E5D4B452F89436F68C238B738" style="OLC"> 
<section id="HC6E7DE7A6BD34A35965829B8710AE3FE" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Critical Electric Infrastructure Cybersecurity Incident Reporting Act</short-title></quote>.</text></section> <section id="H3EC033E82B7F4A4FA3B898DAB66ACD1A"><enum>2.</enum><header>Cybersecurity incident reporting for critical electric infrastructure</header><text display-inline="no-display-inline">Section 215A of the Federal Power Act (<external-xref legal-doc="usc" parsable-cite="usc/16/824o-1">16 U.S.C. 824o–1</external-xref>) is amended—</text>
<paragraph id="HD06F1C3BD1CD45AF8D4A1164F8774B3F"><enum>(1)</enum><text>in subsection (a)—</text> <subparagraph id="HA1351FD0E67E4F63BFE549A45A38FE60"><enum>(A)</enum><text>by amending paragraph (1) to read as follows: </text>
<quoted-block style="OLC" id="H37276B98BB5B431CA1C21CAC75F33576" display-inline="no-display-inline">
<paragraph id="H8A85FF3D3D2947AEADE3DA026250B345"><enum>(1)</enum><header>Bulk-power system; cybersecurity incident; electric reliability organization; regional entity</header><text display-inline="yes-display-inline">The terms <term>bulk-power system</term>, <term>cybersecurity incident</term>, <term>Electric Reliability Organization</term>, and <term>regional entity</term> have the meanings given such terms in paragraphs (1), (8), (2), and (7) of section 215(a), respectively.</text></paragraph><after-quoted-block>; and</after-quoted-block></quoted-block></subparagraph> <subparagraph id="H9D13C6712BA743DAA7F0F7CE9212C91A"><enum>(B)</enum><text>in paragraph (7)(A)(i), by inserting <quote>, including a cybersecurity incident,</quote> after <quote>a malicious act</quote>;</text></subparagraph></paragraph>
<paragraph id="H540DF4AD4DA94E7BAAF53D8697CAE925"><enum>(2)</enum><text>by redesignating subsections (e) and (f) as subsections (f) and (g), respectively; and</text></paragraph> <paragraph id="HA4D1055E7391443BA453A23BDCF9FBAF"><enum>(3)</enum><text>by inserting after subsection (d) the following:</text>
<quoted-block style="OLC" id="H65B99F59738C4C55A3314869A3E226B0" display-inline="no-display-inline">
<subsection id="HFBF07E9AD1BB488197C6A6E64B4B83A2"><enum>(e)</enum><header>Cybersecurity incident reporting</header>
<paragraph id="H9271C5822B6044238D297D71F0F2379B"><enum>(1)</enum><header>Designation</header><text display-inline="yes-display-inline">The Department of Energy shall be a designated agency within the Federal Government to receive notifications regarding cybersecurity incidents and potential cybersecurity incidents with respect to critical electric infrastructure from other Federal agencies and owners, operators, and users of critical electric infrastructure.</text></paragraph> <paragraph id="H384CA1371B194EFE8F1014369D6B4D7F"><enum>(2)</enum><header>Regulations</header> <subparagraph id="HA574705FF3574B5CA952CC73471BD115"><enum>(A)</enum><header>In general</header><text>Not later than 240 days after the date of enactment of the <short-title>Critical Electric Infrastructure Cybersecurity Incident Reporting Act</short-title>, the Secretary shall promulgate regulations to facilitate the submission of timely, secure, and confidential notifications regarding cybersecurity incidents and potential cybersecurity incidents with respect to critical electric infrastructure from Federal agencies and owners, operators, and users of critical electric infrastructure. </text></subparagraph>
<subparagraph id="H4941A95319B34AB3B84E1C3D1F81E08D"><enum>(B)</enum><header>Inclusions</header><text display-inline="yes-display-inline">The regulations promulgated under subparagraph (A) shall—</text> <clause id="HA3E5331AE716486A950020CB5066097D" commented="no"><enum>(i)</enum><text display-inline="yes-display-inline">detail what constitutes a potential cybersecurity incident for purposes of this subsection; and</text></clause>
<clause id="HDF1B73DE062B4291A53E1C10CF906E91"><enum>(ii)</enum><text>require a Federal agency or an owner, operator, or user of critical electric infrastructure that discovers a cybersecurity incident or a potential cybersecurity incident with respect to critical electric infrastructure to submit to the Secretary, not later than 24 hours after discovery of such cybersecurity incident or potential cybersecurity incident, notification regarding such cybersecurity incident or potential cybersecurity incident.</text></clause></subparagraph></paragraph> <paragraph id="H32274E4D5E984150960A56A6C050B4CE"><enum>(3)</enum><header>Annual reports</header><text display-inline="yes-display-inline">Not later than one year after the date of enactment of <short-title>the Critical Electric Infrastructure Cybersecurity Incident Reporting Act</short-title>, and annually thereafter, the Secretary shall submit to the Committee on Energy and Commerce of the House of Representatives and the Committee on Energy and Natural Resources of the Senate a report, in classified form if necessary, on the number of notifications received pursuant to this subsection, and a description of the actions taken by the Department of Energy regarding such notifications, during the 1-year period preceding the report. </text></paragraph></subsection><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></section> 
</legis-body></bill>

