<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-type="olc" bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-WAL26042-RYF-SR-5T8"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>119 S4565 IS: Strengthening Cyber Resilience Against State-Sponsored Threats Act</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2026-05-19</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>119th CONGRESS</congress><session>2d Session</session><legis-num>S. 4565</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20260519">May 19, 2026</action-date><action-desc><sponsor name-id="S404">Mr. Scott of Florida</sponsor> introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSGA00">Committee on Homeland Security and Governmental Affairs</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To ensure the security and integrity of United States critical infrastructure by establishing an interagency task force and requiring a comprehensive report on the targeting of United States critical infrastructure by People’s Republic of China state-sponsored cyber actors, and for other purposes.</official-title></form><legis-body style="OLC" display-enacting-clause="yes-display-enacting-clause" id="HCCDEB20971A04DED8816315A21C695BF"><section section-type="section-one" id="HC0CF3039E1F34CEFB3EF4E71B666F557"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Strengthening Cyber Resilience Against State-Sponsored Threats Act</short-title></quote>.</text></section><section id="H4B7358655D134CCABF122294DFF2A432"><enum>2.</enum><header>Interagency task force and report on the targeting of United States critical infrastructure by People’s Republic of China state-sponsored cyber actors</header><subsection id="HFECF22619A024D6A963E19E85C0A60E0"><enum>(a)</enum><header>Definitions</header><text>In this section:</text><paragraph id="H3E9E8C268ACB462EA45252DDB69F3A03"><enum>(1)</enum><header>Appropriate congressional committees</header><text>The term <quote>appropriate congressional committees</quote> means—</text><subparagraph id="HBC848FD919F04F84BE02B12DD1B08A87"><enum>(A)</enum><text>the Committee on Homeland Security and Governmental Affairs, the Committee on the Judiciary, and the Select Committee on Intelligence of the Senate; and<committee-name committee-id="SSGA00"></committee-name></text></subparagraph><subparagraph id="H803E3F37ED4145E9A168056DAD1FEE37"><enum>(B)</enum><text>the Committee on Homeland Security, the Committee on the Judiciary, and the Permanent Select Committee on Intelligence of the House of Representatives. </text></subparagraph></paragraph><paragraph id="H0F02153EC2CB44BEBA603B0E7ACC6E96"><enum>(2)</enum><header>Asset</header><text>The term <quote>asset</quote> means a person, structure, facility, information, material, equipment, network, or process, whether physical or virtual, that enables the services, functions, or capabilities of an organization. </text></paragraph><paragraph id="HC3555A6FE9CF4207BF7633C6D5B494D9"><enum>(3)</enum><header>Critical infrastructure</header><text>The term <quote>critical infrastructure</quote> has the meaning given the term in section 1016(e) of the Critical Infrastructures Protection Act of 2001 (<external-xref legal-doc="usc" parsable-cite="usc/42/5195c">42 U.S.C. 5195c(e)</external-xref>).</text></paragraph><paragraph id="H4A20086DCE8E430E9F93D8BABCDBF661"><enum>(4)</enum><header>Cybersecurity threat</header><text>The term <quote>cybersecurity threat</quote> has the meaning given the term in section 2200 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/650">6 U.S.C. 650</external-xref>).</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id7dd7394be53d4a6686f7ee7a74787352"><enum>(5)</enum><header>Director</header><text>The term <quote>Director</quote> means the Director of the Cybersecurity and Infrastructure Security Agency. </text></paragraph><paragraph id="H0726FF7FA3B04E9F96B4FEC4630EBDA1"><enum>(6)</enum><header>Homeland Security Enterprise</header><text>The term <quote>Homeland Security Enterprise</quote> has the meaning given the term in section 2200 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/650">6 U.S.C. 650</external-xref>).</text></paragraph><paragraph id="H1A31D6F77972490A84BCE78FADE8898D"><enum>(7)</enum><header>Incident</header><text>The term <quote>incident</quote> has the meaning given the term in section 2200 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/650">6 U.S.C. 650</external-xref>).</text></paragraph><paragraph id="H04ABCB8A079F47DBBF2F103DAC32763F"><enum>(8)</enum><header>Information sharing</header><text>The term <quote>information sharing</quote> means the bidirectional sharing of timely and relevant information concerning a cybersecurity threat posed by a State-sponsored cyber actor of the People’s Republic of China to United States critical infrastructure.</text></paragraph><paragraph id="H145351C3E49C4563B2E1C07F0678CFE8"><enum>(9)</enum><header>Intelligence community</header><text>The term <quote>intelligence community</quote> has the meaning given the term in section 3(4) of the National Security Act of 1947 (<external-xref legal-doc="usc" parsable-cite="usc/50/3003">50 U.S.C. 3003(4)</external-xref>).</text></paragraph><paragraph id="H7C3B3A31437842628415EC1A6F29E7C5"><enum>(10)</enum><header>Locality</header><text>The term <quote>locality</quote> means any local government authority or agency or component thereof within a State having jurisdiction over matters at a county, municipal, or other local government level.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id14bc986b825d4e788355f26894487467"><enum>(11)</enum><header>Secretary</header><text>The term <quote>Secretary</quote> means the Secretary of Homeland Security. </text></paragraph><paragraph id="H738DF74D36B54B6AA6FDD8805F804892"><enum>(12)</enum><header>Sector</header><text>The term <quote>sector</quote> means a collection of assets, systems, networks, entities, or organizations that provide or enable a common function for national security (including national defense and continuity of Government), national economic security, national public health or safety, or any combination thereof.</text></paragraph><paragraph id="H420A42B698DA4826AFC0CEA7584CC72D"><enum>(13)</enum><header>Sector Risk Management Agency</header><text>The term <quote>Sector Risk Management Agency</quote> has the meaning given the term in section 2200 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/650">6 U.S.C. 650</external-xref>).</text></paragraph><paragraph id="H3298579CE0F643288B3189882CB979F6"><enum>(14)</enum><header>State</header><text>The term <quote>State</quote> means any State of the United States, the District of Columbia, the Commonwealth of Puerto Rico, the Northern Mariana Islands, the United States Virgin Islands, Guam, American Samoa, and any other territory or possession of the United States.</text></paragraph><paragraph id="HCB867864C7C2425F90CE833EB17F5957"><enum>(15)</enum><header>Systems</header><text>The term <quote>systems</quote> means a combination of personnel, structures, facilities, information, materials, equipment, networks, or processes, whether physical or virtual, integrated or interconnected for a specific purpose that enables the services, functions, or capabilities of an organization. </text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id1a924d6456654160800eb16ee8f7354c"><enum>(16)</enum><header>Task force</header><text>The term <quote>task force</quote> means the joint interagency task force established under subsection (b). </text></paragraph><paragraph id="HB09D3CBBC4B34F19A4C12C9A1CFA89C0"><enum>(17)</enum><header>United States</header><text>The term <quote>United States</quote>, when used in a geographic sense, means any State of the United States.</text></paragraph><paragraph id="H1369913F3F8D4B2D913A46DF02FA6029" commented="no" display-inline="no-display-inline"><enum>(18)</enum><header>Volt Typhoon</header><text>The term <quote>Volt Typhoon</quote> means the People’s Republic of China State-sponsored cyber actor described in the Cybersecurity and Infrastructure Security Agency cybersecurity advisory entitled <quote>PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure</quote>, issued on February 07, 2024, or any successor advisory.</text></paragraph></subsection><subsection id="HE232D1A9A1334E38B8A93BD8294049F5"><enum>(b)</enum><header>Interagency task force</header><text>Not later than 120 days after the date of enactment of this Act, the Secretary, acting through the Director, in consultation with the Attorney General, the Director of the Federal Bureau of Investigation, and the heads of appropriate Sector Risk Management Agencies as determined by the Director, shall establish a joint interagency task force to facilitate collaboration and coordination among the Sector Risk Management Agencies assigned a Federal role or responsibility in National Security Memorandum–22, issued April 30, 2024 (relating to critical infrastructure security and resilience), or any successor document, to detect, analyze, and respond to the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China by ensuring that the actions of those agencies are aligned and mutually reinforcing.</text></subsection><subsection id="H4B66B4A41E57474694B6674D35A76E2F"><enum>(c)</enum><header>Chairs</header><paragraph id="H62BF07D762ED40E4A7C5232B79D34FFA"><enum>(1)</enum><header>Chairperson</header><text>The Director, or the designee of the Director, shall serve as the Chairperson of the task force.</text></paragraph><paragraph id="H96F3A225BAC641E497C6B033A40C73F1"><enum>(2)</enum><header>Vice Chairperson</header><text>The Director of the Federal Bureau of Investigation, or the designee of the Director, shall serve as the Vice Chairperson of the task force.</text></paragraph></subsection><subsection id="HFA5AE3E71EF646C5B9CA5CC0D95BF391"><enum>(d)</enum><header>Composition</header><paragraph id="H4507405D92DB4B82AC08371914383018"><enum>(1)</enum><header>In general</header><text>The task force shall consist of appropriate representatives of the departments and agencies specified in subsection (b) appointed by the Chairperson in consultation with the Vice Chairperson.</text></paragraph><paragraph id="H420BEDA962844D79933CB39ECC92CF06"><enum>(2)</enum><header>Qualifications</header><text>To materially assist in the activities of the task force, representatives under paragraph (1) shall be subject matter experts who have familiarity and technical expertise regarding cybersecurity, digital forensics, or threat intelligence analysis, or in-depth knowledge of the tactics, techniques, and procedures commonly used by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China.</text></paragraph></subsection><subsection id="H0EF9988D5F1741A38967423FE6153898"><enum>(e)</enum><header>Vacancy</header><text>Any vacancy occurring in the membership of the task force shall be filled in the same manner in which the original appointment was made.</text></subsection><subsection id="HDB3673C38C3E4751AC47058A452ACD17"><enum>(f)</enum><header>Establishment flexibility</header><text>To avoid redundancy, the task force may coordinate with any preexisting task force, working group, or cross-intelligence effort within the Homeland Security Enterprise or the intelligence community that has examined or responded to the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China.</text></subsection><subsection id="HA14C3CB9CC874BF58E52FCA0DE17D63E"><enum>(g)</enum><header>Task force reports; briefing</header><paragraph id="H0A3FAB4CEDBF47E88199D685BE5DAC5E"><enum>(1)</enum><header>Initial report</header><text>Not later than 540 days after the establishment of the task force, the task force shall submit to the appropriate congressional committees the first report containing the initial findings, conclusions, and recommendations of the task force.</text></paragraph><paragraph id="H8A054065E55D4DDA9063FBD4E5B9D63E"><enum>(2)</enum><header>Annual report</header><text>Not later than 1 year after the date of the submission of the initial report under paragraph (1), and annually thereafter for 5 years, the task force shall submit to the appropriate congressional committees an annual report containing the findings, conclusions, and recommendations of the task force.</text></paragraph><paragraph id="HD2FC6FA971FE4E4FA74195A15AC982B2"><enum>(3)</enum><header>Contents</header><text>The reports under this subsection shall include the following:</text><subparagraph id="HFD37BD0302B9487F9F63D8DAC59C2C1D"><enum>(A)</enum><text>An assessment at the lowest classification feasible of the sector-specific risks, trends relating to incidents impacting sectors, and tactics, techniques, and procedures utilized by or relating to State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China.</text></subparagraph><subparagraph id="HAE7E0DC1712B47D18FC48E025D48B95F"><enum>(B)</enum><text>An assessment of additional resources and authorities needed by Federal departments and agencies to better counter the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China.</text></subparagraph><subparagraph id="HA93BC151C91A49CABE62AE5B3E55F77A"><enum>(C)</enum><text>A classified assessment of the extent of potential destruction, compromise, or disruption to United States critical infrastructure by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China in the event of a major crisis or future conflict between the People’s Republic of China and the United States.</text></subparagraph><subparagraph id="H2015644DC70D4C6AAC98B79CAEABB027"><enum>(D)</enum><text>A classified assessment of the ability of the United States to counter the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China in the event of a major crisis or future conflict between the People’s Republic of China and the United States, including with respect to different cybersecurity measures and recommendations that could mitigate such a threat.</text></subparagraph><subparagraph id="H07231AFD8DEF49F6ABCC82796B23D93C"><enum>(E)</enum><text>A classified assessment of the ability of State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China to disrupt operations of the United States Armed Forces by hindering mobility across critical infrastructure such as rail, aviation, and ports, including how such disruption would impair the ability of the United States Armed Forces to deploy and maneuver forces effectively.</text></subparagraph><subparagraph id="HC9949ED631E2408CA7AEB6C615D926F0"><enum>(F)</enum><text>A classified assessment of the economic and social ramifications of a disruption to 1 or multiple United States critical infrastructure sectors by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China in the event of a major crisis or future conflict between the People’s Republic of China and the United States.</text></subparagraph><subparagraph id="H2070A0B0CAF8464FADA6E5C66C44E9B6"><enum>(G)</enum><text>Such recommendations as the task force may have for the Homeland Security Enterprise, the intelligence community, or critical infrastructure owners and operators to improve the detection and mitigation of the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China.</text></subparagraph><subparagraph id="H6DAA1008CCCE4A7390C8CF7F79E1922B"><enum>(H)</enum><text>A one-time plan for an awareness campaign to familiarize critical infrastructure owners and operators with security resources and support offered by Federal departments and agencies to mitigate the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China.</text></subparagraph></paragraph><paragraph id="H8E8E8E4AF43B4B04B2DAD571BAA17431"><enum>(4)</enum><header>Briefing</header><text>Not later than 30 days after the date of the submission of each report under this subsection, the task force shall provide to the appropriate congressional committees a classified briefing on the findings, conclusions, and recommendations of the task force.</text></paragraph><paragraph id="HBD7E95B14E25409ABF75CFBC14B0AA10"><enum>(5)</enum><header>Form</header><text>Each report under this subsection shall be submitted in classified form, consistent with the protection of intelligence sources and methods, but may include an unclassified executive summary.</text></paragraph><paragraph id="H626F89E45AAD4A5098ED59ED66AE8CEB"><enum>(6)</enum><header>Publication</header><text>The unclassified executive summary of each report required under this subsection shall be published on a publicly accessible website of the Department of Homeland Security.</text></paragraph></subsection><subsection id="HFF1CCFC874984471AFF4613100DE2B7B"><enum>(h)</enum><header>Access to information</header><paragraph id="H11463AE818944CDD848E7040E66CA7D2"><enum>(1)</enum><header>In general</header><text>The Secretary, the Director, the Attorney General, the Director of the Federal Bureau of Investigation, and the heads of appropriate Sector Risk Management Agencies, as determined by the Director, shall provide to the task force such information, documents, analysis, assessments, findings, evaluations, inspections, audits, or reviews relating to efforts to counter the cybersecurity threat posed by State-sponsored cyber actors, including Volt Typhoon, of the People’s Republic of China as the task force considers necessary to carry out this section.</text></paragraph><paragraph id="HF4022221A76D42349094BF77A82E65B5"><enum>(2)</enum><header>Receipt, handling, storage, and dissemination</header><text>Information, documents, analysis, assessments, findings, evaluations, inspections, audits, and reviews described in this subsection shall be received, handled, stored, and disseminated only by members of the task force consistent with all applicable statutes, regulations, and Executive orders.</text></paragraph><paragraph id="HB5DA36C121714B2189D437769A999B09"><enum>(3)</enum><header>Security clearances for task force members</header><text>No member of the task force may be provided with access to classified information under this section without the appropriate security clearances.</text></paragraph></subsection><subsection id="H2E79B72025F1414A85A0B894539F8A54"><enum>(i)</enum><header>Termination</header><text>The task force, and all the authorities of this section, shall terminate on the date that is 60 days after the final briefing required under subsection (g)(4).</text></subsection><subsection id="H565F08A3E6C041A9A3924776B5B74DE5"><enum>(j)</enum><header>Exemption from FACA</header><text><external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/5/10">Chapter 10</external-xref> of title 5, United States Code, shall not apply to the task force.</text></subsection><subsection id="H8B1A8389F7534F4C80D4077E3FF73F05"><enum>(k)</enum><header>Exemption from Paperwork Reduction Act</header><text><external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/35">Chapter 35</external-xref> of title 44, United States Code (commonly known as the <quote>Paperwork Reduction Act</quote>), shall not apply to the task force.</text></subsection></section></legis-body></bill> 

