<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-WAL26352-GVN-RH-629"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>119 S4699 IS: Guaranteeing Universal Access to Cybersecurity Act</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2026-06-08</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>119th CONGRESS</congress><session>2d Session</session><legis-num>S. 4699</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20260608">June 8, 2026</action-date><action-desc><sponsor name-id="S327">Mr. Warner</sponsor> introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSGA00">Committee on Homeland Security and Governmental Affairs</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To restore funding to the Multi-State Information Sharing and Analysis Center, and for other purposes.</official-title></form><legis-body><section id="S1" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Guaranteeing Universal Access to Cybersecurity Act</short-title></quote>.</text></section><section id="id1039172e6fc34fe1959cd800a670bc47"><enum>2.</enum><header>Restoration of funding for the Multi-State Information Sharing and Analysis Center</header><text display-inline="no-display-inline">Section 2209 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/659">6 U.S.C. 659</external-xref>) is amended by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id6935d18c520a4a839ede080fa1146203"><subsection id="id2fb490878782492baf49657c2e053621"><enum>(t)</enum><header>Multi-State Information Sharing and Analysis Center</header><paragraph commented="no" display-inline="no-display-inline" id="iddee9bd4cf58f421fb1d98bea68d77216"><enum>(1)</enum><header display-inline="yes-display-inline">Cooperative agreement</header><subparagraph id="idfc761129789c49938770d42dd2975d5f"><enum>(A)</enum><header>In general</header><text>The Director shall enter into a cooperative agreement with the operator of the Multi-State Information Sharing and Analysis Center to provide Federal support for—</text><clause commented="no" display-inline="no-display-inline" id="id48334298c039481b9603ef1b5a423a6d"><enum>(i)</enum><text display-inline="yes-display-inline">cybersecurity services;</text></clause><clause commented="no" display-inline="no-display-inline" id="id68ed8bedea3648ba9aca79339901bd7d"><enum>(ii)</enum><text display-inline="yes-display-inline">cyber threat intelligence collection and dissemination; and</text></clause><clause commented="no" display-inline="no-display-inline" id="id725d97e4376c4c83a81b538170c52de7"><enum>(iii)</enum><text display-inline="yes-display-inline">technical assistance to SLTT entities.</text></clause></subparagraph><subparagraph id="id0643e3a4e12b4733bf9858daa76e4b41"><enum>(B)</enum><header>Requirements</header><text>Any cooperative agreement entered into under subparagraph (A) shall require the operator of the Multi-State Information Sharing and Analysis Center to—</text><clause id="idae12a37706744199bf1bc2293d527b8b"><enum>(i)</enum><text>provide no-cost membership and access to core cybersecurity services, including cyber threat intelligence products, real-time indicator feeds, and incident response support, to all SLTT entities that apply for membership in the Multi-State Information Sharing and Analysis Center;</text></clause><clause id="idcc959b672aca421ba1f986c6126c34c9"><enum>(ii)</enum><text>prioritize outreach to and enrollment of SLTT entities that—</text><subclause commented="no" display-inline="no-display-inline" id="id91c8939a7cf34fefbaba3d3735eae78e"><enum>(I)</enum><text display-inline="yes-display-inline">lack dedicated cybersecurity staff;</text></subclause><subclause commented="no" display-inline="no-display-inline" id="id814c8a888bee46e7bd5d34589a7eb82b"><enum>(II)</enum><text display-inline="yes-display-inline">operate on limited budgets; or</text></subclause><subclause commented="no" display-inline="no-display-inline" id="id6acd4d4de50941c69c1aa9cbcf03cf9d"><enum>(III)</enum><text display-inline="yes-display-inline">have been identified as covered entities, as defined in section 2240 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/681">6 U.S.C. 681</external-xref>);</text></subclause></clause><clause id="idf9ec0f45595f4e53b7948d39de79b2e9"><enum>(iii)</enum><text>maintain interoperability and data-sharing arrangements with the Agency, the Federal Bureau of Investigation, and other relevant Federal agencies for the purposes of enhancing the national cyber threat intelligence ecosystem; and</text></clause><clause id="idbbfc5c598df2430c9312ab049c44ffdd"><enum>(iv)</enum><text>submit annual reports to the Director and to the appropriate congressional committees on—</text><subclause commented="no" display-inline="no-display-inline" id="idea47230b5113476e94f10eac410cfdfc"><enum>(I)</enum><text display-inline="yes-display-inline">membership levels of the Multi-State Information Sharing and Analysis Center;</text></subclause><subclause commented="no" display-inline="no-display-inline" id="id72e425dabc204833a29c87a2419a0ebc"><enum>(II)</enum><text display-inline="yes-display-inline">threat intelligence activities;</text></subclause><subclause commented="no" display-inline="no-display-inline" id="idfea4f263908247f2ac120c356893fe86"><enum>(III)</enum><text display-inline="yes-display-inline">significant cyber incidents affecting SLTT entities; and</text></subclause><subclause commented="no" display-inline="no-display-inline" id="id334442bd1a154ec89c8d296bf3fc7bed"><enum>(IV)</enum><text display-inline="yes-display-inline">the efficacy of outreach to under-resourced SLTT entities.</text></subclause></clause></subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id323c1d14c03c4abab573ec124859697c"><enum>(2)</enum><header>CISA and Multi-State Information Sharing and Analysis Center plan for SLTT assistance</header><subparagraph id="id5da86449a3af4c3ab05afb555ccec5c9"><enum>(A)</enum><header>In general</header><text>Not later than 60 days after the date of enactment of the <short-title>Guaranteeing Universal Access to Cybersecurity Act</short-title>, the Director, in coordination with the operator of the Multi-State Information Sharing and Analysis Center, shall develop and implement a plan to—</text><clause id="idf665f07dc62a42c5a5e0bc315aec3a3a"><enum>(i)</enum><subclause commented="no" display-inline="yes-display-inline" id="id0bbc66b6301d4ec69b54086197040661"><enum>(I)</enum><text>identify SLTT entities and owners and operators of critical infrastructure that previously held membership in the Multi-State Information Sharing and Analysis Center and have not enrolled in the Multi-State Information Sharing and Analysis Center under the fee-based membership model; and</text></subclause><subclause commented="no" display-inline="no-display-inline" id="idd320477bb4084fcc8cb44c350d0bf265" indent="up1"><enum>(II)</enum><text display-inline="yes-display-inline">conduct targeted outreach to restore participation by those SLTT entities and owners and operators of critical infrastructure in the Multi-State Information Sharing and Analysis Center;</text></subclause></clause><clause id="id406238602fdb43f4a9786bcc64d537d0"><enum>(ii)</enum><subclause commented="no" display-inline="yes-display-inline" id="id93dcc3f56ef44a1983d549361514a401"><enum>(I)</enum><text>identify SLTT entities and owners and operators of critical infrastructure that previously held membership in the Multi-State Information Sharing and Analysis Center and are enrolled in the Multi-State Information Sharing and Analysis Center under the fee-based membership model; and</text></subclause><subclause commented="no" display-inline="no-display-inline" id="id77931b83b5824554816a834582e259aa" indent="up1"><enum>(II)</enum><text display-inline="yes-display-inline">conduct targeted outreach to retain participation by those SLTT entities and owners and operators of critical infrastructure in the Multi-State Information Sharing and Analysis Center;</text></subclause></clause><clause id="idb6ce47c876384dd3a9d95ac63377673e"><enum>(iii)</enum><subclause commented="no" display-inline="yes-display-inline" id="id8a4419a0c8a846bcad19c1edecd501f7"><enum>(I)</enum><text>identify SLTT entities and owners and operators of critical infrastructure that have never held membership in the Multi-State Information Sharing and Analysis Center and that face elevated cyber risk due to limited cybersecurity resources; and</text></subclause><subclause commented="no" display-inline="no-display-inline" id="id56e500f9ea2a45778823ab6f5d392796" indent="up1"><enum>(II)</enum><text display-inline="yes-display-inline">conduct targeted outreach to encourage participation by those SLTT entities and owners and operators of critical infrastructure in the Multi-State Information Sharing and Analysis Center; and</text></subclause></clause><clause id="id6322c98a5bac457ba501d2048d1afdd1"><enum>(iv)</enum><text>provide technical assistance and cybersecurity capacity-building support to SLTT entities identified under clauses (i)(I) and (ii)(I), including through partnerships with cyber-capable governments and entities.</text></clause></subparagraph><subparagraph id="id0b104182a4814a54b3fe7d012d9374ae" commented="no" display-inline="no-display-inline"><enum>(B)</enum><header>Report</header><text>Not later than 1 year after the date of enactment of the <short-title>Guaranteeing Universal Access to Cybersecurity Act</short-title>, the Director shall submit to the appropriate congressional committees a report on the implementation of this paragraph, including—</text><clause commented="no" display-inline="no-display-inline" id="id922dfe36781d46a9a177a8234ef1a702"><enum>(i)</enum><text display-inline="yes-display-inline">the number of SLTT entities re-enrolled in the Multi-State Information Sharing and Analysis Center;</text></clause><clause commented="no" display-inline="no-display-inline" id="ida957334cd57e45d7acb6efa511b84b0e"><enum>(ii)</enum><text display-inline="yes-display-inline">the number of new members enrolled in the Multi-State Information Sharing and Analysis Center since the date of enactment of the <short-title>Guaranteeing Universal Access to Cybersecurity Act</short-title>; and</text></clause><clause commented="no" display-inline="no-display-inline" id="id4b489663242d48e0a8afeb30cba0fd14"><enum>(iii)</enum><text display-inline="yes-display-inline">any barriers to participation in the Multi-State Information Sharing and Analysis Center that remain as of the date of the report.</text></clause></subparagraph></paragraph><paragraph id="id2401a6abfe1c4241a5f3efa4f1929443"><enum>(3)</enum><header>Appropriations</header><text>There is appropriated to carry out this subsection $50,000,000 for fiscal year 2027 and each fiscal year thereafter, to remain available until expended.</text></paragraph></subsection><after-quoted-block>.</after-quoted-block></quoted-block></section></legis-body></bill>

