<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-type="olc" bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-ELL26587-FF2-RW-FN8"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>119 S5098 IS: Enhancing K–12 Cybersecurity Act</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2026-07-23</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>119th CONGRESS</congress><session>2d Session</session><legis-num>S. 5098</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20260723">July 23, 2026</action-date><action-desc><sponsor name-id="S396">Mrs. Blackburn</sponsor> (for herself and <cosponsor name-id="S327">Mr. Warner</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSGA00">Committee on Homeland Security and Governmental Affairs</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To direct the Director of the Cybersecurity and Infrastructure Security Agency to establish a K–12 Cybersecurity Technology Improvement Program, and for other purposes.</official-title></form><legis-body style="OLC" display-enacting-clause="yes-display-enacting-clause" id="H85503008C65B429FB55058B795E23C5F"><section section-type="section-one" id="H17FE6554F0854860927D0F9DEB38051C"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Enhancing K–12 Cybersecurity Act</short-title></quote>.</text></section><section id="H08EF705E696D4F5C82342C75CDD58A8A"><enum>2.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act:</text><paragraph id="H3887A404673B4D0797DF084FE14C1BD1"><enum>(1)</enum><header>Covered entity</header><text>The term <term>covered entity</term> means the following:</text><subparagraph id="H93233DA861354AD18490A3785121D6A4"><enum>(A)</enum><text display-inline="yes-display-inline">An elementary school.</text></subparagraph><subparagraph id="H71123D0DB08F4048967DE932A1B01E03"><enum>(B)</enum><text>A secondary school.</text></subparagraph><subparagraph id="HFBDBF79E4475428282BF4ADD14188ECD"><enum>(C)</enum><text>A local educational agency.</text></subparagraph><subparagraph id="H63268C790B254F98B15F2BEE4DCA2489"><enum>(D)</enum><text>A State educational agency.</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="H4C499B97BD3D4A308D985795F6D6981E"><enum>(E)</enum><text>An educational service agency.</text></subparagraph></paragraph><paragraph id="HA3EBA21C5B2D4AC08332307322CD9DF7"><enum>(2)</enum><header>Director</header><text>The term <term>Director</term> means the Director of the Cybersecurity and Infrastructure Security Agency.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id7b818a1c49324c6bad37e83b145e271e"><enum>(3)</enum><header display-inline="yes-display-inline">Educational service agency</header><text display-inline="yes-display-inline">The term <term>educational service agency</term> has the meaning given that term in section 8101 of the Elementary and Secondary Education Act of 1965 (<external-xref legal-doc="usc" parsable-cite="usc/20/7801">20 U.S.C. 7801</external-xref>).</text></paragraph><paragraph id="HD4B467C20C5F4AFC8AADAB12FB187024"><enum>(4)</enum><header>Elementary school</header><text display-inline="yes-display-inline">The term <term>elementary school</term> has the meaning given that term in section 8101 of the Elementary and Secondary Education Act of 1965 (<external-xref legal-doc="usc" parsable-cite="usc/20/7801">20 U.S.C. 7801</external-xref>).</text></paragraph><paragraph id="H4540D76CCD5C4BFDA138157296381167"><enum>(5)</enum><header>Information Exchange</header><text>The term <term>Information Exchange</term> means the School Cybersecurity Information Exchange established under section 3(a).</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id56e25a632d3a4b58b52f0742c0a32117"><enum>(6)</enum><header display-inline="yes-display-inline">Information Sharing and Analysis Organization</header><text display-inline="yes-display-inline">The term <term>Information Sharing and Analysis Organization</term> has the meaning given that term in section 2200 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/650">6 U.S.C. 650</external-xref>).</text></paragraph><paragraph id="H9962B71340F242B899F6DFE4086FC57E"><enum>(7)</enum><header>Local educational agency</header><text>The term <term>local educational agency</term> has the meaning given that term in section 8101 of the Elementary and Secondary Education Act of 1965 (<external-xref legal-doc="usc" parsable-cite="usc/20/7801">20 U.S.C. 7801</external-xref>).</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="HDCE185321DC74474ABF76CA57B8ED524"><enum>(8)</enum><header>Secondary school</header><text display-inline="yes-display-inline">The term <term>secondary school</term> has the meaning given that term in section 8101 of the Elementary and Secondary Education Act of 1965 (<external-xref legal-doc="usc" parsable-cite="usc/20/7801">20 U.S.C. 7801</external-xref>).</text></paragraph><paragraph commented="no" id="H35447C1CE67C4154BA5D96C6BA41D6D7"><enum>(9)</enum><header>State educational agency</header><text display-inline="yes-display-inline">The term <term>State educational agency</term> has the meaning given that term in section 8101 of the Elementary and Secondary Education Act of 1965 (<external-xref legal-doc="usc" parsable-cite="usc/20/7801">20 U.S.C. 7801</external-xref>).</text></paragraph></section><section id="H33D48EECC14A4EA59CCA50B6CF63BEBB"><enum>3.</enum><header>School cybersecurity information exchange</header><subsection id="H6446CF00A7914B0ABD0A435D988B06B2"><enum>(a)</enum><header>Establishment</header><text display-inline="yes-display-inline">The Director shall enhance existing information exchange efforts implemented through partnerships with 1 or more Information Sharing and Analysis Organizations to focus specific attention on the needs of covered entities with regard to cybersecurity, including a new publicly accessible website (to be known as the <quote>School Cybersecurity Information Exchange</quote>) to disseminate information, cybersecurity best practices, training, and lessons learned tailored to the specific needs of, technical expertise of, and resources available to covered entities, in accordance with subsection (b).</text></subsection><subsection id="H8EC1BC65576B40E3985A3FD508D9AA1A"><enum>(b)</enum><header>Duties</header><text display-inline="yes-display-inline">In establishing the Information Exchange, the Director shall—</text><paragraph id="HB2CD4A6E7EC14D0695F3772FF1B90C5B"><enum>(1)</enum><text display-inline="yes-display-inline">engage appropriate Federal, State, local, and nongovernmental organizations to identify, promote, and disseminate information and best practices for State educational agencies, local educational agencies, and educational service agencies with respect to cybersecurity, data protection, remote learning security, and student online privacy;</text></paragraph><paragraph commented="no" id="HA28371AB59CB4E5698C6F06246FBBB82"><enum>(2)</enum><text display-inline="yes-display-inline">maintain a database through which an elementary school, secondary school, local educational agency, State educational agency, or educational service agency may identify cybersecurity tools and services funded by the Federal Government and tools and services recommended for purchase with State and local government funding; and</text></paragraph><paragraph id="H38DBA571ABCF44C590D97914E3DBD05E"><enum>(3)</enum><text display-inline="yes-display-inline">provide a searchable database through which covered entities may find and apply for funding opportunities to improve cybersecurity.</text></paragraph></subsection><subsection id="H4685CD9FD8AE4B509216DA5FB20C6A2B"><enum>(c)</enum><header>Consultation</header><text display-inline="yes-display-inline">In carrying out the duties under subsection (b), the Director shall consult with the following:</text><paragraph id="H5748AE14D9684CCB8A937401173A37CA"><enum>(1)</enum><text display-inline="yes-display-inline">The Secretary of Education.</text></paragraph><paragraph id="H3FDC9639A63A4743A9CB4D8813BAD35E"><enum>(2)</enum><text display-inline="yes-display-inline">The Director of the National Institute of Standards and Technology.</text></paragraph><paragraph id="HB42B3F6ADEB1494EA7F6D44777656D43"><enum>(3)</enum><text>The Federal Communications Commission.</text></paragraph><paragraph id="HEF657B5CC9CC4A7A8FB5EED1660B2772"><enum>(4)</enum><text>The Director of the National Science Foundation.</text></paragraph><paragraph id="HA9792588D7CD4545B53DE5EF848A9E3B"><enum>(5)</enum><text>The Federal Bureau of Investigation.</text></paragraph><paragraph id="H02C597962E354CF1BFB0A3D540973187"><enum>(6)</enum><text display-inline="yes-display-inline">State and local leaders, including, when appropriate, Governors, employees of State departments and agencies, members of State legislatures and State boards of education, local educational agencies, State educational agencies, representatives of Indian Tribes, teachers, principals, other school leaders, charter school leaders, specialized instructional support personnel, paraprofessionals, school administrators, other school staff, and parents.</text></paragraph><paragraph id="HD27BC1191A4B410E825FC74180A210F3"><enum>(7)</enum><text display-inline="yes-display-inline">When determined appropriate by the Director, subject matter experts and expert organizations, including nongovernmental organizations, vendors of school information technology products and services, cybersecurity insurance companies, and cybersecurity threat companies.</text></paragraph></subsection></section><section id="H770C9F94F34F41108812826D3999DE25"><enum>4.</enum><header>Cybersecurity incident registry</header><subsection id="HEA8C608680B1461DB8A42C094B21A419"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">The Director shall—</text><paragraph commented="no" display-inline="no-display-inline" id="ide94356fd94424780903e136efb232acf"><enum>(1)</enum><text display-inline="yes-display-inline">establish, through partnerships with 1 or more Information Sharing and Analysis Organizations, a voluntary registry of information relating to cyber incidents affecting information technology systems owned or managed by a covered entity; and</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ide5fb3b13b7ab498c9ba399f09b65b204"> <enum>(2)</enum> <text display-inline="yes-display-inline">determine the scope of cyber incidents to be included in the registry and processes by which incidents can be reported for collection in the registry.</text>
 </paragraph></subsection><subsection id="HF81F58C30F62459C89D8C9FB0771932D"><enum>(b)</enum><header>Use</header><text display-inline="yes-display-inline">Information in the registry established pursuant to subsection (a) may be used to—</text><paragraph commented="no" id="HF48F717B923545C7BCA0E78C3520C597"><enum>(1)</enum><text display-inline="yes-display-inline">improve data collection and coordination activities related to the nationwide monitoring of the incidence and impact of cyber incidents affecting a covered entity;</text></paragraph><paragraph id="H9C4C6173191E49DCB208EB1BFF5467A7"><enum>(2)</enum><text>conduct analyses regarding trends in cyber incidents affecting a covered entity;</text></paragraph><paragraph id="H5BE4175D48764A38AC576A5FFA9C6820"><enum>(3)</enum><text>develop systematic approaches to assist a covered entity in preventing and responding to cyber incidents;</text></paragraph><paragraph id="HAD376846E2D34B4D836095EE06EDF01D"><enum>(4)</enum><text>increase the awareness and preparedness of a covered entity regarding the cybersecurity of the covered entity; and</text></paragraph><paragraph id="HBA4945439E4249E0AA766F5FCFFE247B"><enum>(5)</enum><text display-inline="yes-display-inline">identify, prevent, or investigate cyber incidents targeting a covered entity.</text></paragraph></subsection><subsection id="HA9D4BF4E00B548628CFCB1CCCCFC76CC"><enum>(c)</enum><header>Information collection</header><paragraph commented="no" display-inline="no-display-inline" id="id62eed4530e6f4e4fbf326cd2bd0ef61a"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">The Director may collect information relating to cyber incidents to store in the registry established pursuant to subsection (a).</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="idfec6b5437e5c45cfba1cfa9aee0d4695"><enum>(2)</enum><header>Submission of information</header><text display-inline="yes-display-inline">Information relating to a cyber incident may be submitted by a covered entity and may include the following:</text><subparagraph id="HF16BF752C81D494DA6F1C93379119C78"><enum>(A)</enum><text display-inline="yes-display-inline">The date of the cyber incident, including the date on which the incident was initially detected and the date on which the incident was first publicly reported or disclosed to another entity.</text></subparagraph><subparagraph id="HF1B684E9A7944E9BB0978CB9850E9D39"><enum>(B)</enum><text display-inline="yes-display-inline">A description of the cyber incident, which shall include whether the incident was as a result of a breach, malware, distributed denial of service attack, or other method designed to cause a vulnerability.</text></subparagraph><subparagraph id="HC5FE423EA2D1406E8E525C0D53F3E0CA"><enum>(C)</enum><text display-inline="yes-display-inline">The effects of the cyber incident, including descriptions of the type and size of each such incident.</text></subparagraph><subparagraph id="H21BB814B7E6A417BBAAE4B87E6BF376D"><enum>(D)</enum><text display-inline="yes-display-inline">Other information determined relevant by the Director.</text></subparagraph></paragraph></subsection><subsection id="H45AF152BF8EC4A838B47FA54B3DCF4E7"><enum>(d)</enum><header>Report</header><text display-inline="yes-display-inline">The Director shall make available on the Information Exchange an annual report relating to cyber incidents affecting elementary schools and secondary schools which includes data, and the analysis of such data, in a manner that—</text><paragraph id="H6B6AD1B79DE34C65A6A0FB839219BC82"><enum>(1)</enum><text>is—</text><subparagraph id="H399A200CB2F543B99196DE2EE6589FB7"><enum>(A)</enum><text>de-identified; and</text></subparagraph><subparagraph id="H4379DE1088A948999F0FBD59FB25BFD2"><enum>(B)</enum><text>presented in the aggregate; and</text></subparagraph></paragraph><paragraph id="HC2FDC638F5CC410BA5399754E1BAE40A"><enum>(2)</enum><text>at a minimum, protects personal privacy to the extent required by applicable Federal and State privacy laws.</text></paragraph></subsection></section><section id="H115A4A5157664EA68D13270CC38EA212"><enum>5.</enum><header>K–12 Cybersecurity Technology Improvement program</header><subsection id="H0EBABB20987A44E982221EEC95D24E07"><enum>(a)</enum><header>Establishment</header><text display-inline="yes-display-inline">The Director shall establish, through partnerships with 1 or more Information Sharing and Analysis Organizations, a program (to be known as the <quote>K–12 Cybersecurity Technology Improvement Program</quote>) to deploy cybersecurity capabilities to address cybersecurity risks and threats to information systems of elementary schools and secondary schools through—</text><paragraph id="HC01C08140F42496080913E8AA8A3CD56"><enum>(1)</enum><text display-inline="yes-display-inline">the development of cybersecurity strategies and installation of effective cybersecurity tools tailored for covered entities;</text></paragraph><paragraph id="HA4CE8A250B6E45568B0441AFC22F0F0D"><enum>(2)</enum><text display-inline="yes-display-inline">making available cybersecurity services that enhance the ability of elementary schools and secondary schools to protect themselves from ransomware and other cybersecurity threats; and</text></paragraph><paragraph id="HD11E816B49EE4EAF85009A35454BFEEF"><enum>(3)</enum><text display-inline="yes-display-inline">providing training opportunities on cybersecurity threats, best practices, and relevant technologies for elementary schools and secondary schools.</text></paragraph></subsection><subsection id="H0437227BA25F4442BED9757B62C5BAEF"><enum>(b)</enum><header>Report</header><text display-inline="yes-display-inline">The Director shall make available on the Information Exchange an annual report relating to the impact of the K–12 Cybersecurity Technology Improvement Program, including information on the cybersecurity capabilities made available to information technology systems owned or managed by covered entities, the number of students served, and cybersecurity incidents identified or prevented.</text></subsection></section><section id="H066FB928FF0B4F87BBDEDE8C96450965"><enum>6.</enum><header>Authorization of appropriations</header><text display-inline="no-display-inline">There are authorized to be appropriated to carry out this Act $10,000,000 for each of fiscal years 2027 and 2028.</text></section></legis-body></bill>

