Data Infrastructure Risk Reduction Act

United States119th CongressHR-8711House of Representatives
Updated: May 8, 2026

Summary

This legislation mandates the Secretary of Homeland Security, acting through the Director of the Cybersecurity and Infrastructure Security Agency (CISA) and in collaboration with the Secretary of Defense, to develop a comprehensive strategy for data center protection within 180 days of enactment. This strategy must first identify data centers that should be treated as critical infrastructure, using existing definitions for both terms. It also requires consideration of the security of power and water supply infrastructure connected to these centers, with a specific focus on above-ground electric power transmission lines and electrical substations. Additionally, the bill directs the Secretary to assess any potential implications of data centers sited in proximity to communities or other residential areas. The resulting strategy, which must be submitted to Congress, will include recommendations to defend identified data centers from external breaches by malefactors and to protect surrounding communities and residential areas from potential impacts. This proactive approach aims to enhance both cybersecurity and physical security around vital data infrastructure.

Bill texts

Available versions
Introduced (House)View official text

1 version available

All available records shown.

Timeline

  1. Introduced in House

  2. Referred to the Committee on Homeland Security, and in addition to the Committee on Energy and Commerce, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.

    House of Representatives

  3. Referred to the Subcommittee on Cybersecurity and Infrastructure Protection.

    House of Representatives

All available records shown.