Homeland Security and Governmental Affairs Committee
Introduced
In Committee
On Floor
Passed Chamber
Enacted
The "Streamlining Federal Cybersecurity Regulations Act of 2025" aims to harmonize and streamline the complex landscape of federal cybersecurity regulations. It establishes an interagency Harmonization Committee , chaired by the National Cyber Director, comprising heads of various regulatory agencies, including the Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology (NIST). This Committee is tasked with enhancing the consistency and reciprocity of cybersecurity requirements across the United States. Within one year, the Committee must develop a regulatory framework that includes a common set of baseline cybersecurity requirements applicable across sectors, alongside sector-specific rules. This framework will also outline common approaches and language for future cybersecurity requirements and establish mechanisms for reciprocal compliance for entities regulated by multiple agencies. To test this framework, the bill mandates a pilot program involving 3 to 5 regulatory agencies and specific cybersecurity requirements, allowing for waivers of existing regulations for participating entities. Beyond the pilot, regulatory agencies will be required to consult with the Committee before promulgating or amending cybersecurity requirements, receiving advisory reports with recommendations for alignment. The Office of Management and Budget (OMB) will issue guidance to federal agencies on coordinating with the Committee and, later, to all agencies to ensure cybersecurity requirements are consistent with the developed framework, incorporating lessons learned from the pilot program. The Committee will also provide annual reports to Congress on its activities and the framework's application.
Streamlining Federal Cybersecurity Regulations Act
Introduced in Senate
Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
Science, Technology, Communications
Streamlining Federal Cybersecurity Regulations Act of 2025
USA119th CongressS-1875| Senate
| Updated: 5/22/2025
The "Streamlining Federal Cybersecurity Regulations Act of 2025" aims to harmonize and streamline the complex landscape of federal cybersecurity regulations. It establishes an interagency Harmonization Committee , chaired by the National Cyber Director, comprising heads of various regulatory agencies, including the Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology (NIST). This Committee is tasked with enhancing the consistency and reciprocity of cybersecurity requirements across the United States. Within one year, the Committee must develop a regulatory framework that includes a common set of baseline cybersecurity requirements applicable across sectors, alongside sector-specific rules. This framework will also outline common approaches and language for future cybersecurity requirements and establish mechanisms for reciprocal compliance for entities regulated by multiple agencies. To test this framework, the bill mandates a pilot program involving 3 to 5 regulatory agencies and specific cybersecurity requirements, allowing for waivers of existing regulations for participating entities. Beyond the pilot, regulatory agencies will be required to consult with the Committee before promulgating or amending cybersecurity requirements, receiving advisory reports with recommendations for alignment. The Office of Management and Budget (OMB) will issue guidance to federal agencies on coordinating with the Committee and, later, to all agencies to ensure cybersecurity requirements are consistent with the developed framework, incorporating lessons learned from the pilot program. The Committee will also provide annual reports to Congress on its activities and the framework's application.