S4699
Referred to committee
Guaranteeing Universal Access to Cybersecurity Act
- Federal
- Senate
- Introduced Jun 8, 2026
- Session 119
Bill Text
Version ISThis Act may be cited as the Guaranteeing Universal Access to Cybersecurity Act.
Section 2209 of the Homeland Security Act of 2002 (6 U.S.C. 659) is amended by adding at the end the following:
The Director shall enter into a cooperative agreement with the operator of the Multi-State Information Sharing and Analysis Center to provide Federal support for—
cybersecurity services;
cyber threat intelligence collection and dissemination; and
technical assistance to SLTT entities.
Any cooperative agreement entered into under subparagraph (A) shall require the operator of the Multi-State Information Sharing and Analysis Center to—
provide no-cost membership and access to core cybersecurity services, including cyber threat intelligence products, real-time indicator feeds, and incident response support, to all SLTT entities that apply for membership in the Multi-State Information Sharing and Analysis Center;
prioritize outreach to and enrollment of SLTT entities that—
lack dedicated cybersecurity staff;
operate on limited budgets; or
have been identified as covered entities, as defined in section 2240 of the Homeland Security Act of 2002 (6 U.S.C. 681);
maintain interoperability and data-sharing arrangements with the Agency, the Federal Bureau of Investigation, and other relevant Federal agencies for the purposes of enhancing the national cyber threat intelligence ecosystem; and
submit annual reports to the Director and to the appropriate congressional committees on—
membership levels of the Multi-State Information Sharing and Analysis Center;
threat intelligence activities;
significant cyber incidents affecting SLTT entities; and
the efficacy of outreach to under-resourced SLTT entities.
Not later than 60 days after the date of enactment of the Guaranteeing Universal Access to Cybersecurity Act, the Director, in coordination with the operator of the Multi-State Information Sharing and Analysis Center, shall develop and implement a plan to—
identify SLTT entities and owners and operators of critical infrastructure that previously held membership in the Multi-State Information Sharing and Analysis Center and have not enrolled in the Multi-State Information Sharing and Analysis Center under the fee-based membership model; and
conduct targeted outreach to restore participation by those SLTT entities and owners and operators of critical infrastructure in the Multi-State Information Sharing and Analysis Center;
identify SLTT entities and owners and operators of critical infrastructure that previously held membership in the Multi-State Information Sharing and Analysis Center and are enrolled in the Multi-State Information Sharing and Analysis Center under the fee-based membership model; and
conduct targeted outreach to retain participation by those SLTT entities and owners and operators of critical infrastructure in the Multi-State Information Sharing and Analysis Center;
identify SLTT entities and owners and operators of critical infrastructure that have never held membership in the Multi-State Information Sharing and Analysis Center and that face elevated cyber risk due to limited cybersecurity resources; and
conduct targeted outreach to encourage participation by those SLTT entities and owners and operators of critical infrastructure in the Multi-State Information Sharing and Analysis Center; and
provide technical assistance and cybersecurity capacity-building support to SLTT entities identified under clauses (i)(I) and (ii)(I), including through partnerships with cyber-capable governments and entities.
Not later than 1 year after the date of enactment of the Guaranteeing Universal Access to Cybersecurity Act, the Director shall submit to the appropriate congressional committees a report on the implementation of this paragraph, including—
the number of SLTT entities re-enrolled in the Multi-State Information Sharing and Analysis Center;
the number of new members enrolled in the Multi-State Information Sharing and Analysis Center since the date of enactment of the Guaranteeing Universal Access to Cybersecurity Act; and
any barriers to participation in the Multi-State Information Sharing and Analysis Center that remain as of the date of the report.
There is appropriated to carry out this subsection $50,000,000 for fiscal year 2027 and each fiscal year thereafter, to remain available until expended.
Section 2209 of the Homeland Security Act of 2002 (6 U.S.C. 659) is amended by adding at the end the following:
The Director shall enter into a cooperative agreement with the operator of the Multi-State Information Sharing and Analysis Center to provide Federal support for—
cybersecurity services;
cyber threat intelligence collection and dissemination; and
technical assistance to SLTT entities.
Any cooperative agreement entered into under subparagraph (A) shall require the operator of the Multi-State Information Sharing and Analysis Center to—
provide no-cost membership and access to core cybersecurity services, including cyber threat intelligence products, real-time indicator feeds, and incident response support, to all SLTT entities that apply for membership in the Multi-State Information Sharing and Analysis Center;
prioritize outreach to and enrollment of SLTT entities that—
lack dedicated cybersecurity staff;
operate on limited budgets; or
have been identified as covered entities, as defined in section 2240 of the Homeland Security Act of 2002 (6 U.S.C. 681);
maintain interoperability and data-sharing arrangements with the Agency, the Federal Bureau of Investigation, and other relevant Federal agencies for the purposes of enhancing the national cyber threat intelligence ecosystem; and
submit annual reports to the Director and to the appropriate congressional committees on—
membership levels of the Multi-State Information Sharing and Analysis Center;
threat intelligence activities;
significant cyber incidents affecting SLTT entities; and
the efficacy of outreach to under-resourced SLTT entities.
Not later than 60 days after the date of enactment of the Guaranteeing Universal Access to Cybersecurity Act, the Director, in coordination with the operator of the Multi-State Information Sharing and Analysis Center, shall develop and implement a plan to—
identify SLTT entities and owners and operators of critical infrastructure that previously held membership in the Multi-State Information Sharing and Analysis Center and have not enrolled in the Multi-State Information Sharing and Analysis Center under the fee-based membership model; and
conduct targeted outreach to restore participation by those SLTT entities and owners and operators of critical infrastructure in the Multi-State Information Sharing and Analysis Center;
identify SLTT entities and owners and operators of critical infrastructure that previously held membership in the Multi-State Information Sharing and Analysis Center and are enrolled in the Multi-State Information Sharing and Analysis Center under the fee-based membership model; and
conduct targeted outreach to retain participation by those SLTT entities and owners and operators of critical infrastructure in the Multi-State Information Sharing and Analysis Center;
identify SLTT entities and owners and operators of critical infrastructure that have never held membership in the Multi-State Information Sharing and Analysis Center and that face elevated cyber risk due to limited cybersecurity resources; and
conduct targeted outreach to encourage participation by those SLTT entities and owners and operators of critical infrastructure in the Multi-State Information Sharing and Analysis Center; and
provide technical assistance and cybersecurity capacity-building support to SLTT entities identified under clauses (i)(I) and (ii)(I), including through partnerships with cyber-capable governments and entities.
Not later than 1 year after the date of enactment of the Guaranteeing Universal Access to Cybersecurity Act, the Director shall submit to the appropriate congressional committees a report on the implementation of this paragraph, including—
the number of SLTT entities re-enrolled in the Multi-State Information Sharing and Analysis Center;
the number of new members enrolled in the Multi-State Information Sharing and Analysis Center since the date of enactment of the Guaranteeing Universal Access to Cybersecurity Act; and
any barriers to participation in the Multi-State Information Sharing and Analysis Center that remain as of the date of the report.
There is appropriated to carry out this subsection $50,000,000 for fiscal year 2027 and each fiscal year thereafter, to remain available until expended.
Legislative Timeline
2 actions-
Introduced in Senate
-
Read twice and referred to the Committee on Homeland Security and Governmental Affairs.