The bills that would reach private operators — and where each one is stuck
The one federal cybersecurity grant program for state and local government excludes the private owner-operators who hold most of America's critical infrastructure. Several bills would fix that. None has moved.
Status verified September 23, 2026. Bill status changes; this page is updated as it does.
There is a gap in federal cybersecurity funding that has nothing to do with money and everything to do with eligibility.
The only federal cybersecurity grant program aimed at state and local government is the State and Local Cybersecurity Grant Program, created by the Infrastructure Investment and Jobs Act and codified at 6 U.S.C. §665g. FEMA's own notice of funding opportunity for FY2025 puts the boundary plainly: eligible subrecipients include local governments and do not include nonprofit and for-profit organizations.
Read that against who actually owns American critical infrastructure. Electric cooperatives, private nonprofit rural hospitals, investor-owned utilities and the small suppliers feeding the defense industrial base are excluded by category — not by score, not by merit, not by need. The organizations holding the most exposed operational technology in the country are outside the one program built to help.
And the program's own authority is in question. Subsection (s)(1) of §665g states that the requirements of the section terminate on September 30, 2026. It was extended once this year, by Public Law 119-75, which substituted "September 30, 2026" for "September 30, 2025" in that subsection alone. It did not touch the cost-share table in (m), which runs FY2022 through FY2025 and has no FY2026 row, nor the authorization of appropriations in (r), which likewise ends at FY2025.
So here is where the bills come in. Several would close the eligibility gap. None of them has moved.
The reauthorization vehicles
S. 3251 and H.R. 5078 — PILLAR Act and SLCGP Reauthorization. H.R. 5078 passed the House by voice vote on November 17, 2025. S. 3251 was introduced on November 20, 2025. Referral is the entire action history of both; there has been nothing since.
As passed the House, PILLAR reauthorizes the grant program through FY2033, adds operational technology and AI systems, permits spending on legacy and no-longer-supported OT, and lets a local government petition DHS when a state stalls. S. 3251 is narrower — its official title authorizes grants for fiscal year 2026 only.
Both keep eligibility at "a State; or a Tribal government." The most developed reauthorization vehicle in Congress would not, as written, reach a single private owner-operator.
The bill that already solves it
H.R. 7266 and S. 5360 — Rural and Municipal Utility Cybersecurity Act. H.R. 7266 passed the House on June 29, 2026 and has been in Senate Energy and Natural Resources since July 13. S. 5360 was introduced August 7, 2026, and ENR held a legislative hearing on it September 16.
It authorizes $250,000,000 for FY2027 through FY2031, and its eligibility clause reaches rural electric cooperatives, municipally owned and political-subdivision utilities, and investor-owned utilities selling under 4,000,000 MWh per year — plus not-for-profits partnering with six or more qualifying utilities.
This is the one to watch. The eligibility language already does what the grant program will not. The drafting problem is solved; what remains is whether it moves.
Sector by sector
S. 5368 — Water Cyber Shield Act of 2026. Introduced August 7, 2026, referred to Senate Environment and Public Works. One cosponsor, no hearing. It would have EPA establish baseline cybersecurity standards by rulemaking, reaching operational technology through the assessment loop, with $300,000,000 per year for FY2027–2032 across two separate funds. It also amends the CIRCIA covered-entity definition to include community water systems serving more than 3,300 people. It is the only pending bill that reaches installed OT and carries money.
S. 3315 — Health Care Cybersecurity and Resiliency Act of 2026. Reported by the HELP Committee on March 23, 2026 and placed on the Senate Calendar. It has sat there six months. Grants would go to federally qualified health centers, Indian Health Service facilities, nonprofit hospitals and rural health clinics — and for-profit hospitals are not eligible, which makes it a live example of the same carve-out producing partial coverage.
H.R. 7305 — Energy Threat Analysis Center Act of 2026. Passed the House June 29, 2026; in Senate ENR since July 13. It reauthorizes the Department of Energy's operational support program for cyber resilience for FY2027–2031. Read the eligibility language carefully: its "governmental or private entity" phrasing is discretionary and creates no entitlement to assistance.
S. 4728 — Combat Emerging Threats to Critical Infrastructure Act of 2026. Introduced June 10, 2026, in Senate Homeland Security and Governmental Affairs. No hearing, no markup. It would require CISA and the Sector Risk Management Agencies to update sector-specific plans for all sixteen sectors within a year, then reassess at least every two years. It is the only all-sixteen-sector bill pending.
S. 5061 — Secure A.I. Development Act of 2026. Introduced July 21, 2026, Senate Commerce. It directs that critical-infrastructure operators shall access a secure test-bed for testing the impact of frontier AI models — notable for putting frontier-model testing in front of operators rather than vendors.
H.R. 9797 — RESILIENCE Act of 2026. Introduced July 21, 2026. Its core is a one-year training pilot for state, local, tribal and territorial governments. Secondarily, CISA may maintain clearinghouses for owners and operators to access voluntary guidance. Note the verb: may maintain, not shall establish.
Two water bills are effectively dormant: H.R. 2594, which would establish a Water Risk and Resilience Organization, has had no action in roughly eighteen months, and S. 1549, the Water Cybersecurity Enhancement Act of 2025, has had nothing since introduction.
Why waiting is not a strategy
Every door is narrow. The FY2027 Homeland Security appropriations bill, H.R. 9310, contains a $50,000,000 line for the grant program, but it has three actions in its entire history and no scheduled floor time — and it would appropriate money to a program whose authorizing statute has lapsed. On defense authorization, the House passed its bill in July and the Senate's own measure failed cloture; there is no conference, because there is no Senate-passed NDAA.
That is the honest position: the fix is drafted, it is sitting in committee, and the organizations that need it are the ones the current program was never written to reach.
If you operate a clinic, a co-op, a small utility or a plant, the practical conclusion is not to wait for a grant. The equipment most at risk is the equipment you already own and cannot replace — controllers, cameras, building systems, clinical devices that cannot run security software of their own. A Faction Pod sits in front of that equipment and handles authentication and encryption on its behalf, with nothing installed on the device and nothing about it changed. It joins a network that is invisible and unreachable from the internet, where access is granted by key possession rather than a policy administered elsewhere.
Sources: bill text and status via Congress.gov · 6 U.S.C. §665g · FEMA SLCGP
Own your trust. Keep your peace of mind.
The new threat environment calls for a new Zero Trust model. We'd welcome the chance to show you how Faction puts you in control and secures your critical systems and assets rapidly with low cost and IT overhead.