This Act mandates CISA to update security plans for all 16 critical infrastructure sectors to address emerging technology threats like AI and report the comprehensive revisions to Congress.
Mark Warner
Senator
VA
The Combat Emerging Threats to Critical Infrastructure Act of 2026 mandates the CISA Director to update security plans for all 16 critical infrastructure sectors within one year. These updates must specifically address risks posed by disruptive technologies like artificial intelligence and quantum computing. Furthermore, the Act requires CISA to reassess and revise these sector-specific plans biennially to keep pace with evolving threats.
The Combat Emerging Threats to Critical Infrastructure Act of 2026 sets a one-year deadline for the Cybersecurity and Infrastructure Security Agency (CISA) to rewrite the security playbooks for the 16 sectors that keep the country running—ranging from the power grid and water systems to your local hospital and grocery supply chain. This isn't just a routine paperwork update; the bill specifically mandates that these new plans account for high-tech risks like AI-driven hacking, the security of cloud computing, and the way deepfakes or social engineering can be used to trick employees. By mid-2027, every major industry will have a new set of federally coordinated guidelines designed to prevent digital sabotage before it hits your wallet or your thermostat.
This bill focuses on the 'how' of modern sabotage. It requires CISA to look at the entire supply chain of artificial intelligence, including the data used to train it and the software libraries it sits on, to ensure hackers aren't secretly degrading these systems (Section 3). For you, this means the software managing your bank account or the local power plant is required to have a defense strategy against 'poisoned' data or AI-powered network attacks. It also pushes for 'zero trust' principles—a security model that assumes a breach could happen at any moment and requires constant verification—moving away from older, 'fortress-style' security that is easily bypassed once a single password is stolen.
One of the most forward-looking parts of the bill targets the financial sector. It requires CISA and the Treasury Department to identify vulnerabilities in digital assets—like the encryption protecting your online transactions—that could be cracked by future quantum computers (Section 3). While quantum computing sounds like sci-fi, the bill treats it as a looming reality for banking security. By identifying these 'cryptographic risks' now, the goal is to swap out old security locks before the technology exists to pick them, aiming to keep your digital identity and assets secure as computing power explodes.
Because technology moves faster than Congress, the bill includes a 'use it or lose it' style maintenance requirement. Every two years, CISA must reassess and revise these plans to ensure they aren't gathering dust while new threats emerge (Section 4). This biennial check-up means that if a new type of digital threat becomes popular in 2028, the 2029 security plans for sectors like transportation and emergency services are legally required to address it. It’s an attempt to turn a slow-moving bureaucracy into a more agile defense system that keeps pace with the apps and tech we use every day.