Congress mandates FEMA cybersecurity duty, demands progress report
H.R. 4579 — FEMA Cybersecurity Improvement Act · Filed by Bennie Thompson (D-MS) · Introduced Jul 21, 2025 · Referred to committee
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This bill adds cybersecurity risk mitigation to FEMA's statutory duties under the Homeland Security Act and requires FEMA to submit a progress report to Congress within one year on how it is addressing cybersecurity threats to its own operations. The bill does not create new funding, new enforcement powers, or new restrictions on private entities—it clarifies FEMA's internal operational mandate and creates a reporting requirement to Congress.
Why we flagged it
The bill's operative mechanism is to add cybersecurity risk mitigation as an explicit statutory duty for FEMA and require reporting to Congress. This is a straightforward accountability and transparency measure, not a subsidy, deregulation, or private carve-out.
What the text implies
- The bill references 'section 2200' for the definition of 'cybersecurity risks' but does not restate that definition in this text. The operative scope of FEMA's new duty depends on what section 2200 actually says—a limit of this analysis, not a defect of the bill.
- The one-year reporting deadline creates a near-term accountability checkpoint but does not establish ongoing reporting cadence; Congress may need to revisit the reporting requirement if it wishes continuous oversight.
The full analysis lists 3 implications of this text.
Who it affects
Citizens depend on FEMA for emergency response; a cybersecurity breach could cripple disaster relief. This bill makes cybersecurity a statutory duty for FEMA and mandates public reporting to Congress, improving accountability and reducing the risk that cyber vulnerabilities in emergency systems go unaddressed.