Congress funds cybersecurity for state and local governments through 2033
H.R. 5078 — Protecting Information by Local Leaders for Agency Resilience Act · Filed by Andrew Ogles (R-TN) · 4 cosponsors · Introduced Sep 2, 2025 · Passed chamber
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This bill reauthorizes and expands CISA's State and Local Cybersecurity Grant Program through fiscal year 2033, adding new definitions and requirements around artificial intelligence systems, multi-factor authentication, and foreign entity restrictions. It increases federal cost-sharing for states and localities that adopt multi-factor authentication by October 2027, mandates outreach to rural and under-resourced jurisdictions, and requires GAO reviews of the program including AI adoption tracking.
Why we flagged it
The bill's core function is reauthorizing and expanding a federal grant program for state and local cybersecurity resilience, with new AI-related definitions and foreign-entity restrictions. It is a straightforward infrastructure-protection measure, not a deregulation, tax provision, or commemorative act.
What the text implies
- The requirement that states/localities adopt multi-factor authentication by October 1, 2027 to receive higher federal cost-sharing (65–75% vs. 60–70%) creates a de facto mandate for a specific security technology, potentially favoring vendors offering MFA solutions and creating compliance pressure on under-resourced jurisdictions.
- The ban on purchasing software/hardware from 'foreign entities of concern' (defined by the CHIPS Act) may restrict procurement options for state and local governments and could increase costs if domestic alternatives are more expensive or less mature.
The full analysis lists 5 implications of this text.
Who stands to gain
cybersecurity software and hardware vendors (especially those offering multi-factor authentication,; managed security service providers and cybersecurity consulting firms; academic and nonprofit cybersecurity clinics and technical assistance programs