QuorumCivic. Hidden in plain sight Get the app
Bill intelligence

Congress funds cybersecurity for state and local governments through 2033

H.R. 5078 — Protecting Information by Local Leaders for Agency Resilience Act · Filed by Andrew Ogles (R-TN) · 4 cosponsors · Introduced Sep 2, 2025 · Passed chamber

65%
Transparency
Typical bill: 82%
15/100
Hidden-provision risk
Typical bill: 15/100
Cybersecurity Infrastructure Grant…

Your members of Congress

Enter a ZIP to see where your representative and both senators stood on this bill.

Looked up on this device — your ZIP is never stored on our servers.

What it does

This bill reauthorizes and expands CISA's State and Local Cybersecurity Grant Program through fiscal year 2033, adding new definitions and requirements around artificial intelligence systems, multi-factor authentication, and foreign entity restrictions. It increases federal cost-sharing for states and localities that adopt multi-factor authentication by October 2027, mandates outreach to rural and under-resourced jurisdictions, and requires GAO reviews of the program including AI adoption tracking.

Why we flagged it

The bill's core function is reauthorizing and expanding a federal grant program for state and local cybersecurity resilience, with new AI-related definitions and foreign-entity restrictions. It is a straightforward infrastructure-protection measure, not a deregulation, tax provision, or commemorative act.

What the text implies

  • The requirement that states/localities adopt multi-factor authentication by October 1, 2027 to receive higher federal cost-sharing (65–75% vs. 60–70%) creates a de facto mandate for a specific security technology, potentially favoring vendors offering MFA solutions and creating compliance pressure on under-resourced jurisdictions.
  • The ban on purchasing software/hardware from 'foreign entities of concern' (defined by the CHIPS Act) may restrict procurement options for state and local governments and could increase costs if domestic alternatives are more expensive or less mature.

The full analysis lists 5 implications of this text.

Who stands to gain

cybersecurity software and hardware vendors (especially those offering multi-factor authentication,; managed security service providers and cybersecurity consulting firms; academic and nonprofit cybersecurity clinics and technical assistance programs

Correlative observation from public records — not evidence of coordination or wrongdoing, and not financial advice.
This page is the record as of today. The app tells you when it changes.
Quorum analysis of the full bill text · 119th Congress · public record