Congress creates cybersecurity waiver authority, bypassing public comment rules
S. 1875 — Streamlining Federal Cybersecurity Regulations Act of 2025 · Filed by Gary Peters (D-MI) · 1 cosponsor · Introduced May 22, 2025 · Referred to committee
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This bill creates a federal Harmonization Committee led by the National Cyber Director to align cybersecurity regulations across different government agencies and sectors. The committee will develop a common baseline of cybersecurity requirements, identify conflicting or redundant rules, and run a 7-year pilot program allowing selected agencies to waive or modify rules for participating companies—with the goal of reducing regulatory burden while maintaining security standards.
Why we flagged it
The bill frames itself as a coordination and efficiency measure, but its core mechanism is to establish a committee with authority to waive cybersecurity requirements during a 7-year pilot, effectively creating a deregulation pathway that bypasses standard Administrative Procedure Act notice-and-comment processes.
What the text implies
- The pilot program grants regulatory agencies authority to issue waivers and establish alternative procedures 'notwithstanding' the Administrative Procedure Act, potentially allowing cybersecurity rules to be suspended or modified without full public comment periods, reducing transparency in how security standards are set.
- Reciprocity provisions allow one agency's assessment of compliance to satisfy another agency's requirements, which may create a 'lowest common denominator' effect where a company complying with a weaker regulator's standard is deemed compliant across all sectors, potentially lowering overall security posture.
The full analysis lists 5 implications of this text.
Who stands to gain
Large financial institutions and critical infrastructure operators (banks, energy, telecom) subject; Cybersecurity consulting and compliance firms (Cognizant, Accenture, others) that may benefit from h; Technology vendors (Cisco, HPE, AMD, Verisign) whose products are subject to varying security certif