Pentagon gets new legal authority for offensive cyber operations
S. 2602 — A bill to amend title 10, United States Code, to expand the scope of affirmation of authority for cyber operations to include defense of critical infrastructure of the Department of Defense, and for other purposes. · Filed by Mike Rounds (R-SD) · Introduced Jul 31, 2025 · Referred to committee
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This bill amends federal law to authorize the Department of Defense to conduct offensive cyber operations to defend its own critical infrastructure—computer systems, networks, and facilities essential to military operations. Previously, DoD cyber authority was limited to force protection; this expands it to include infrastructure defense, and defines 'critical infrastructure' as assets whose loss would severely degrade military capability.
Why we flagged it
The bill's sole function is to expand the legal scope of DoD cyber operations authority. It is a straightforward amendment to existing military law, not a rider or concealed provision.
What the text implies
- The definition of 'critical infrastructure' is not limited to purely military systems—it could encompass dual-use infrastructure (power grids, communications networks) that serves both DoD and civilian populations, potentially authorizing offensive cyber operations affecting civilians.
- The bill does not establish new congressional notification, reporting, or approval requirements for cyber operations under the expanded authority, leaving oversight to executive discretion.
The full analysis lists 4 implications of this text.
Who stands to gain
defense contractors specializing in cyber defense and offensive cyber capabilities; military technology vendors