USDA to map food-supply cybersecurity gaps with annual crisis drills
S. 754 — Farm and Food Cybersecurity Act of 2025 · Filed by Tom Cotton (R-AR) · 9 cosponsors · Introduced Feb 26, 2025 · Referred to committee
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This bill directs the U.S. Department of Agriculture to conduct biennial risk assessments of cybersecurity threats to farms, food processors, and food distribution networks, in coordination with federal cybersecurity agencies. It also requires annual crisis simulation exercises over five years to test government and private-sector readiness for food-supply emergencies caused by cyberattacks or other disruptions, with $5 million in total funding authorized.
Why we flagged it
The bill's core function is to mandate federal risk assessment and simulation exercises for cybersecurity threats to agriculture and food systems. It is a public-health and national-security measure, not a subsidy, deregulation, or private-sector carve-out.
What the text implies
- The bill's language about 'intrusive, duplicative, or conflicting regulatory requirements' in the risk assessment may signal an intent to recommend regulatory relief for the agriculture sector, potentially weakening existing food-safety or environmental rules under the guise of cybersecurity efficiency.
- Annual simulation exercises involving private-sector cybersecurity firms and equipment manufacturers (explicitly named in the design section) may create recurring consulting and contracting opportunities for those vendors, though the bill does not mandate procurement from specific companies.
The full analysis lists 3 implications of this text.
Who stands to gain
cybersecurity consulting firms; IT infrastructure and equipment manufacturers; food-sector technology vendors