SB 453 creates the Kansas Critical Infrastructure Protection Act, a new framework aimed at limiting foreign access to Kansas critical infrastructure and restricting the purchase or use of certain software, hardware, and technology tied to designated “countries of concern.” Those countries are China (including Hong Kong), Cuba, Iran, North Korea, Russia, and Venezuela, while Taiwan is expressly excluded. The bill defines critical infrastructure broadly to include physical and virtual systems vital to state or national security, economic security, public health, and related functions, and it covers items such as data storage systems, cybersecurity systems, routers, cameras, and laser sensor technology.
The bill would prohibit state agencies and companies working on critical infrastructure from entering agreements with foreign principals if those agreements would allow direct or remote access to the infrastructure. It also requires replacement of certain preexisting critical components with U.S.-domiciled, U.S.-manufactured alternatives when they are replaced, unless an exception is approved by the adjutant general under a necessity-and-security standard. In addition, companies seeking access to state critical infrastructure would need certification from the adjutant general, including background checks, disclosure of foreign ownership or control, domestic data storage and processing, restrictions on foreign access, and immediate reporting of cyber incidents. The adjutant general would also be responsible for investigating proposed foreign sales, transfers, or investments in critical infrastructure and could seek an injunction through the attorney general if a transaction is suspected to threaten security.
SB 453 further bans state infrastructure from using software produced in a country of concern, software or hardware owned by a foreign principal, or software otherwise barred by federal law, with prohibited software to be removed or disabled by January 1, 2027. It also restricts government contracts for wireless routers, modems, traffic enforcement camera systems, and LiDAR technology when the vendor is a foreign principal or the product is made in a country of concern. The adjutant general must maintain public lists of prohibited router/modem and traffic camera/LiDAR technologies, and must adopt rules to implement the act. The measure is severable and takes effect upon publication in the statute book.
The overall sentiment reflected in the bill text is strongly security-focused and precautionary, emphasizing protection against foreign influence, cyber threats, and supply-chain vulnerabilities in state infrastructure. Because there are no committee transcripts or recorded votes provided, there is no documented floor or committee debate to indicate support or opposition in the available materials. The structure of the bill suggests an intent to give the adjutant general broad oversight authority while creating multiple compliance obligations for agencies, contractors, and infrastructure owners.
Potential points of contention include the breadth of the “country of concern” and “foreign principal” definitions, the practical burden of certification, background checks, domestic data-storage requirements, and replacement mandates, as well as the scope of the adjutant general’s discretion to approve otherwise prohibited acquisitions. The restrictions on software, routers, cameras, and LiDAR could also raise cost, procurement, and implementation concerns for agencies and infrastructure operators that rely on existing vendors or global supply chains.
SB 453 would add a new chapter of state policy governing procurement, ownership changes, and cybersecurity-related access for Kansas critical infrastructure. It would affect state agencies, contractors, and owners/operators of critical infrastructure by barring certain foreign-linked products and services, requiring certification and reporting to the adjutant general, and mandating removal of prohibited software and replacement of certain components with U.S.-based alternatives. The bill would also create new administrative duties for the adjutant general and attorney general, including certification, rulemaking, public prohibited-technology lists, investigations, and possible injunction actions.
The bill’s apparent sentiment is generally supportive of stronger infrastructure security and reduced foreign dependence, with a clear national-security and cyber-defense orientation. No committee testimony or vote history is available in the provided materials, so there is no recorded evidence of bipartisan support, opposition, or amendments. Based on the text alone, the measure appears designed to appeal to lawmakers concerned about espionage, cyberattacks, and supply-chain risk.
The main likely points of contention are the bill’s broad restrictions on foreign-linked companies and products, the administrative and compliance burden on agencies and private infrastructure operators, and the potential cost of replacing existing equipment and software. The requirement that the adjutant general certify companies, approve exceptions, and maintain prohibited-technology lists gives significant discretion to that office, which could also be debated. Critics may question whether the definitions of “country of concern,” “foreign principal,” and “critical infrastructure” are too expansive, while supporters are likely to argue that the restrictions are necessary to protect security and public safety.