Missouri 2025 Regular Session

Missouri House Bill HB1231

Introduced
2/6/25  

Caption

Creates new provisions related to infrastructure security

Summary

HB 1231 creates two new Missouri statutes: the Missouri Critical Infrastructure Protection Act and the Missouri Secure Communications Act. The bill is aimed at protecting critical infrastructure and communications systems from foreign adversary influence, cyber intrusion, and equipment or software deemed risky to state security. It defines critical infrastructure broadly to include energy, water, telecommunications, electrical power, emergency services, transportation, and data storage/cybersecurity systems, and it also defines foreign adversaries, foreign principals, and federally banned corporations for purposes of restricting contracts and equipment use. Under the critical infrastructure provisions, companies and governmental entities would be barred from entering certain contracts with foreign principals from foreign adversary ქვეყნies if those agreements would allow direct or remote access to critical infrastructure. The bill requires certification and fees to the Department of Public Safety, background checks for employees with access, disclosure of foreign ownership or control, domestic data storage, reporting of cyber incidents, and notice to the state before sales, transfers, or investments involving foreign ownership. It also authorizes the Department of Public Safety and the attorney general to seek injunctions to block transactions found to threaten infrastructure, economic security, or public health. The bill further prohibits state infrastructure software from including software produced by companies headquartered in or controlled by foreign adversaries, and after August 28, 2025, restricts certain vendors and products, including traffic enforcement systems, surveillance equipment, LiDAR, and Wi-Fi routers/modems, from foreign-adversary ownership or control. The communications section would prohibit critical communications infrastructure in Missouri from using equipment manufactured by federally banned corporations, including equipment identified by the FCC as a national security risk. Communications providers using such equipment would have to register with the Public Service Commission, pay fees, update information annually, and file quarterly reports if participating in the federal rip-and-replace reimbursement program. The PSC would also publish a quarterly map of prohibited equipment locations. Violations could result in daily fines, and noncompliant providers would be barred from receiving certain state, local, and federal funds for communications infrastructure development or support. The bill’s impact on state law would be substantial, creating new compliance, reporting, and enforcement obligations for private companies, utilities, communications providers, and governmental entities that operate or contract for infrastructure in Missouri. It would expand the Department of Public Safety’s role in reviewing contracts, monitoring threats, and maintaining public listings of prohibited products and companies, while also giving the Public Service Commission new oversight duties for communications equipment. The bill would likely affect procurement, cybersecurity practices, vendor selection, ownership disclosures, and infrastructure modernization projects across multiple sectors. No committee discussion or votes were provided, so there is no recorded legislative sentiment in the supplied materials. Based on the bill text alone, the measure appears to be motivated by national-security and cybersecurity concerns, with a strong emphasis on limiting foreign adversary access to sensitive systems. Potential points of contention likely include the breadth of the restrictions, the cost and feasibility of compliance, the impact on existing contracts and infrastructure upgrades, and whether the bill could limit vendor choice or increase costs for public entities and private operators.

Impact

HB 1231 would add two new sections to Chapter 1, RSMo, creating statewide restrictions on foreign-adversary involvement in critical infrastructure and communications infrastructure. It would impose registration, certification, reporting, background-check, data-storage, and procurement requirements on affected companies and governmental entities, while also authorizing state agencies to investigate, publish prohibited-product lists, and seek court action to block certain transactions. The bill would also establish penalties and funding restrictions for noncompliance, and it would affect statutes and practices governing public safety, procurement, telecommunications, cybersecurity, and infrastructure ownership.

Sentiment

No votes or committee testimony were provided, so there is no documented public or legislative sentiment in the record supplied. The bill’s text suggests a security-focused, precautionary approach that would likely appeal to lawmakers concerned about foreign influence, cyber threats, and critical infrastructure resilience. At the same time, the scope of the restrictions and compliance obligations suggests the measure could draw concern from affected industries and public entities over cost, implementation, and operational flexibility.

Contention

The main likely points of contention are the bill’s broad definitions and sweeping restrictions on foreign-adversary-linked companies, software, and equipment. Opponents may argue that the bill could be difficult to administer, expensive to comply with, and disruptive to existing infrastructure and procurement arrangements, especially where replacement equipment or software is not readily available. Supporters would likely emphasize national security, cyber defense, and supply-chain protection, while critics may focus on the risk of overbreadth, market disruption, and the practical burden on utilities, communications providers, and government agencies.

Companion Bills

No companion bills found.

Similar Bills

No similar bills found.