HB1604, the Farm and Food Cybersecurity Act of 2025, would direct the Secretary of Agriculture to regularly assess cybersecurity threats and vulnerabilities affecting the agriculture and food critical infrastructure sector. The bill defines that sector broadly to include the production, processing, distribution, storage, transportation, consumption, and disposal of agricultural and food products, and it requires the Department of Agriculture to consult with private-sector partners such as the Food and Agriculture-Information Sharing and Analysis Center and sector coordinating councils when conducting its assessments.
The bill also requires an annual cross-sector simulation exercise over a five-year period to test preparedness for a food-related emergency or disruption. Those exercises would involve multiple federal agencies, state, tribal, local, territorial, and private-sector participants, and would be designed to identify gaps in the food supply chain, improve coordination and information sharing, and generate recommendations for strengthening food security and resilience. The Secretary would provide feedback after each exercise and submit a report to Congress summarizing findings, lessons learned, and recommendations.
In addition to the exercise requirement, the bill mandates a biennial cybersecurity risk assessment and report to congressional committees beginning within one year of enactment. The assessment must examine the nature of cyberattacks, potential impacts on food availability, public health, the economy, and national security, as well as the readiness of government and private-sector entities to prevent, detect, respond to, and recover from incidents. It also directs the Secretary to identify existing policies and any gaps, barriers, or conflicting regulatory requirements that may hinder operational security efforts.
The bill’s impact on state and federal practice would be to create a new federal planning, reporting, and coordination framework for food and agriculture cybersecurity, but it does not directly amend state statutes or impose a new regulatory regime on states. Its main legal effect is to require USDA-led assessments, interagency coordination, and recurring reports and exercises, with an authorized appropriation of $1 million annually from fiscal years 2026 through 2030 to carry out the program.
The overall sentiment reflected by the bill text is preventative and collaborative, emphasizing resilience, preparedness, and information sharing rather than enforcement or punishment. Because there are no committee transcripts or recorded votes provided, there is no documented floor or committee controversy in the available materials. The only notable point of potential contention visible in the text is the bill’s explicit concern that duplicative or conflicting regulations could divert resources away from actual security improvements, suggesting an interest in minimizing compliance burdens on industry.
HB1604 would establish a federal cybersecurity and resilience planning mandate for the agriculture and food critical infrastructure sector, requiring USDA to conduct biennial threat assessments, consult with private-sector stakeholders, and report findings to Congress. It would also require annual cross-sector simulation exercises for five years, coordinated with multiple federal agencies and public/private stakeholders, and authorize $1 million per year for implementation. The bill does not directly change state law, but it would influence federal agency practice and could affect farmers, ranchers, processors, distributors, retailers, regulators, and related supply-chain participants through increased coordination and preparedness expectations.
The bill appears broadly supportive of proactive risk management and cross-sector cooperation. Its framing suggests bipartisan interest in protecting food systems from cyber threats and disruptions, with emphasis on resilience, preparedness, and practical recommendations. No votes or committee debate are provided, so there is no recorded opposition or support to gauge beyond the bill’s collaborative structure and its inclusion of multiple sponsors from both parties.
No formal contention is documented in the provided materials because there are no committee transcripts or votes. The text itself hints at one likely area of debate: the bill’s concern that intrusive, duplicative, or conflicting regulatory requirements could undermine operational security by shifting attention toward compliance. That language suggests stakeholders in agriculture and food industries may favor the bill’s coordination focus while remaining wary of added administrative burdens or overlapping federal requirements.