Protecting Critical Infrastructure Act
HB3278, the Protecting Critical Infrastructure Act, would increase federal criminal penalties for certain computer fraud and related offenses when the offense involves critical infrastructure. Under the bill, an offense involving critical infrastructure could be punished by a fine and imprisonment for not less than 30 years or for life, significantly raising the stakes for cyberattacks targeting systems such as energy, communications, transportation, water, and other essential sectors covered by the federal critical infrastructure definition.
The bill also creates a new sanctions regime directed at foreign persons who knowingly access or attempt to access critical infrastructure for the purpose of harming U.S. national security, defense, or the safety and security of U.S. citizens and lawful permanent residents. Those sanctions would include blocking property and interests in property under the International Emergency Economic Powers Act, visa ineligibility and revocation, and related immigration consequences, with a narrow exception for compliance with U.N. Headquarters Agreement obligations. The President would have waiver authority for up to 180 days on a case-by-case basis if the waiver is certified as vital to U.S. national security interests, and the bill directs the executive branch to issue implementing regulations within 90 days.
In practical terms, the bill would amend title 18 of the U.S. Code to create a much harsher penalty tier for cyber-related offenses tied to critical infrastructure and would expand the federal government’s tools for responding to foreign cyber actors through sanctions and immigration restrictions. It would affect defendants prosecuted under the Computer Fraud and Abuse Act framework, foreign individuals and entities subject to sanctions, and U.S. persons and institutions that may be required to comply with blocking and transaction prohibitions.
The available context shows no recorded committee debate or votes, so there is no documented partisan or stakeholder sentiment in the materials provided. Based on the bill’s framing and sponsors, the measure appears intended as a national security and cyber-defense response to threats against essential infrastructure, suggesting generally supportive sentiment around protecting critical systems. At the same time, the bill’s very severe sentencing provisions and broad sanctions authority could raise concerns about proportionality, executive discretion, and the reach of immigration and financial penalties, though those objections are not reflected in the provided record.
The bill would amend 18 U.S.C. § 1030(c) to add a new penalty category for computer fraud and related offenses involving critical infrastructure, authorizing a fine and imprisonment for not less than 30 years or for life. It would also authorize the President to impose sanctions on foreign persons who knowingly access or attempt to access critical infrastructure to harm U.S. national security or the safety and security of U.S. persons, using authorities under the International Emergency Economic Powers Act and the Immigration and Nationality Act. The bill would require implementing regulations and define key terms such as foreign person, United States person, and knowingly.
No committee transcripts or votes were provided, so there is no direct record of support or opposition in the available materials. The bill’s title, sponsors, and structure indicate a strong security-oriented purpose focused on deterring cyberattacks against critical infrastructure, which suggests an overall protective and punitive policy posture. Any broader sentiment beyond that cannot be reliably inferred from the record provided.
The main potential points of contention are the bill’s very severe sentencing enhancement—30 years to life for qualifying offenses—and the breadth of the new sanctions authority over foreign persons. Critics could question whether the penalty is proportionate, whether the definition of critical infrastructure is too expansive, and whether the President’s waiver and implementation powers provide sufficient guardrails. Supporters are likely to emphasize deterrence, national security, and the need to respond forcefully to foreign cyber threats against essential systems.