US Federal 2025-2026 Regular Session

US Federal House Bill HB6309

Introduced
 
Introduced
11/25/25  

Caption

Cyber Deterrence and Response Act of 2025

Summary

HB6309, titled the Cyber Deterrence and Response Act of 2025, would create a new federal sanctions regime aimed at foreign persons, foreign state agencies, and governments involved in state-sponsored cyber activities against the United States. The bill directs the President, acting through the National Cyber Director and in coordination with other agencies, to designate “critical cyber threat actors” under a new National Attribution Framework. Those designations would cover actors tied to cyber operations that significantly threaten U.S. national security, foreign policy, economic health, financial stability, critical infrastructure, financial systems, energy systems, or election and government institutions, as well as those who materially support such activity or knowingly profit from misappropriated data or trade secrets. The bill also requires the National Cyber Director to develop a formal attribution framework within 180 days, setting evidentiary standards, confidence levels, timelines, and procedures for using private-sector threat intelligence and coordinating with allies. Once a designation is made, the President must report it to Congress within seven days. The measure authorizes a broad set of non-travel sanctions, including restrictions on foreign assistance, opposition to multilateral lending, limits on development finance, procurement bans, export controls, blocking of property and financial transactions, and restrictions under the International Emergency Economic Powers Act. It also imposes travel-related sanctions by making designated aliens inadmissible and revoking existing visas. In addition to sanctions on individual actors, the bill allows the President to impose country-level sanctions on governments that aid, abet, or direct designated cyber actors. Those sanctions can include cutting off assistance, opposing international financial institution support, and banning exports of defense articles, Commerce Control List items, intrusion software, and IP network surveillance tools to the government or entities under its control. The bill includes exemptions for authorized U.S. intelligence activities, waiver authority for national interest, law enforcement, or humanitarian reasons, and a process for removing sanctions if the conduct stops and assurances are given. It also preserves existing presidential authority under other sanctions laws. The overall sentiment reflected in the bill text is strongly supportive of a tougher, more structured U.S. response to foreign cyber operations. The legislation emphasizes deterrence, coordination with allies, and rapid attribution, suggesting a policy approach focused on pressure, accountability, and international alignment rather than ad hoc responses. Because there are no committee transcripts or votes provided, there is no recorded debate or formal voting record here to indicate broader political support or opposition. The main points of potential contention are the breadth of the designation authority, the scope of sanctions, and the reliance on attribution judgments that may involve classified or contested intelligence. The bill’s inclusion of entities that materially support cyber actors, as well as persons who knowingly use misappropriated data for commercial gain, could raise concerns about overbreadth or unintended effects on third parties. Other likely issues include the impact on diplomacy, trade, and financial institutions, the reach of export and procurement restrictions, and the balance between rapid action and due process through waivers, exemptions, and appeals.

Impact

HB6309 would add a new statutory framework for identifying and sanctioning foreign cyber actors, expanding the federal government’s tools under sanctions, export control, immigration, and financial authorities. It would require the National Cyber Director to establish a formal attribution process and would authorize the President to impose targeted and country-level penalties affecting foreign assistance, defense sales, procurement, investment, visas, and transactions involving property or exports. The bill would not repeal existing authorities, but it would layer a specific cyber-sanctions regime on top of current law, especially the Foreign Assistance Act, the Immigration and Nationality Act, the Export Administration Regulations, and the International Emergency Economic Powers Act.

Sentiment

The bill’s tone and structure indicate a generally hawkish, security-focused sentiment aimed at deterring foreign cyber aggression and signaling a stronger U.S. response to state-sponsored hacking. It frames cyber operations as a national security, economic, and democratic integrity threat and seeks to institutionalize faster attribution and coordinated allied action. No committee discussion or vote data were provided, so there is no recorded legislative opposition or support beyond the bill’s text and referral status.

Contention

Likely areas of contention include how broadly “critical cyber threat actor” is defined, whether the attribution standards are sufficiently objective, and how much discretion the President has to impose or waive sanctions. Critics may also question the risk of collateral damage to innocent parties, private-sector firms, or diplomatic relationships, especially where sanctions extend to supporting entities, procurement bans, and export restrictions. Supporters are likely to emphasize deterrence, accountability, and the need for a clear framework to respond to ransomware, espionage, critical infrastructure attacks, election interference, and theft of trade secrets.

Companion Bills

No companion bills found.

Previously Filed As

US SB435

IRONDOME Act of 2025 Increasing Response Options and Deterrence of Missile Engagements Act of 2025

US SB3404

Satellite Cybersecurity Act of 2025

US HB1716

Taiwan Conflict Deterrence Act of 2025

US SB1851

Healthcare Cybersecurity Act of 2025

US HB3841

Healthcare Cybersecurity Act of 2025

US HB1604

Farm and Food Cybersecurity Act of 2025

US HB912

9–8–8 Lifeline Cybersecurity Responsibility Act

US SB1136

DETERRENCE Act Deterring External Threats and Ensuring Robust Responses to Egregious and Nefarious Criminal Endeavors Act

US SB1875

Streamlining Federal Cybersecurity Regulations Act of 2025

US HB7625

MTS CYBER Act of 2026 Marine Transportation System Cybersecurity Budget and Evaluation Report Act of 2026

Similar Bills

No similar bills found.