HB7266, titled the Rural and Municipal Utility Cybersecurity Act, reauthorizes and updates the Rural and Municipal Utility Advanced Cybersecurity Grant and Technical Assistance Program in the Infrastructure Investment and Jobs Act. The bill directs the Secretary to maintain a program that provides technical assistance and awards funding, including grants, cooperative agreements, and prizes, to eligible electric utilities and related entities to help them protect against, detect, respond to, and recover from cybersecurity threats.
The bill defines key terms such as advanced cybersecurity technology, eligible entity, bulk-power system, and defense critical electric infrastructure. It also sets program objectives to deploy advanced cybersecurity technologies for electric utility systems and to increase participation in cybersecurity threat information-sharing programs. The Secretary must develop criteria for assistance and funding, ensure eligible entities are informed about opportunities, and prioritize entities with limited cybersecurity resources or those that own assets critical to grid reliability or defense critical infrastructure.
Impact
HB7266 would amend section 40124 of the Infrastructure Investment and Jobs Act and extend federal support for cybersecurity improvements in the electric utility sector. It authorizes $250 million for fiscal years 2026 through 2030 and expands the federal role in assisting rural electric cooperatives, municipal utilities, certain public power entities, qualifying not-for-profit partnerships, and smaller investor-owned utilities. The bill also protects information shared under the program from disclosure under federal, state, tribal, and local open records or freedom of information laws, which could affect transparency rules for participating entities and governments.
Sentiment
The available context suggests the bill moved forward without recorded controversy: there are no committee transcripts or recorded votes in the provided materials, and the last action notes that a motion to reconsider was laid on the table and agreed to without objection. The bill’s framing as a cybersecurity and grid-resilience measure indicates generally supportive sentiment, especially for rural and municipal utilities that may lack resources to address cyber threats on their own.
Contention
The main policy tension in the bill is between expanding cybersecurity support and limiting public disclosure of information shared through the program. The exemption from FOIA and similar state, tribal, and local transparency laws may draw concern from open-government advocates, even though it is intended to encourage candid information sharing about vulnerabilities. Another possible point of debate is the prioritization of limited federal funds toward entities with the greatest need or critical infrastructure responsibilities, which could raise questions about eligibility and allocation criteria.
Requires businesses in financial essential infrastructure, and health care industries to develop cybersecurity plans and report cybersecurity incidents.
Relating to the establishment of the Texas Cyber Command and the transfer to it of certain powers and duties of the Department of Information Resources.