HB 8710, the National Defense Data Resilience Act, would require the Secretary of Defense to establish and implement Department of Defense-wide data recovery requirements for data that is designated as critical, important, or necessary. The bill directs DoD to set mandatory recovery time objectives for critical data within 180 days of enactment, and for important and necessary data within 270 days, with those objectives based on data type and threat exposure and updated as intelligence on evolving threats changes. It also requires annual auditable recovery certification reports to the congressional defense committees.
The bill further requires the Department to field data recovery capabilities that prioritize critical national defense services and include immutable backups, segmented or isolated storage, continuous monitoring for tampering and malicious corruption, annual recovery exercises simulating sophisticated nation-state cyberattacks, and independent audits that test whether recovery objectives can be met under realistic threat conditions. For important and necessary data, the same capabilities must be implemented on a slightly longer timeline. The bill also limits the technology DoD may adopt to tools listed in a certified cybersecurity and data protection inventory and, for recovery or repair tools, requires immutable storage, robust recovery, full audit trails, and continuous integrity monitoring.
In addition to the operational requirements, the bill defines key terms such as critical data, important data, necessary data, data recovery capability, and recovery time objective. It also requires the Secretary of Defense to submit a broader data recovery strategy within 90 days, including recovery objectives, needed technology, oversight processes, and funding requirements, with the option of a classified annex. The bill would amend title 10 of the U.S. Code by adding a new section 391c and updating the chapter table of contents.
The overall sentiment reflected in the bill text is strongly supportive of cybersecurity resilience, continuity of operations, and protection of defense data from destructive cyberattacks, including threats from state and non-state actors such as the People’s Republic of China. Because there were no committee transcripts or recorded votes provided, there is no documented debate or formal opposition in the materials supplied. The main policy emphasis appears to be on hardening DoD data systems, improving recoverability, and increasing congressional oversight through reporting and certification requirements.
Notable points of potential contention, based on the bill’s structure, are the operational and fiscal burdens of meeting mandatory recovery timelines, the cost of implementing immutable backups and continuous monitoring across the Department, and the requirement to use approved/certified technologies. Another possible issue is the level of discretion left to the Secretary of Defense in classifying data and setting recovery objectives, balanced against the bill’s detailed mandates and reporting obligations.
The bill would add a new section 391c to chapter 19 of title 10, United States Code, creating statutory requirements for Department of Defense data resilience, recovery planning, and reporting. It would impose new duties on the Secretary of Defense to classify DoD data by criticality, establish recovery time objectives, deploy specified recovery capabilities, use approved cybersecurity technologies, and submit annual certification reports and a department-wide recovery strategy to Congress. The affected parties are the Department of Defense, its individual elements, and congressional defense committees, with the practical effect of formalizing cyber recovery standards and oversight for defense data systems.
The available materials suggest a generally favorable, security-focused sentiment toward the bill. Its purpose is framed as strengthening national defense against destructive cyberattacks and improving the Department of Defense’s ability to recover essential data quickly and verifiably. No committee discussion or vote record was provided, so there is no evidence of recorded opposition or amendment debate in the supplied context.
No specific contention is documented in the provided transcripts or votes, but the bill’s likely pressure points are the cost, complexity, and implementation burden of meeting mandatory recovery objectives across DoD. The requirements for immutable backups, continuous monitoring, annual attack simulations, independent audits, and use of certified technologies could raise concerns about procurement flexibility, technical feasibility, and funding. Any disagreement would likely center on how prescriptive Congress should be in setting cyber recovery standards versus leaving implementation details to the Department of Defense.