Search

Search bills, members, committees and pages...

S. 4728

U.S. SenateIn Senate Committee

Summary

S. 4728, the Combat Emerging Threats to Critical Infrastructure Act of 2026, was introduced in the Senate on Jun 10, 2026 by Sen. Mark Warner (D). It was referred to Homeland Security And Governmental Affairs, and last saw action on Jun 10, 2026: Read twice and referred to the Committee on Homeland Security and Governmental Affairs.


Record

Text

S. 4728 has no co-sponsors and has not gone to a roll call.

sb4728/introduced-in-senate.txt
119 S4728 IS: Combat Emerging Threats to Critical Infrastructure Act of 2026
U.S. Senate
2026-06-10
text/xml
EN
Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.
II 119th CONGRESS 2d Session S. 4728 IN THE SENATE OF THE UNITED STATES June 10, 2026 Mr. Warner introduced the following bill; which was read twice and referred to the Committee on Homeland Security and Governmental Affairs A BILL
To require the Director of the Cybersecurity and Infrastructure Security Agency to work with Sector Risk Management Agencies to update sector-specific plans, and for other purposes.
1.
Short title
This Act may be cited as the Combat Emerging Threats to Critical Infrastructure Act of 2026 .
2.
Definitions
In this Act:
(1)
Artificial intelligence
The term artificial intelligence has the meaning given that term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 ( 15 U.S.C. 9401 ).
(2)
Digital asset
The term digital asset has the meaning given that term in section 2 of the GENIUS Act ( 12 U.S.C. 5901 ).
(3)
Director
The term Director means the Director of the Cybersecurity and Infrastructure Security Agency.
(4)
National Security Memorandum 22
The term National Security Memorandum 22 means the National Security Memorandum on Critical Infrastructure and Resilience (NSM–22), issued April 30, 2024.
(5)
Sector Risk Management Agency
The term Sector Risk Management Agency has the meaning given that term in section 2200 of the Homeland Security Act of 2002 ( 6 U.S.C. 650 ).
3.
Sector Risk Management Agency sector-specific plans
(a)
Update of sector-Specific plans
Not later than 1 year after the date of enactment of this Act, the Director shall update the sector-specific plans for—
(1)
the Chemical Sector, as that term is used in National Security Memorandum 22;
(2)
the Commercial Facilities Sector, as that term is used in National Security Memorandum 22;
(3)
the Communications Sector, as that term is used in National Security Memorandum 22;
(4)
the Critical Manufacturing Sector, as that term is used in National Security Memorandum 22;
(5)
the Dams Sector, as that term is used in National Security Memorandum 22;
(6)
the Defense Industrial Base Sector, as that term is used in National Security Memorandum 22;
(7)
the Emergency Services Sector, as that term is used in National Security Memorandum 22;
(8)
the Energy Sector, as that term is used in National Security Memorandum 22;
(9)
the Financial Services Sector, as that term is used in National Security Memorandum 22;
(10)
the Food and Agriculture Sector, as that term is used in National Security Memorandum 22;
(11)
the Government Services and Facilities Sector, as that term is used in National Security Memorandum 22;
(12)
the Healthcare and Public Health Sector, as that term is used in National Security Memorandum 22;
(13)
the Information Technology Sector, as that term is used in National Security Memorandum 22;
(14)
the Nuclear Reactors, Materials, and Waste Sector, as that term is used in National Security Memorandum 22;
(15)
the Transportation Systems Sector, as that term is used in National Security Memorandum 22; and
(16)
the Water and Wastewater Sector, as that term is used in National Security Memorandum 22.
(b)
Technology-Facilitated threats
In carrying out subsection (a)—
(1)
each sector-specific plan shall incorporate sector-specific risk management practices to address risks exacerbated or facilitated by disruptive technologies, such as artificial intelligence, including—
(A)
malicious activity, sabotage, or efforts to otherwise clandestinely degrade artificial intelligence systems or the supply chain of an artificial intelligence system, including training or test data, frameworks or software libraries, training or inference computing environments, or other components necessary for the training, management, or maintenance of an artificial intelligence system used by an owner or operator of critical infrastructure;
(B)
malicious activity leveraging artificial intelligence capabilities for computer network exploitation campaigns directed at the networks of owners and operators of critical infrastructure;
(C)
risks and mitigations associated with the deployment of cloud-based architecture, robotics, and zero trust principles (as defined in NIST Special Publication 800–207 or any successor publication);
(D)
evolving risks associated with social engineering techniques and digitally manipulated or digitally generated images, audio, video, or text documents; and
(E)
interagency and public-private information and threat intelligence sharing functions dependent on the organization, funding, and expertise of agencies (as defined in section 4101 of title 5, United States Code); and
(2)
with respect to the sector-specific plan for the Financial Services Sector pursuant to subsection (a)(9), the Director shall coordinate with the Secretary of the Treasury to develop a process to determine digital asset vulnerabilities relating to cryptographic risks resulting from quantum computing.
(c)
Interagency coordination
In carrying out subsection (a), the Director shall coordinate with each relevant designated Sector Risk Management Agency.
(d)
Reports to Congress
Not later than 30 days after the date on which the Director completes the update of the sector-specific plans required under subsection (a), the Director shall—
(1)
inform and provide a copy of each sector-specific plan to—
(A)
the Committee on Homeland Security and Governmental Affairs of the Senate ;
(B)
the Select Committee on Intelligence of the Senate ;
(C)
the Committee on Homeland Security of the House of Representatives ; and
(D)
the Permanent Select Committee on Intelligence of the House of Representatives ;
(2)
inform and provide a copy of the sector-specific plan for the Defense Industrial Base Sector updated pursuant to subsection (a)(6) to—
(A)
the Committee on Armed Services of the Senate ; and
(B)
the Committee on Armed Services of the House of Representatives ;
(3)
inform and provide a copy of the sector-specific plan for the Energy Sector updated pursuant to subsection (a)(8) to—
(A)
the Committee on Energy and Natural Resources of the Senate ; and
(B)
the Committee on Energy and Commerce of the House of Representatives ;
(4)
inform and provide a copy of the sector-specific plan for the Financial Services Sector updated pursuant to subsection (a)(9) to—
(A)
the Committee on Finance of the Senate ; and
(B)
the Committee on Financial Services of the House of Representatives ;
(5)
inform and provide a copy of the sector-specific plan for the Food and Agriculture Sector updated pursuant to subsection (a)(10) to—
(A)
the Committee on Agriculture, Nutrition, and Forestry of the Senate ;
(B)
the Committee on Health, Education, Labor, and Pensions of the Senate ;
(C)
the Committee on Finance of the Senate ;
(D)
the Committee on Agriculture of the House of Representatives ;
(E)
the Committee on Energy and Commerce of the House of Representatives ; and
(F)
the Committee on Ways and Means of the House of Representatives ;
(6)
inform and provide a copy of the sector-specific plan for the Government Services and Facilities Sector updated pursuant to subsection (a)(11) to—
(A)
the Committee on Environment and Public Works of the Senate ;
(B)
the Committee on Oversight and Government Reform of the House of Representatives ; and
(C)
the Committee on Transportation and Infrastructure of the House of Representatives ;
(7)
inform and provide a copy of the sector-specific plan for the Healthcare and Public Health Sector updated pursuant to subsection (a)(12) to—
(A)
the Committee on Health, Education, Labor, and Pensions of the Senate ;
(B)
the Committee on Finance of the Senate ;
(C)
the Committee on Energy and Commerce of the House of Representatives ; and
(D)
the Committee on Ways and Means of the House of Representatives ;
(8)
inform and provide a copy of the sector-specific plan for the Transportation Systems Sector updated pursuant to subsection (a)(15) to—
(A)
the Committee on Commerce, Science, and Transportation of the Senate ; and
(B)
the Committee on Transportation and Infrastructure of the House of Representatives ; and
(9)
inform and provide a copy of the sector-specific plan for the Water and Wastewater Sector updated pursuant to subsection (a)(16) to—
(A)
the Committee on Environment and Public Works of the Senate ; and
(B)
the Committee on Transportation and Infrastructure of the House of Representatives .
4.
Biennial reassessment
(a)
In general
Not later than 2 years after the date on which the Director completes the update of the sector-specific plans required under section 3(a), and not less frequently than once every 2 years thereafter, the Director shall—
(1)
conduct a reassessment of each sector-specific plan; and
(2)
issue revised sector-specific plans.
(b)
Notification to Congress
Not later than 30 days after the date on which the Director completes each update of the sector-specific plans required under subsection (a), the Director shall inform and provide copies of each sector-specific plan to the relevant committees of Congress in the manner prescribed under section 3(d).

Tracker

The tracker indicates the progress of this legislation as it moves through the legislative process.

  1. Introduced2026-06-10
  2. Passed Senate
  3. Passed House
  4. Conference
  5. To President
  6. Became Law

A bill to require the Director of the Cybersecurity and Infrastructure Security Agency to work with Sector Risk Management Agencies to update sector-specific plans, and for other purposes.

Sponsors

Sen. Mark Warner (D) sponsors S. 4728 alone.

Committees

S. 4728 went before 1 committee: Homeland Security and Governmental Affairs.

Homeland Security and Governmental Affairs
Homeland Security and Governmental Affairs
Referred To · Jun 10, 2026 · 444 Bills

Actions

S. 4728 has taken 2 actions since Jun 10, 2026.

ChamberAction
Jun 10, 2026
Senate
Read twice and referred to the Committee on Homeland Security and Governmental Affairs.Homeland Security and Governmental Affairs Committee
Jun 10, 2026
Introduced in Senate

Votes

S. 4728 has not gone to a roll call.

Titles

S. 4728 goes by 3 titles, 1 of them short titles.

  • Combat Emerging Threats to Critical Infrastructure Act of 2026 — Display Title
  • Combat Emerging Threats to Critical Infrastructure Act of 2026 — Short Title(s) as Introduced
  • A bill to require the Director of the Cybersecurity and Infrastructure Security Agency to work with Sector Risk Management Agencies to update sector-specific plans, and for other purposes. — Official Title as Introduced

Lobbying

6 clients hired 6 firms and 34 registered lobbyists who named S. 4728 in 6 quarterly filings, 2025 to 2026. Reported under the Lobbying Disclosure Act; a filing’s income covers everything its registrant worked that quarter, so the amounts below are the filings’, not this bill’s.

Filed under Taxation/Internal Revenue Code, Telecommunications, Budget/Appropriations, Consumer Issues/Safety/Products, Defense, Energy/Nuclear, Homeland Security, Science/Technology.

Clients

Who paid to be heard, by how many filings named the bill.

ClientBusinessStateFirmsFilingsReported
BIOSTLOrganization of regional technology startups around medicine, healthcare, and agricultureMissouri11$20K
ANTHROPICAnthropic is an AI safety and research company that builds frontier AI systems.California11
CTIA-THE WIRELESS ASSOCIATIONDistrict of Columbia11
EDISON INTERNATIONALDistrict of Columbia11
NATIONAL ASSOCIATION OF MUTUAL INSURANCE COMPANIESDistrict of Columbia11
VERIZON COMMUNICATIONS INC AND VARIOUS SUBSIDIARIESDistrict of Columbia11

Firms

Registrants who filed on the bill, by filings.

Lobbyists

Named on the filings that cite the bill. The 20 named most often, of 34.

Filings

The documents themselves, on the Senate’s Lobbying Disclosure site, largest reported first.

ClientRegistrantPeriodReportedDocument
CTIA-THE WIRELESS ASSOCIATIONCTIA-THE WIRELESS ASSOCIATION2026 second_quarter$3.6M2nd Quarter - Report
VERIZON COMMUNICATIONS INC AND VARIOUS SUBSIDIARIESVERIZON COMMUNICATIONS INC. AND VARIOUS SUBSIDIARIES2026 second_quarter$3.1M2nd Quarter - Report
ANTHROPICANTHROPIC2026 second_quarter$2M2nd Quarter - Report
NATIONAL ASSOCIATION OF MUTUAL INSURANCE COMPANIESNATIONAL ASSOCIATION OF MUTUAL INSURANCE COMPANIES2026 second_quarter$540K2nd Quarter - Report
EDISON INTERNATIONALEDISON INTERNATIONAL2026 second_quarter$290K2nd Quarter - Report
BIOSTLVAN SCOYOC ASSOCIATES2025 first_quarter$20K1st Quarter - Report

Classification

The Congressional Research Service files S. 4728 under Government Operations and Politics, one of its 31 policy areas.

CRS Subjects

CRS assigns every bill one policy area from its 31; S. 4728’s is Government Operations and Politics.

s4728/policy-areas.txt
Government Operations and PoliticsAgriculture and FoodAnimalsArmed Forces and National SecurityArts, Culture, ReligionCivil Rights and Liberties, Minority IssuesCommerceCongressCrime and Law EnforcementEconomics and Public FinanceEducationEmergency ManagementEnergyEnvironmental ProtectionFamiliesFinance and Financial SectorForeign Trade and International FinanceHealthHousing and Community DevelopmentImmigrationInternational AffairsLabor and EmploymentLawNative AmericansPublic Lands and Natural ResourcesScience, Technology, CommunicationsSocial WelfareSports and RecreationTaxationTransportation and Public WorksWater Resources Development

Source: congress.gov · legiscan.com