- H.R. 10171August 27, 2026
- H.R. 10156August 27, 2026
- H.R. 10172August 27, 2026
- H.R. 10160August 27, 2026
- H.R. 10181August 27, 2026
- H.R. 10176August 27, 2026
- H.Res. 1496August 27, 2026
- H.R. 10164August 27, 2026
- H.R. 10170August 27, 2026
- H.Res. 1494August 27, 2026
- H.R. 10163August 27, 2026
- H.R. 10157August 27, 2026
- Administration
- Agriculture
- Agriculture, Nutrition, And Forestry
- Appropriations
- Armed Services
- Banking, Housing, And Urban Affairs
- Budget
- Commerce, Science, And Transportation
- Education and Workforce
- Energy And Commerce
- Energy And Natural Resources
- Environment And Public Works
- Ethics
- Finance
- Financial Services
- Foreign Affairs
- Foreign Relations
- Health, Education, Labor, And Pensions
- Homeland Security
- Homeland Security And Governmental Affa…
- Indian Affairs
- Indian and Insular Affairs
- Intelligence
- Judiciary
- Natural Resources
- Oversight And Government Reform
- Permanent Select Intelligence
- Rules
- Rules And Administration
- Science, Space, And Technology
- Select Intelligence
- Small Business
- Small Business And Entrepreneurship
- Subcommittee on Aviation
- Subcommittee on Border Security and Enf…
- Subcommittee on Coast Guard and Maritim…
- Subcommittee on Commodity Markets, Digi…
- Subcommittee on Conservation, Research,…
- Subcommittee on Counterterrorism and In…
- Subcommittee on Cybersecurity and Infra…
- Subcommittee on Disability Assistance a…
- Subcommittee on Economic Development, P…
- Subcommittee on Economic Opportunity
- Subcommittee on Emergency Management an…
- Subcommittee on Energy and Mineral Reso…
- Subcommittee on Federal Lands
- Subcommittee on Forestry and Horticultu…
- Subcommittee on General Farm Commoditie…
- Subcommittee on Health
- Subcommittee on Highways and Transit
- Subcommittee on Livestock, Dairy, and P…
- Subcommittee on Nutrition and Foreign A…
- Subcommittee on Oversight and Investiga…
- Subcommittee on Oversight, Investigatio…
- Subcommittee on Railroads, Pipelines, a…
- Subcommittee on Transportation and Mari…
- Subcommittee on Water Resources and Env…
- Subcommittee on Water, Wildlife and Fis…
- Transportation And Infrastructure
- Veterans' Affairs
- Ways And Means

H.R. 9918
U.S. House•In House Committee
Summary
H.R. 9918, the Enhancing K–12 Cybersecurity Act, was introduced in the House on Jul 23, 2026 by Rep. Doris Matsui (D) with 1 co-sponsor. It was referred to Subcommittee on Cybersecurity and Infrastructure Protection, and last saw action on Jul 24, 2026: Referred to the Subcommittee on Cybersecurity and Infrastructure Protection.
Record
Text
H.R. 9918 has 1 co-sponsor.
hb9918/introduced-in-house.txt119 HR 9918 IH: Enhancing K–12 Cybersecurity ActU.S. House of Representatives2026-07-23text/xmlENPursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.I 119th CONGRESS 2d Session H. R. 9918 IN THE HOUSE OF REPRESENTATIVES July 23, 2026 Ms. Matsui (for herself and Mr. Nunn of Iowa ) introduced the following bill; which was referred to the Committee on Homeland Security , and in addition to the Committee on Education and Workforce , for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned A BILLTo direct the Director of the Cybersecurity and Infrastructure Security Agency to establish a School Cybersecurity Improvement Program, and for other purposes.1.Short titleThis Act may be cited as the Enhancing K–12 Cybersecurity Act .2.School cybersecurity information exchange(a)EstablishmentThe Director of the Cybersecurity and Infrastructure Security Agency shall enhance existing information exchange efforts implemented through partnerships with one or more information sharing and analysis organizations to focus specific attention on the needs of K–12 organizations with regard to cybersecurity, including a new publicly accessible website (to be known as the School Cybersecurity Information Exchange ) to disseminate information, cybersecurity best practices, training, and lessons learned tailored to the specific needs, technical expertise, and resources available to K–12 organizations in accordance with subsection (b).(b)DutiesIn establishing the School Cybersecurity Information Exchange under subsection (a), the Director shall—(1)engage appropriate Federal, State, local, and nongovernmental organizations to identify, promote, and disseminate information and best practices for local educational agencies, state educational agencies, and educational service agencies (as such terms are defined in section 8101 of the Elementary and Secondary Education Act of 1965 ( 20 U.S.C. 7801 )) with respect to cybersecurity, data protection, remote learning security, and student online privacy;(2)maintain a database for an elementary school, secondary school, local educational agency, State educational agency, and educational service agency to identify cybersecurity security tools and services funded by the Federal Government, as well as tools and services recommended for purchase with State and local government funding; and(3)provide a searchable database for an elementary school, secondary school, local educational agency, State educational agency, and educational service agency to find and apply for funding opportunities to improve cybersecurity.(c)ConsultationIn carrying out the duties under subsection (b), the Director shall consult with the following:(1)The Secretary of Education.(2)The Director of the National Institute of Standards and Technology.(3)The Federal Communications Commission.(4)The Director of the National Science Foundation.(5)The Federal Bureau of Investigation.(6)State and local leaders, including, when appropriate, Governors, employees of State government departments and agencies, members of State legislatures and State boards of education, local educational agencies, State educational agencies, representatives of Indian tribes, teachers, principals, other school leaders, charter school leaders, specialized instructional support personnel, paraprofessionals, administrators, other staff, and parents.(7)When determined appropriate by the Director, subject-matter experts and expert organizations, including nongovernmental organizations, vendors of school information technology products and services, cybersecurity insurance companies, and cybersecurity threat companies.3.Cybersecurity incident registry(a)In generalThe Director of the Cybersecurity and Infrastructure Security Agency shall establish, through partnerships with one or more information sharing and analysis organizations, a voluntary registry of information relating to cyber incidents affecting information technology systems owned or managed by a covered entity, and determine the scope of cyber incidents to be included in the registry and processes by which incidents can be reported for collection in the registry.(b)UseInformation in the registry established pursuant to subsection (a) may be used to—(1)improve data collection and coordination activities related to the nationwide monitoring of the incidence and impact of cyber incidents affecting a covered entity;(2)conduct analyses regarding trends in cyber incidents against such entity;(3)develop systematic approaches to assist such entity in preventing and responding to cyber incidents;(4)increase the awareness and preparedness of a covered entity regarding the cybersecurity of such covered entity; and(5)identify, prevent, or investigate cyber incidents targeting a covered entity.(c)Information collectionThe Director of the Cybersecurity and Infrastructure Security Agency may collect information relating to cyber incidents to store in the registry established pursuant to subsection (a). Such information may be submitted by a covered entity and may include the following:(1)The dates of each cyber incident, including the dates on which each such incident was initially detected and the dates on which each such incident was first publicly reported or disclosed to another entity.(2)A description of each cyber incident, which shall include whether each such incident was as a result of a breach, malware, distributed denial of service attack, or other method designed to cause a vulnerability.(3)The effects of each cyber incident, including descriptions of the type and size of each such incident.(4)Other information determined relevant by the Director.(d)ReportThe Director of the Cybersecurity and Infrastructure Security Agency shall make available on the School Cybersecurity Information Exchange established under section 2 an annual report relating to cyber incidents affecting elementary schools and secondary schools which includes data, and the analysis of such data, in a manner that—(1)is—(A)de-identified; and(B)presented in the aggregate; and(2)at a minimum, protects personal privacy to the extent required by applicable Federal and State privacy laws.(e)Covered entity definedIn this section, the term covered entity means the following:(1)An elementary school.(2)A secondary school.(3)A local educational agency.(4)A State educational agency.(5)An educational service agency.4.K–12 Cybersecurity Technology Improvement program(a)EstablishmentThe Director of the Cybersecurity and Infrastructure Security Agency shall establish, through partnerships with one or more information sharing and analysis organizations, a program (to be known as the K–12 Cybersecurity Technology Improvement Program ) to deploy cybersecurity capabilities to address cybersecurity risks and threats to information systems of elementary schools and secondary schools through—(1)developing cybersecurity strategies and installation of effective cybersecurity tools tailored for K–12 schools;(2)making available cybersecurity services that enhance the ability of K–12 schools to protect themselves from ransomware and other cybersecurity threats; and(3)continuing training opportunities on cybersecurity threats, best practices, and relevant technologies for K–12 schools.(b)ReportThe Director of the Cybersecurity and Infrastructure Security Agency shall make available on the School Cybersecurity Information Exchange established under section 2 an annual report relating to the impact of the K–12 Cybersecurity Technology Improvement Program, including information on the cybersecurity capabilities made available to information technology systems owned or managed by elementary schools, secondary schools, local educational agencies, State educational agencies, and educational service agencies, the number of students served, and cybersecurity incidents identified or prevented.5.Authorization of appropriationsThere are authorized to be appropriated to carry out this Act $10,000,000 for each of fiscal years 2027 and 2028.6.DefinitionsIn this Act:(1)Educational service agencyThe term educational service agency has the meaning given that term in section 8101 of the Elementary and Secondary Education Act of 1965 ( 20 U.S.C. 7801 ).(2)Elementary schoolThe term elementary school has the meaning given that term in section 8101 of the Elementary and Secondary Education Act of 1965 ( 20 U.S.C. 7801 ).(3)Information sharing and analysis organizationThe term information sharing and analysis organization has the meaning given that term in section 2200 of the Homeland Security Act of 2002 ( 6 U.S.C. 650 ).(4)Local educational agencyThe term local educational agency has the meaning given that term in section 8101 of the Elementary and Secondary Education Act of 1965 ( 20 U.S.C. 7801 ).(5)State educational agencyThe term State educational agency has the meaning given that term in section 8101 of the Elementary and Secondary Education Act of 1965 ( 20 U.S.C. 7801 ).(6)Secondary schoolThe term secondary school has the meaning given that term in section 8101 of the Elementary and Secondary Education Act of 1965 ( 20 U.S.C. 7801 ).
Tracker
The tracker indicates the progress of this legislation as it moves through the legislative process.
- Introduced2026-07-23
- Passed House
- Passed Senate
- Conference
- To President
- Became Law
To direct the Director of the Cybersecurity and Infrastructure Security Agency to establish a School Cybersecurity Improvement Program, and for other purposes.
Sponsors
Rep. Doris Matsui (D) sponsors H.R. 9918, and 1 member has co-sponsored it from the day it was introduced.
Committees
H.R. 9918 went before 3 committees: Cybersecurity and Infrastructure Protection Subcommittee, Education and Workforce and Homeland Security.

Actions
H.R. 9918 has taken 3 actions since Jul 23, 2026, the latest on Jul 24, 2026.
| Chamber | Action | |||
|---|---|---|---|---|
Jul 24, 2026 | House | Referred to the Subcommittee on Cybersecurity and Infrastructure Protection.Cybersecurity and Infrastructure Protection Subcommittee | ||
Jul 23, 2026 | House | Introduced in House | ||
Jul 23, 2026 | House | Referred to the Committee on Homeland Security, and in addition to the Committee on Education and Workforce, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.Homeland Security Committee |
Votes
H.R. 9918 has not gone to a roll call.
Titles
H.R. 9918 goes by 3 titles, 1 of them short titles.
- Enhancing K–12 Cybersecurity Act — Display Title
- Enhancing K–12 Cybersecurity Act — Short Title(s) as Introduced
- To direct the Director of the Cybersecurity and Infrastructure Security Agency to establish a School Cybersecurity Improvement Program, and for other purposes. — Official Title as Introduced
Classification
The Congressional Research Service files H.R. 9918 under Education, one of its 31 policy areas.
CRS Subjects
CRS assigns every bill one policy area from its 31; H.R. 9918’s is Education.
hr9918/policy-areas.txtConstitutional authority
The clause the sponsor cites as Congress’s power to enact H.R. 9918, as entered in the Congressional Record.
[Congressional Record Volume 172, Number 121 (Thursday, July 23, 2026)][House]From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]By Ms. MATSUI:H.R. 9918.Congress has the power to enact this legislation pursuantto the following:Clause 3 of Section 8 of Article I of the U.S. Constitution[Page H5198]
Source: congress.gov · legiscan.com