WeVote

Bill

Bill

HR 9918

Enhancing K–12 Cybersecurity Act

119th Congress Introduced by Doris Matsui and 1 co-sponsor

Creates a national framework that shares K–12 cybersecurity resources, hosts an incident registry, and funds deployment of tailored tools and training.

Referred to the Subcommittee on Cybersecurity and Infrastructure Protection.
0
WeVote Research Nonpartisan
Bill Summary · HR 9918

Summary of HR 9918: Enhancing K–12 Cybersecurity Act

Purpose and intent

  • Create a Federal framework to strengthen cybersecurity in K–12 schools and districts.
  • Direct the Director of the Cybersecurity and Infrastructure Security Agency (CISA) to establish two programs focused on K–12 cybersecurity, plus an information exchange and incident registry to improve awareness, collaboration, and protection of student data and school networks.

Key provisions and changes

  1. School Cybersecurity Information Exchange (Section 2)

    • Establishes a publicly accessible website (the School Cybersecurity Information Exchange) to share information, best practices, training, and lessons tailored to K–12 needs.
    • Duties of the Director include:
      • Partnering with Federal, State, local, and non-governmental entities to identify and disseminate cybersecurity information for local educational agencies (LEAs), State educational agencies (SEAs), and educational service agencies (ESAs).
      • Maintaining a database of cybersecurity tools and services funded by federal and state/local sources, as well as recommended tools for purchase.
      • Providing a searchable database to help LEAs/SEAs/ESAs find and apply for funding opportunities.
    • Consultation requirements with multiple stakeholders (Education Department, NIST, FCC, NSF, FBI, state/local leaders, teachers, administrators, parents, and subject-matter experts).
  2. Cybersecurity Incident Registry (Section 3)

    • Establishes a voluntary registry of cyber incidents affecting information technology systems owned or managed by covered entities (elementary schools, secondary schools, LEAs, SEAs, ESAs) through partnerships with information sharing and analysis organizations.
    • Uses of registry data include: improving nationwide incident monitoring, analyzing trends, developing prevention/response approaches, raising awareness/preparedness, and helping identify/prevent/investigate incidents.
    • Allows collection of incident data (dates, descriptions, effects, etc.) with privacy protections.
    • Annual, de-identified, aggregated reporting on cyber incidents affecting K–12 entities, protecting personal privacy per applicable laws.
  3. K–12 Cybersecurity Technology Improvement Program (Section 4)

    • Establishes a program to deploy cybersecurity capabilities to address risks to K–12 information systems.
    • Activities include:
      • Developing strategies and installing effective cybersecurity tools tailored for K–12 schools.
      • Providing cybersecurity services to reduce ransomware and other threats.
      • Offering ongoing training on threats, best practices, and technologies.
    • Annual report on program impact, including capabilities deployed, number of students served, and incidents identified or prevented.
  4. Funding and Resources (Section 5)

    • Authorized appropriations of $10,000,000 for each of fiscal years 2027 and 2028 to implement the Act.
  5. Definitions (Section 6)

    • Clarifies terms: Educational Service Agency, Elementary School, Local Educational Agency, State Educational Agency, Information Sharing and Analysis Organization, Secondary School, etc., aligning with definitions in the Elementary and Secondary Education Act of 1965 and related federal law.

Who would be affected

  • Primary beneficiaries: elementary and secondary schools, local educational agencies, state educational agencies, and educational service agencies.
  • Federal and non-governmental partners involved in information sharing, cybersecurity vendor engagement, and cyber threat analysis.
  • Stakeholders at the state and local levels, including governors, state departments, school boards, teachers, school leaders, and parents, through participation in consultations and program procurement.

Procedural and timeline aspects

  • Introduced in the 119th Congress on July 23, 2026.
  • Referred to the House Homeland Security Committee and the Education and Workforce Committee, with subcommittee consideration anticipated.
  • Authorized funding set at $10 million per year for 2027 and 2028 (no funding beyond those years explicitly authorized in the bill text).
  • Provisions emphasize voluntary participation for incident reporting and active engagement with multiple partners for information sharing and program deployment.

Practical impact and considerations

  • Creates a centralized, publicly accessible information hub for K–12 cybersecurity resources and funding opportunities.
  • Enables systematic collection and analysis of cyber incidents in K–12 settings while preserving privacy.
  • Supports deployment of tailored cybersecurity tools and training for K–12 schools, potentially reducing ransomware and other cyber risks.
  • Requires ongoing interagency and stakeholder collaboration, with annual reporting to measure progress and impact.

Compiled from official sources — confirm details with the bill’s official record.

Sign in to ask a question.