← Back to results
Federal

Critical Electric Infrastructure Cybersecurity Incident Reporting Act

Source: Congress.gov  ·  737 words in original text
This bill requires the Secretary of Energy to create rules for reporting cyber attacks and potential cyber attacks on the electric power system. The bill directs the Department of Energy to receive notifications about these incidents from federal agencies and companies that own or operate critical electric infrastructure.
Federal agencies, owners of critical electric infrastructure, operators of critical electric infrastructure, and users of critical electric infrastructure.
• The Department of Energy becomes the designated federal agency to receive notifications about cyber security incidents and potential cyber security incidents affecting critical electric infrastructure (Sec. 2(3)). • The Secretary of Energy must create regulations within 240 days after the bill becomes law to make it easier for people to submit timely, secure and confidential reports about cyber incidents affecting the electric system (Sec. 2(3)). • The regulations must explain what counts as a potential cyber security incident and require anyone who discovers a cyber incident to notify the Secretary within 24 hours of discovery (Sec. 2(3)). • The Secretary must submit an annual report to Congress describing how many notifications were received and what actions the Department of Energy took in response (Sec. 2(3)).
The Department of Energy gains the responsibility to receive cyber incident reports from federal agencies and electric infrastructure companies. Federal agencies and electric infrastructure companies must report incidents within 24 hours.
None defined in the bill text.
Important: This plain English summary was generated by AI and is provided for informational purposes only. It is not legal advice. Always consult the official bill text on Congress.gov or a qualified attorney for legal matters.