Key Takeaways
- Senator Mark Warner (D‑VA) introduced the Combat Emerging Threats to Critical Infrastructure Act of 2026, which would compel CISA to refresh cybersecurity plans for all 16 U.S. critical‑infrastructure sectors within nine months of enactment.
- The bill mandates biennial reviews and updates of those plans, with timely notification and delivery of the revised documents to relevant congressional oversight committees.
- Required risk assessments must cover technology‑enabled threats such as AI‑enhanced cyberattacks, AI supply‑chain weaknesses, deepfakes, robotics‑related risks, and quantum‑enabled attacks on cryptography.
- Industry groups, exemplified by the National Electrical Manufacturers Association (NEMA), support the legislation, citing the need for current security plans to sustain operational resilience and competitiveness.
- The proposal also seeks to restore permanent funding for the Multi‑State Information Sharing and Analysis Center (MS‑ISAC), a vital resource for state, local, tribal, and territorial cybersecurity coordination.
Legislative Context and Objectives
Senator Warner’s bill emerges from mounting apprehension that rapid advances in artificial intelligence could lower the barrier for sophisticated cyberattacks against essential services. By compelling CISA to continually refresh sector‑specific cybersecurity strategies, the legislation aims to keep defensive measures aligned with evolving threat landscapes. Warner emphasized that government, industry, regulators, and cybersecurity experts must collaborate to produce plans that address not only traditional vulnerabilities but also those amplified by AI and other emerging technologies.
Mandated Timeline and Reporting Requirements
Under the act, CISA would have nine months to update the cybersecurity plans for each of the 16 critical‑infrastructure sectors identified in National Security Memorandum 22. Once a sector’s plan is revised, the agency must notify Congress and supply copies of the updated document within one month. The bill further requires that these plans be reviewed and refreshed every two years, with the same congressional notification protocol applied at each update cycle, ensuring ongoing oversight and accountability.
Scope of Technology‑Enabled Risk Assessments
The legislation obliges CISA to evaluate each sector’s risk profile for a range of technology‑driven threats. This includes AI‑enhanced cyberattacks, vulnerabilities in AI supply chains (such as compromised training data or software frameworks), deepfake‑enabled social engineering, robotics‑related risks, and quantum‑enabled attacks that could undermine existing cryptographic protections. By explicitly naming these threat vectors, the bill seeks to compel planners to consider how emerging capabilities could be weaponized against critical infrastructure.
Sector‑Specific Coverage
The act’s scope encompasses all 16 sectors designated as critical infrastructure: chemical, commercial facilities, communications, critical manufacturing, dams, defense industrial base, emergency services, energy, financial services, food and agriculture, government facilities, healthcare and public health, information technology, nuclear reactors and materials, transportation systems, and water and wastewater. Each sector’s plan must incorporate risk‑management measures that address threats enabled or amplified by AI and other emerging technologies, ensuring a uniform yet tailored approach across diverse industries.
Coordination with Sector Risk Management Agencies
CISA’s director would be required to work closely with the appropriate Sector Risk Management Agencies (SRMAs) when updating each sector’s plan. This collaborative model leverages the specialized expertise of SRMAs while maintaining a centralized oversight function within CISA. The bill stipulates that within 30 days of completing updates, the director must inform Congress and deliver copies of each plan to the relevant oversight committees in both the Senate and House of Representatives.
Congressional Notification Details
The legislation outlines precise committee assignments for receiving sector‑specific plans. For example, the defense industrial base plan would go to the Senate and House Armed Services Committees; the energy sector plan to the Senate Committee on Energy and Natural Resources and the House Committee on Energy and Commerce; and the financial services plan to the Senate Finance Committee and the House Financial Services Committee. Similar detailed routings are prescribed for the food and agriculture, government services, healthcare and public health, transportation, and water and wastewater sectors, ensuring that subject‑matter experts in Congress receive the information most pertinent to their jurisdictions.
Industry Support and Rationale
The National Electrical Manufacturers Association voiced strong backing for the bill, highlighting that the electroindustry supplies foundational technologies upon which every other critical‑infrastructure sector relies. NEMA’s managing director of government relations, Brian Papp, argued that regularly updated security plans would strengthen operational resilience, help manufacturers confront emerging risks, and preserve American competitiveness in a global market increasingly shaped by cyber threats.
Addressing State and Local Cybersecurity Gaps
In addition to sector‑specific reforms, Senator Warner earlier sought to bolster cybersecurity at the state and local levels by proposing the restoration and permanent funding of the Multi‑State Information Sharing and Analysis Center (MS‑ISAC). MS‑ISAC serves roughly 19,000 state, local, tribal, and territorial organizations as a hub for cyber threat intelligence and incident response. By securing enduring federal support for MS‑ISAC, the legislation aims to close a notable gap in the nation’s cybersecurity posture, particularly as AI lowers the technical barriers for attackers targeting less‑resourced jurisdictions.
Implications for Critical‑Infrastructure Resilience
If enacted, the Combat Emerging Threats to Critical Infrastructure Act would institutionalize a rhythm of continual planning, assessment, and congressional oversight designed to keep pace with rapid technological change. By mandating explicit consideration of AI‑related threats, deepfakes, robotics, and quantum risks, the bill pushes critical‑infrastructure owners to adopt forward‑looking defenses rather than relying on outdated frameworks. The requirement for biennial updates, coupled with strict reporting to relevant congressional committees, creates a feedback loop that could accelerate the adoption of best practices and foster greater public‑private coordination across the nation’s most vital assets.

