PILLAR Act
Latest action (17 Nov 2025): On motion to suspend the rules and pass the bill, as amended Agreed to by voice vote.
What this bill does
The PILLAR Act would reauthorize and update the State and Local Cybersecurity Grant Program run by the Cybersecurity and Infrastructure Security Agency (CISA) within the Department of Homeland Security. It extends the program's authorization and related funding provisions through fiscal year 2033, and it broadens the program's scope beyond traditional "information systems" to explicitly cover "operational technology systems" and systems using artificial intelligence. It adds new definitions (including artificial intelligence, AI systems, multi-factor authentication, and "foreign entity of concern"), restricts grant funds from being used to buy technology that doesn't align with CISA security guidance or that comes from foreign entities of concern, adjusts cost-share and matching requirements for grant recipients, and requires periodic GAO reviews, including of AI adoption in the program.
The bill primarily affects state, local, and tribal governments that receive or seek these federal cybersecurity grants, as well as CISA and DHS, which administer the program. It also addresses rural areas and smaller local governments by requiring outreach efforts and representation in planning committees, and it allows academic and nonprofit technical-assistance groups to participate in grant-funded activities. Local governments that don't receive expected funds from a state within a set time may petition DHS for direct funding.
The bill passed the House by voice vote on November 17, 2025, after being introduced by Rep. Andrew Ogles on September 2, 2025. It now goes to the Senate for consideration; no further action has yet occurred there.
Plain-English summary generated by Bill100 AI from the official record. Always verify against the source below.
Official summary
Protecting Information by Local Leaders for Agency Resilience Act or the PILLAR Act
This bill extends the State and Local Cybersecurity Grant Program through FY2035, expands the scope of the program, and imposes certain limits on the use of grant funds. (The program provides grants to states and Indian tribes to address cybersecurity risks to government information systems.)
The bill expands the scope of systems that may be secured using grant funds to include operational technology systems and specifies that systems using artificial intelligence are included. Such systems must be maintained, owned, or operated by or on behalf of state, local, or tribal governments.
The bill also specifies that grant funds may not be used to purchase software, hardware, or related products or services that do not align with relevant guidance provided by the Cybersecurity and Infrastructure Security Agency (CISA).
Further, the bill increases the federal share of costs available to entities that implement or enable multifactor authentication and identity and access management tools for critical infrastructure by a specified date.
The bill requires annual reports by grant recipients to include a description of recipients’ progress in assuming the cost of continuing cybersecurity programs after grant funds are fully expended.
The Government Accountability Office must periodically review the program. This effort must include a review of artificial intelligence adoption across a sample of grants.
Finally, CISA must implement an outreach plan to inform local governments, including governments in rural areas or areas with small populations, about CISA’s no-cost cybersecurity offerings.
Timeline
17 Nov 2025
On motion to suspend the rules and pass the bill, as amended Agreed to by voice vote.
3 Sep 2025
Ordered to be Reported by the Yeas and Nays: 21 - 1.
Common questions
- What does H.R. 5078 do?
- The PILLAR Act would reauthorize and update the State and Local Cybersecurity Grant Program run by the Cybersecurity and Infrastructure Security Agency (CISA) within the Department of Homeland Security. It extends the program's authorization and related funding provisions through fiscal year 2033, and it broadens the program's scope beyond traditional "information systems" to explicitly cover "operational technology systems" and systems using artificial intelligence. It adds new definitions (including artificial intelligence, AI systems, multi-factor authentication, and "foreign entity of concern"), restricts grant funds from being used to buy technology that doesn't align with CISA security guidance or that comes from foreign entities of concern, adjusts cost-share and matching requirements for grant recipients, and requires periodic GAO reviews, including of AI adoption in the program. The bill primarily affects state, local, and tribal governments that receive or seek these federal cybersecurity grants, as well as CISA and DHS, which administer the program. It also addresses rural areas and smaller local governments by requiring outreach efforts and representation in planning committees, and it allows academic and nonprofit technical-assistance groups to participate in grant-funded activities. Local governments that don't receive expected funds from a state within a set time may petition DHS for direct funding. The bill passed the House by voice vote on November 17, 2025, after being introduced by Rep. Andrew Ogles on September 2, 2025. It now goes to the Senate for consideration; no further action has yet occurred there.
- Has H.R. 5078 become law?
- Not yet. As of 17 Nov 2025, H.R. 5078 is passed house (senate next).
- Who sponsored H.R. 5078?
- H.R. 5078 was sponsored by Rep. Andrew Ogles [R-TN5] (Republican-TN), with 4 cosponsors.
- What's the latest action on H.R. 5078?
- On motion to suspend the rules and pass the bill, as amended Agreed to by voice vote. (17 Nov 2025).
Related bills in Science, Technology, Communications
Open-Source AI Leadership Act
AI for Secure Networks Act
Memory Chip Competitiveness Assessment Act of 2026
ITS Codification Act
Bill100 mirrors the public U.S. legislative record from Congress.gov and GovTrack and adds plain-English AI summaries. It is an information tool, not legal, compliance or lobbying advice, and it is not affiliated with the U.S. Congress or any government agency. AI summaries can simplify or omit detail — every bill links to the official source; verify there before you rely on it.