executive-ordertrade-pressNewsThe Broadside1 min read

House Rules clears FY2027 NDAA cyber amendments for votes

Rules kept DoD reporting and AI security items alive while leaving CISA grant and CVE codification measures outside.


TL;DR

Inside Cybersecurity reports the House Rules Committee approved more than 300 of nearly 1,400 proposed fiscal 2027 National Defense Authorization Act amendments for floor consideration. The package includes Rep. Nick Begich’s 72-hour DoD contractor reporting deadline for Chinese-linked hardware, software or firmware found in covered networks, plus AI data center, post-quantum and supply-chain counterinfluence items. Left out: the CISA/FEMA state and local cyber grant program, due to lapse Sept. 30, and a CISA Common Vulnerabilities and Exposures codification measure.

According to Inside Cybersecurity, the House Rules Committee’s June 29 package gives floor slots to more than 300 amendments to the fiscal 2027 National Defense Authorization Act, from nearly 1,400 filed. For cyber readers, the practical split is blunt: amendments tied to Defense Department networks, contractors, AI data-center security and supply-chain counterintelligence got through Rules. Two CISA-adjacent institutional items did not.

Rep. Nick Begich’s amendment would add a mandatory 72-hour deadline for operationally critical DoD contractors to report discovery of hardware, software or firmware manufactured by or linked to Chinese entities within covered networks, on top of existing cyber incident reporting. The package also includes Rep. French Hill’s Government Accountability Office review of DoD cyber-related intelligence sharing with state, local, tribal, territorial and private-sector partners, Rep. Troy Nehls’ post-quantum cryptography measure at DoD, Rep. August Pfluger’s supply-chain pilot, and Rep. Erin Houchin’s assessment of AI data-center security frameworks for espionage risks from nation-state adversaries.

The omissions are the part practitioners should not ignore. Rep. Andy Ogles’ amendment for the CISA and Federal Emergency Management Agency state and local cyber grant program, which is set to lapse Sept. 30, was not included. Neither was Rep. Delia Ramirez’s proposal to codify CISA’s Common Vulnerabilities and Exposures program, nor a bill to establish a Cyber Force at the Coast Guard. That does not kill any policy outright, and Inside Cybersecurity reports the floor timing remains unclear because of GOP disputes over potentially merging the NDAA with non-defense issues. It does show which cyber problems are getting a defense-bill vehicle now, and which ones still need another ride.


Published ·Deep Fathom