Bipartisan Bills Push CISA to Cover Biotech as Critical Infrastructure
Two companion bills introduced September 24 would direct CISA to extend cybersecurity protections to biotechnology, biomanufacturing, and genomic data that currently fall outside the government's 16 recognized critical infrastructure sectors.
A bipartisan, bicameral group of lawmakers dropped two bills last week that would force the federal government to treat biotechnology infrastructure and sensitive biological data the way it treats power grids and water systems: as assets worth defending before something breaks.
The Protecting Biotechnology and Biomanufacturing as Critical Infrastructure Act and the Protecting Biological Data as Critical Infrastructure Act were introduced September 24, according to a press release reviewed from the National Security Commission on Emerging Biotechnology. In the Senate, NSCEB Chair Todd Young (R-IN) and Maggie Hassan (D-NH) are the lead sponsors. In the House, the companion bills carry Ro Khanna (D-CA-17), Stephanie Bice (R-OK-05), and Scott Peters (D-CA-50), per bill text filed with the Government Publishing Office.
The core problem the bills address isn't exotic. Biotech doesn't fit cleanly into any of the 16 government-designated critical infrastructure sectors, as CyberScoop reported after the announcement, so hospitals, genomic databases, and biomanufacturing facilities that cut across health, agriculture, and industrial designations can end up in a coverage gap. The first bill would direct DHS to establish a mechanism for cross-sector infrastructure that doesn't fit the existing boxes, and would require updating the National Infrastructure Protection Plan to incorporate biotech sector input. The second bill would direct CISA specifically to designate systems handling genomic sequences and sensitive biometric data as critical infrastructure, and to build security protocols in collaboration with industry stakeholders.
The legislative rationale draws on NSCEB's own April 2025 report to Congress, which assessed, at what the commission described as a clear finding, that malicious actors will increasingly target the biotechnology sector's infrastructure and data. That report also noted that biological data are not currently treated or protected as a strategic national resource. Treat that as a moderate-confidence policy assessment grounded in open-source incident data, not a confirmed threat-actor campaign.
The dual-use dimension here deserves flagging. Genomic sequence data is both a target and an instrument: the same databases that make precision medicine possible make a foreign intelligence service's job easier if left unsecured. The bills don't resolve that ambiguity, and the press release doesn't wrestle with it either. What the bills do is structural: they route biotech into CISA's statutory mandate rather than relying on informal coordination.
There's a policy tension worth watching. These bills land as the current administration has moved to scale back biodefense language and priorities at NIAID, per reporting by Nature earlier this year, and as the National Science Advisory Board for Biosecurity has sat at five of 25 voting member seats filled since at least late 2024. Directing CISA to do more on biotech cyber while the public health preparedness apparatus shrinks on the research side is a coherent posture only if you believe the threat is primarily adversarial intrusion rather than natural emergence. That's a bet worth naming explicitly.
Both bills were referred to committee on September 24, the Senate version to Homeland Security and Governmental Affairs, the House version to the Committee on Homeland Security. No markup date has been announced. Prospects in a compressed legislative calendar are unclear.
Sources cited:
- National Security Commission on Emerging Biotechnology press release (https://www.biotech.senate.gov/press-releases/new-bills-designate-biotechnology-biomanufacturing-and-biological-data-as-critical-infrastructure/)
- CyberScoop (https://cyberscoop.com/biotech-critical-infrastructure-cybersecurity-legislation/)
- S. 5502 (IS), GovInfo (https://www.govinfo.gov/app/details/BILLS-119s5502is)
- H.R. 10569 (IH), GovInfo (https://www.govinfo.gov/app/details/BILLS-119hr10569ih)
- Senator Young press release (https://www.young.senate.gov/newsroom/press-releases/young-introduces-bills-to-protect-american-biotechnology-infrastructure-data-from-malicious-actors/)
This release was originally distributed via ETL Newswire. Visit National Security Commission on Emerging Biotechnology press release for the full story, related releases, and contact information.
Visit National Security Commission on Emerging Biotechnology press release →