Tap any paragraph to write a margin note. Your notes collect in the Desk below the text and file under cases with @. The side-by-side margin rail opens on a larger screen.

Code · BILL · 119th Congress · S. 1071 (EAH) — 119 S1071 EAH: National Defense Authorization Act for Fiscal Year 2026 · Sec. 866

Sec. 866. Cybersecurity regulatory harmonization

438 words·~2 min read·/bill/119/s/1071/eah/section-866

A research copy — for the controlling text, always check the official state or federal source. Not legal advice.

Not later than June 1, 2026, the Secretary of Defense, in coordination with the Chief Information Officer of the Department of Defense, the Chief Information Officer of each military department, and representatives from the service acquisition executives of each military department, shall— harmonize the cybersecurity requirements applicable to the defense industrial base across the Department of Defense; reduce the number of such requirements that are unique to a specific contract or other agreement of the Department; and submit to the congressional defense committees a report on the actions taken to carry out the harmonization described in paragraph
(1)and the reduction described in paragraph (2). The harmonization required by subsection (a)(1) shall ensure that processes and governance structures exist and are sufficient to identify and eliminate duplicative and inconsistent cybersecurity requirements and cybersecurity requirements unique to single contracts, including— a process and governance structure for assessing whether future proposed cybersecurity contractual requirements for contracts or other agreements of the Department of Defense are duplicative of other applicable requirements of the Department of Defense that are published in the Federal Register; a process for coordinating, centralizing, approving, and publishing any proposed cybersecurity requirement not published in the Federal Register; and a mechanism included in the process described in paragraph
(2)for ensuring the visibility to and input from internal and external stakeholders. Not later than December 31, 2026, and annually thereafter for three years, the Chief Information Officer of the Department of Defense shall submit to the congressional defense committees a report describing the actions taken to implement subsections
(a)and (b), including the status of the harmonization of contractual cybersecurity requirements and of reducing cybersecurity requirements unique to single contracts required by such sections. Each report required by paragraph
(1)shall cover the most recently completed fiscal year prior to the submission of the report and include— a description of any changes made during the period covered by the report to the processes and governance structures described in subsection (b); a list of each contract or other agreement of the Department of Defense entered into during the period covered by the report for which the Department sought to include a cybersecurity requirement not published in the Federal Register; for each contract or other agreement included on the list required by subparagraph (B), whether the Secretary of Defense approved the inclusion of the cybersecurity requirement for which such contract or other agreement was included on such list and an explanation of the reasoning of the Secretary for approving or denying such inclusion; and such other matters as determined necessary by the Chief Information Officer of the Department of Defense.
★   the supreme law of the land   ★
Don't Tread on Me
E Pluribus Unum — out of many, one

"If you don't know your rights, you don't have any."

Marginalia · a citizen's law index
A research desk, not legal advice. Always read the cited source before relying on a summary.
Questions or an issue? support@self-law.org
disclaimerMarginalia is a research index, not a law firm. Nothing on this site is legal, tax, or financial advice and no attorney–client relationship is formed by using it. Statutes, regulations, and case law change; summaries, search results, AI output, and member posts may be incomplete, out of date, or wrong. Any interpretation drawn from material on this site should be validated by a licensed attorney in your jurisdiction before you act on it.