S. 2392Senate115th Congress (2017-2019)In Committee

Cyber SAFETY Act of 2018

Introduced February 7, 2018

AI-Generated Summary

Updated April 15, 2026 at 8:13 PM UTC

The Cyber SAFETY Act of 2018 amends the Homeland Security Act of 2002 so the Secretary of Homeland Security can officially recognize and protect certain cybersecurity technologies, treating them like anti‑terrorism tools. It also expands the definition of covered incidents to include "qualifying cyber incidents," giving them the same legal handling as acts of terrorism. This affects technology vendors, the DHS certification process, and any entity dealing with cyber‑related threats.

Key Provisions

  • Updates the law’s language to add "cybersecurity" alongside "anti‑terrorism" in multiple sections, allowing the Secretary to designate cybersecurity technologies.
  • Creates a new certification process for cybersecurity technologies, issuing certificates of conformance and placing approved products on a DHS Approved Product List.
  • Requires the Secretary to review certified cybersecurity technologies at least every two years.
  • Adds the term "qualifying cyber incident" (defined by the existing definition of “incident” in 44 USC 3552(b)) and treats such incidents like acts of terrorism for risk and litigation management.
  • Makes the Secretary’s determination that a qualifying cyber incident occurred a final agency action subject to judicial review under the Administrative Procedure Act.

Legislative Activity

Stay on top of the latest movement without scrolling through every action

1 earlier action
SenateIntro Referral Latest Action

Read twice and referred to the Committee on Homeland Security and Governmental Affairs. (Sponsor introductory remarks on measure: CR S705-706)

February 7, 2018

View full timeline
SenateIntro Referral

Introduced in Senate

February 7, 2018

SenateIntro Referral

Read twice and referred to the Committee on Homeland Security and Governmental Affairs. (Sponsor introductory remarks on measure: CR S705-706)

February 7, 2018

Floor Debate

2 members

What members said about S. 2392 on the floor

2 Republicans
Chuck Grassley
Sen. Chuck GrassleyR-IA · Feb 7, 2018

Mr. President, two decades ago, I championed passage of the Congressional Accountability Act. It was the first piece of legislation passed by the 104th Congress and the first time in history that…

Steve Daines
Sen. Steve DainesR-MT · Feb 7, 2018

Mr. President, in recent years we have seen the inability of the Federal government to quickly adapt to changing technology and evolving cyber security threats. In June of 2015 the Office of…

Steve Daines
Sen. Steve DainesR-MT · Feb 7, 2018

Mr. President, in recent years we have seen the inability of the Federal government to quickly adapt to changing technology and evolving cyber security threats. In June of 2015 the Office of…

Bill Text

Latest available legislative text

Reading Mode
Latest
Introduced in SenateIssued February 7, 2018

II

115th CONGRESS

2d Session

S. 2392

IN THE SENATE OF THE UNITED STATES

February 7, 2018

Mr. Daines introduced the following bill; which was read twice and referred to the Committee on Homeland Security and Governmental Affairs

A BILL

To amend the Homeland Security Act of 2002 to authorize the Secretary of Homeland Security to designate cybersecurity technologies that qualify for protection under systems of risk and litigation management.

1.

Short title

This Act may be cited as the Cyber Support for Anti-Terrorism by Fostering Effective Technologies Act of 2018 or the Cyber SAFETY Act of 2018.

2.

Inclusion of qualifying cyber incidents

Subtitle G of title VIII of the Homeland Security Act of 2002 (6 U.S.C. 441 et seq.) is amended—

(1)

in section 862(b) (6 U.S.C. 441(b))—

(A)

in the heading, by striking Designation of qualified anti-terrorism technologies and inserting Designation of anti-Terrorism and cybersecurity technologies;

(B)

in the matter preceding paragraph (1), by inserting or cybersecurity after anti-terrorism;

(C)

in paragraphs (3), (4), and (5), by inserting or cybersecurity after anti-terrorism each place that term appears; and

(D)

in paragraph (7)—

(i)

by inserting “or cybersecurity” after “Anti-terrorism”; and

(ii)

by inserting or qualifying cyber incidents after acts of terrorism;

(2)

in section 863 (6 U.S.C. 442)—

(A)

by inserting or cybersecurity after anti-terrorism each place that term appears;

(B)

by inserting or qualifying cyber incident after act of terrorism each place that term appears;

(C)

by inserting or qualifying cyber incidents after acts of terrorism each place that term appears; and

(D)

in subsection (d)(3)—

(i)

by striking (3) Certificate.— and inserting the following:

(3) Certificates.—

(A)

Certificates for anti-terrorism technologies

; and

(ii)

by adding at the end the following:

(B)

Certificates for cybersecurity technologies

(i)

In general

For cybersecurity technology reviewed and approved by the Secretary, the Secretary will issue a certificate of conformance to the Seller and place the cybersecurity technology on an Approved Product List for Homeland Security.

(ii)

Subsequent review

Not less frequently than once every 2 years, the Secretary shall conduct a new review of any cybersecurity technology for which the Secretary issued a certification under clause (i).

;

(3)

in section 864 (6 U.S.C. 443)—

(A)

by inserting or cybersecurity after anti-terrorism each place that term appears; and

(B)

by inserting or qualifying cyber incident after act of terrorism each place that term appears; and

(4)

in section 865 (6 U.S.C. 444)—

(A)

in paragraph (1)—

(i)

in the heading, by inserting or cybersecurity after anti-terrorism;

(ii)

by inserting or cybersecurity after anti-terrorism;

(iii)

by inserting or qualifying cyber incidents after acts of terrorism; and

(iv)

by inserting or incidents after such acts; and

(B)

by adding at the end the following:

(7)

Qualifying cyber incident

The term qualifying cyber incident has the meaning given the term incident in section 3552(b) of title 44, United States Code.

(8)

Final agency action

The determination by the Secretary that an act of terrorism or qualifying cyber incident has occurred shall constitute a final agency action subject to review under chapter 7 of title 5, United States Code.

.