H.R. 1833House117th Congress (2021-2023)In Committee

DHS Industrial Control Systems Capabilities Enhancement Act of 2021

Sponsored by John KatkoRep. John Katko (R-NY)
Introduced March 11, 2021

AI-Generated Summary

Updated February 8, 2026 at 12:17 AM UTC

The DHS Industrial Control Systems Capabilities Enhancement Act of 2021 amends the Homeland Security Act to require the Cybersecurity and Infrastructure Security Agency (CISA) to develop and maintain capabilities for identifying and addressing cyber threats to industrial control systems used in critical infrastructure. It also mandates regular reporting to Congress and a review by the Government Accountability Office. The bill affects federal agencies, industry operators of industrial control systems, and other stakeholders involved in critical infrastructure security.

Key Provisions

  • Adds a new subparagraph requiring CISA’s Center to address security of both information technology and operational technology, including industrial control systems.
  • Creates a new subsection obligating the CISA Director to lead federal efforts to identify and mitigate cyber threats to industrial control systems, maintain threat‑hunting and incident‑response capabilities, provide technical assistance, share vulnerability information, and take other appropriate actions.
  • Requires the CISA Director to brief the House and Senate Homeland Security committees on these capabilities every six months for four years.
  • Mandates the GAO to review the implementation of the new CISA responsibilities within two years and report on inter‑agency coordination, resource adequacy, stakeholder assistance, and vulnerability‑information sharing.

Legislative Activity

Stay on top of the latest movement without scrolling through every action

13 earlier actions
SenateIntro Referral Latest Action

Received in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs.

July 21, 2021

View full timeline
HouseIntro Referral

Introduced in House

March 11, 2021

HouseIntro Referral

Referred to the House Committee on Homeland Security.

March 11, 2021

HouseCommittee

Referred to the Subcommittee on Cybersecurity, Infrastructure Protection, and Innovation.

March 12, 2021

HouseCommittee

Subcommittee on Cybersecurity, Infrastructure Protection, and Innovation Discharged.

March 18, 2021

HouseCommittee

Committee Consideration and Mark-up Session Held.

March 18, 2021

HouseCommittee

Ordered to be Reported (Amended).

March 18, 2021

HouseFloor

Ms. Clarke (NY) moved to suspend the rules and pass the bill, as amended.

July 20, 2021 • 1:13 PM

HouseFloor

Considered under suspension of the rules. (consideration: CR H3695-3696; text: H3695)

July 20, 2021 • 1:13 PM

HouseFloor

DEBATE - The House proceeded with forty minutes of debate on H.R. 1833.

July 20, 2021 • 1:13 PM

HouseFloor

At the conclusion of debate, the Yeas and Nays were demanded and ordered. Pursuant to the provisions of clause 8, rule XX, the Chair announced that further proceedings on the motion would be postponed.

July 20, 2021 • 1:22 PM

HouseFloor

Pursuant to the provisions of H. Res. 535, proceedings on H.R. 1833 are considered vacated.

July 20, 2021 • 4:44 PM

HouseFloor

Passed/agreed to in House: Pursuant to section 7 of H. Res. 535, and the motion offered by Mr. Hoyer, the following bills passed under suspension of the rules: H.R. 678; H.R. 1036; H.R. 1079, as amended; H.R. 1158; H.R. 1250; H.R. 1754; H.R. 1833, as amended; H.R. 1850; H.R. 1871; H.R. 1877, as amended; H.R. 1893; H.R. 1895; H.R. 2118; H.R. 2795, as amended; H.R. 2928; H.R. 2980, as amended; H.R. 3003; H.R. 3138, as amended; H.R. 3223; H.R. 3263; and H.R. 3264; and the following resolutions were agreed to under suspension of the rules: H. Res. 277; and H. Res. 294.(consideration: CR H3715-3730; text: CR H3718)

July 20, 2021 • 4:44 PM

HouseFloor

Pursuant to section 7 of H. Res. 535, and the motion offered by Mr. Hoyer, the following bills passed under suspension of the rules: H.R. 678; H.R. 1036; H.R. 1079, as amended; H.R. 1158; H.R. 1250; H.R. 1754; H.R. 1833, as amended; H.R. 1850; H.R. 1871; H.R. 1877, as amended; H.R. 1893; H.R. 1895; H.R. 2118; H.R. 2795, as amended; H.R. 2928; H.R. 2980, as amended; H.R. 3003; H.R. 3138, as amended; H.R. 3223; H.R. 3263; and H.R. 3264; and the following resolutions were agreed to under suspension of the rules: H. Res. 277; and H. Res. 294. (consideration: CR H3715-3730; text: CR H3718)

July 20, 2021 • 4:44 PM

SenateIntro Referral

Received in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs.

July 21, 2021

Floor Debate

7 members

What members said about H.R. 1833 on the floor

5 Republicans2 Democrats
Yvette D. Clarke
Rep. Yvette D. ClarkeD-NY-9 · Jul 20, 2021

Madam Speaker, I move to suspend the rules and pass the bill (H.R. 1833) to amend the Homeland Security Act of 2002 to provide for the responsibility of the Cybersecurity and Infrastructure Security…

Rick W. Allen
Rep. Rick W. AllenR-GA-12 · Jul 20, 2021

Mr. Speaker, had I been present, I would have voted ``nay'' on rollcall No. 212. members recorded pursuant to house resolution 8, 117th congress Aderholt (Moolenaar) Buchanan (LaHood) DeSaulnier…

John Katko
Rep. John KatkoR-NY-24 · Jul 20, 2021

Madam Speaker, I yield myself such time as I may consume. I want to thank my colleague from New York for supporting my bill, Madam Speaker, I have no further speakers. I urge Members to support this…

Steny H. Hoyer
Rep. Steny H. HoyerD-MD-5 · Jul 20, 2021

Mr. Speaker, pursuant to section 7 of House Resolution 535, I move to suspend the rules and pass the bills: H.R. 678; H.R. 1036; H.R. 1079; H.R. 1158; H.R. 1250; H.R. 1754; H.R. 1833; H.R. 1850;

Pete Stauber
Rep. Pete StauberR-MN-8 · Jul 20, 2021

Mr. Speaker, had I been present, I would have voted ``nay'' on rollcall No. 212.

Show 2 more
Dan Bishop
Rep. Dan BishopR-NC-9 · Jul 20, 2021

Madam Speaker, on that I demand the yeas and nays.

Matthew M. Rosendale, Sr.
Rep. Matthew M. Rosendale, Sr.R-MT · Jul 20, 2021

Mr. Speaker, on that I demand the yeas and nays.

Bill Text

3 versions available

Reading Mode
Latest
Referred in SenateIssued July 21, 2021

IIB

117th CONGRESS

1st Session

H. R. 1833

IN THE SENATE OF THE UNITED STATES

July 21, 2021

Received; read twice and referred to the Committee on Homeland Security and Governmental Affairs

AN ACT

To amend the Homeland Security Act of 2002 to provide for the responsibility of the Cybersecurity and Infrastructure Security Agency to maintain capabilities to identify threats to industrial control systems, and for other purposes.

1.

Short title

This Act may be cited as the DHS Industrial Control Systems Capabilities Enhancement Act of 2021.

2.

Capabilities of the Cybersecurity and Infrastructure Security Agency to identify threats to industrial control systems

(a)

In general

Section 2209 of the Homeland Security Act of 2002 (6 U.S.C. 659) is amended—

(1)

in subsection (e)(1)—

(A)

in subparagraph (G), by striking and after the semicolon;

(B)

in subparagraph (H), by inserting and after the semicolon; and

(C)

by adding at the end the following new subparagraph:

(I)

activities of the Center address the security of both information technology and operational technology, including industrial control systems;

; and

(2)

by adding at the end the following new subsection:

(p)

Industrial control systems

The Director shall maintain capabilities to identify and address threats and vulnerabilities to products and technologies intended for use in the automated control of critical infrastructure processes. In carrying out this subsection, the Director shall—

(1)

lead Federal Government efforts, in consultation with Sector Risk Management Agencies, as appropriate, to identify and mitigate cybersecurity threats to industrial control systems, including supervisory control and data acquisition systems;

(2)

maintain threat hunting and incident response capabilities to respond to industrial control system cybersecurity risks and incidents;

(3)

provide cybersecurity technical assistance to industry end-users, product manufacturers, Sector Risk Management Agencies, other Federal agencies, and other industrial control system stakeholders to identify, evaluate, assess, and mitigate vulnerabilities;

(4)

collect, coordinate, and provide vulnerability information to the industrial control systems community by, as appropriate, working closely with security researchers, industry end-users, product manufacturers, Sector Risk Management Agencies, other Federal agencies, and other industrial control systems stakeholders; and

(5)

conduct such other efforts and assistance as the Secretary determines appropriate.

.

(b)

Report to Congress

Not later than 180 days after the date of the enactment of this Act and every six months thereafter during the subsequent 4-year period, the Director of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security shall provide to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate a briefing on the industrial control systems capabilities of the Agency under section 2209 of the Homeland Security Act of 2002 (6 U.S.C. 659), as amended by subsection (a).

(c)

GAO review

Not later than 2 years after the date of the enactment of this Act, the Comptroller General of the United States shall review implementation of the requirements of subsections (e)(1)(I) and (p) of section 2209 of the Homeland Security Act of 2002 (6 U.S.C. 659), as amended by subsection (a), and submit to the Committee on Homeland Security in the House of Representatives and the Committee on Homeland Security and Government Affairs of the Senate a report containing findings and recommendations relating to such implementation. Such report shall include information on the following:

(1)

Any interagency coordination challenges to the ability of the Director of the Cybersecurity and Infrastructure Agency of the Department of Homeland Security to lead Federal efforts to identify and mitigate cybersecurity threats to industrial control systems pursuant to subsection (p)(1) of such section.

(2)

The degree to which the Agency has adequate capacity, expertise, and resources to carry out threat hunting and incident response capabilities to mitigate cybersecurity threats to industrial control systems pursuant to subsection (p)(2) of such section, as well as additional resources that would be needed to close any operational gaps in such capabilities.

(3)

The extent to which industrial control system stakeholders sought cybersecurity technical assistance from the Agency pursuant to subsection (p)(3) of such section, and the utility and effectiveness of such technical assistance.

(4)

The degree to which the Agency works with security researchers and other industrial control systems stakeholders, pursuant to subsection (p)(4) of such section, to provide vulnerability information to the industrial control systems community.

Passed the House of Representatives July 20, 2021.

Cheryl L. Johnson,

Clerk