PILLAR Act
Bill journey · stage 2 of 5
Under committee review
What it doesSummary introduced in house (Sep 2, 2025)
Protecting Information by Local Leaders for Agency Resilience Act or the PILLAR Act
This bill extends the State and Local Cybersecurity Grant Program through FY2035, expands the scope of the program, and imposes certain limits on the use of grant funds. (The program provides grants to states and Indian tribes to address cybersecurity risks to government information systems.)
The bill expands the scope of systems that may be secured using grant funds to include operational technology systems and specifies that systems using artificial intelligence are included. Such systems must be maintained, owned, or operated by or on behalf of state, local, or tribal governments.
The bill also specifies that grant funds may not be used to purchase software, hardware, or related products or services that do not align with relevant guidance provided by the Cybersecurity and Infrastructure Security Agency (CISA).
Further, the bill increases the federal share of costs available to entities that implement or enable multifactor authentication and identity and access management tools for critical infrastructure by a specified date.
The bill requires annual reports by grant recipients to include a description of recipients’ progress in assuming the cost of continuing cybersecurity programs after grant funds are fully expended.
The Government Accountability Office must periodically review the program. This effort must include a review of artificial intelligence adoption across a sample of grants.
Finally, CISA must implement an outreach plan to inform local governments, including governments in rural areas or areas with small populations, about CISA’s no-cost cybersecurity offerings.
What just happenedNov 18, 2025
Received in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
Who’s behind it
- Referred in SenateNov 18, 2025
- Engrossed in HouseNov 17, 2025
- Reported in HouseNov 12, 2025
- Introduced in HouseSep 2, 2025
- Nov 18, 2025IntroReferral
Received in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
Homeland Security and Governmental Affairs Committee - Nov 17, 2025FloorH38310
Motion to reconsider laid on the table Agreed to without objection.
- Nov 17, 2025FloorH37300
On motion to suspend the rules and pass the bill, as amended Agreed to by voice vote. (text: CR H4685-4687)
- Nov 17, 2025Floor8000
Passed/agreed to in House: On motion to suspend the rules and pass the bill, as amended Agreed to by voice vote. (text: CR H4685-4687)
- Nov 17, 2025FloorH8D000
DEBATE - The House proceeded with forty minutes of debate on H.R. 5078.
- Nov 17, 2025FloorH30000
Considered under suspension of the rules. (consideration: CR H4685-4688)
- Nov 17, 2025FloorH30300
Mr. Garbarino moved to suspend the rules and pass the bill, as amended.
- Nov 12, 2025CalendarsH12410
Placed on the Union Calendar, Calendar No. 328.
- Nov 12, 2025CommitteeH12200
Reported by the Committee on Homeland Security. H. Rept. 119-377.
Homeland Security Committee - Nov 12, 2025Committee5000
Reported by the Committee on Homeland Security. H. Rept. 119-377.
Homeland Security Committee - Sep 3, 2025CommitteeH19000
Ordered to be Reported by the Yeas and Nays: 21 - 1.
Homeland Security Committee - Sep 3, 2025CommitteeH15001
Committee Consideration and Mark-up Session Held
Homeland Security Committee - Sep 3, 2025CommitteeH25000
Subcommittee on Cybersecurity and Infrastructure Protection Discharged
Homeland Security Committee - Sep 2, 2025CommitteeH11000
Referred to the Subcommittee on Cybersecurity and Infrastructure Protection.
Cybersecurity and Infrastructure Protection Subcommittee - Sep 2, 2025IntroReferralH11100
Referred to the House Committee on Homeland Security.
Homeland Security Committee - Sep 2, 2025IntroReferralIntro-H
Introduced in House
- Sep 2, 2025IntroReferral1000
Introduced in House