Data Infrastructure Risk Reduction Act
H.R. 8711119th Congress

Data Infrastructure Risk Reduction Act

Introduced in the HouseRep. Suhas Subramanyam (D-VA-10)12 sections · 1 min read
Version: Introduced in House · May 7, 2026

Section 1. Short title

This Act may be cited as the Data Infrastructure Risk Reduction Act.

(a) In general

Not later than 180 days after the date of the enactment of this Act, the Secretary of Homeland Security, acting through the Director of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security, in collaboration, as appropriate, with the Secretary of Defense, shall—

(1) identify data centers that should be treated as critical infrastructure;

(2) consider—

(A) the security of the power and water supply infrastructure (with a particular focus on above-ground electric power transmission lines and electrical substations) connected to such data centers; and

(B) any potential implications of data centers that are sited in proximity to communities or other residential areas; and

(3) submit to Congress a strategy, including recommendations, to—

(A) defend data centers described in this subsection from external breaches from malefactors; and

(B) protect communities and other residential areas described in paragraph (2)(B).

(b) Definitions

In this section:

(1) Critical infrastructure

The term critical infrastructure has the meaning given such term in section 1016(e) of Public Law 107–56 (42 U.S.C. 5195c(e)).

(2) Data center

The term data center has the meaning given such term in section 453(a) of the Energy Independence and Security Act of 2007 (42 U.S.C. 17112(a)).

to ask questions about this bill.