Skip to main content
Rule Updates

Three Cyber Bills Clear a Senate Panel: Reg Harmonization, Health Security, and Workforce

A Senate committee advanced three bipartisan cyber bills — including one aimed at harmonizing the 'patchwork' of federal cyber rules contractors complain about.

Brandon Hancock, J.D., CMMC-RPPublished July 31, 2024Updated June 5, 20265 min read

On July 31, 2024, the Senate Homeland Security and Governmental Affairs Committee voted 10-1 to advance three bipartisan cybersecurity bills, sending them toward full Senate consideration. One of them targets a complaint every compliance officer knows well: the patchwork of conflicting federal cyber rules. Here is what cleared committee and why it matters to contractors.

1. Streamlining Federal Cybersecurity Regulations Act

Co-sponsored by Chair Gary Peters (D-Mich.) and Sen. James Lankford (R-Okla.), this bill aims to harmonize federal cyber requirements for the private sector — a long-standing industry frustration about overlapping and sometimes contradictory mandates from different agencies.

It would create a committee — including the National Cyber Director, the head of OMB's Office of Information and Regulatory Affairs (OIRA), and the heads of federal regulatory agencies — charged with identifying cyber regulations that are "overly burdensome, inconsistent, or contradictory" and recommending fixes. For contractors juggling FAR/DFARS, agency-specific rules, CISA directives, and sector regulators, harmonization is the holy grail: less duplicated effort, fewer conflicting clocks.

2. Healthcare Cybersecurity Act

From Sens. Jacky Rosen (D-Nev.), Todd Young (R-Ind.), and Angus King (I-Maine), this bill responds to the February 2024 ransomware attack on Change Healthcare, which disrupted payments across much of the U.S. health system. It would direct CISA to collaborate with HHS on health-sector cyber defense, provide resources to non-federal entities, and designate a CISA liaison to HHS to coordinate during cyber events. It is part of a broader federal push on healthcare cyber resilience (see our look at the White House healthcare cybersecurity effort).

3. Federal Cyber Workforce Training Act

From Sens. Mike Rounds (R-S.D.) and Jon Ossoff (D-Ga.), this bill tasks the National Cyber Director with building a centralized training resource for the federal cyber workforce — making it easier to prepare early-career hires and re-skill mid-career staff, leveraging academia to develop curricula.

A Reality Check on "Cleared Committee"

Clearing a committee is an early step, not a law. Bills can stall, change substantially, or die before a floor vote — and many do. Treat this as a signal of direction, not a new obligation. The useful takeaway is where Congress is pointing: toward reducing regulatory friction and shoring up health-sector and workforce cyber capacity.

What to Do Now

  • Track the harmonization bill. If it becomes law, it could reshape how overlapping cyber rules apply to you — for the better.
  • Healthcare contractors: expect continued federal focus on sector cyber resilience; align early. See Healthcare.
  • Don't change compliance plans yet. Build to the rules in force today while watching these for movement.

Key Takeaways

  • A Senate panel advanced three bipartisan cyber bills on reg harmonization, health security, and workforce.
  • The harmonization bill is the one to watch for contractors tired of conflicting mandates.
  • Committee passage is an early signal, not a final rule — keep complying with current requirements.

Keep current obligations straight with Find My Requirements, or review the Federal Statutes library.

Share
BH

Brandon Hancock

J.D. · CMMC Registered Practitioner (RP)

Brandon is the founder and principal advisor of GovConCyber. His advisory approach is shaped by roughly six years as a U.S. Army human intelligence collector, where information accuracy, source protection, classification discipline, need-to-know access, and controlled reporting were daily requirements. He brings that information-discipline mindset to GovConCyber's work helping government contractors understand and comply with federal cybersecurity obligations.

Was this post helpful?

Keep reading

Rule UpdatesMaryland Just Widened Which State Contracts Carry Cyber and Privacy Clauses — Effective October 1The Maryland Data Privacy and Protection Act of 2026 (Chapter 435, House Bill 264) takes effect October 1, 2026 and rewrites State Finance and Procurement § 13-115. Collecting, storing, or processing personal information is now an independent trigger for mandatory security, data collection, and privacy requirements in Maryland State contracts — no connection to a State system required — and the statutory definition of personal information expanded at the same time.August 31, 2026 · 7 min readRule UpdatesCISA Published the Logging Reference Architecture — and Contractor-Operated Systems Are In ScopeCISA published the Logging Reference Architecture on August 20, 2026, implementing OMB Memorandum M-26-14, which rescinded M-21-31 and put federal civilian agencies on a maturity clock for how they log, retain, and produce network data. The memorandum reaches systems operated “by third parties on the agency’s behalf” — so contractor-run systems are inside the agency’s plan, and the obligation will arrive through contract terms rather than the memo itself.August 27, 2026 · 7 min readRule UpdatesOMB Rescinded the Governmentwide Software Attestation Mandate — Now Each Agency Sets Its Own TermsFor two years, software producers selling to the federal government worked from a single assumption: sign the CISA Common Form or the agency cannot use your product. That assumption is no longer correct — and the replacement is harder to track, not easier.August 18, 2026 · 6 min read