CiberLATAMbywhalemate

U.S. Senate advances satellite cyber bill

The Satellite Cybersecurity Act of 2025 cleared its third committee. It would require Commerce to build a public guidance repository for operators.

Whalemate Labs · AI-assisted researchPublished:4 min read

The Satellite Cybersecurity Act of 2025 advanced in the U.S. Senate after clearing markup in the Senate Energy and Natural Resources Committee on July 29, 2026. It was the third committee to approve the bill in three months, moving it closer to a floor vote. The measure, led by Senators Gary Peters, a Michigan Democrat, and John Cornyn, a Texas Republican, aims to create a public repository of best practices for commercial satellite operators.

The Satellite Cybersecurity Act of 2025 advanced in the U.S. Senate after clearing markup in the Senate Energy and Natural Resources Committee on July 29, 2026. It was the third committee to approve the bill in three months, putting it closer to a floor vote. The measure was led by Senators Gary Peters, a Michigan Democrat, and John Cornyn, a Texas Republican.

What would the bill require for the satellite sector?

The text directs the Department of Commerce to create and maintain a publicly accessible online repository of voluntary cybersecurity recommendations for commercial satellite operators. That repository would bring together guidance from the industry and agencies such as CISA and the U.S. Space Force, with the goal of consolidating criteria that are now spread across different sources.

The bill also assigns the Government Accountability Office the task of reviewing existing federal efforts on satellite security. That review is meant to map prior initiatives and provide a basis for measuring how consistent the recommendations already circulating among agencies and the private sector really are.

What other recent bills point to the same regulatory shift?

At the same time, Congress continues to add proposals tied to critical infrastructure, water, and energy. In the House, Rick Crawford, a Republican from Arkansas, and John Duarte, a Republican from California, introduced the H.R.7922 Water Risk and Resilience Organization Establishment Act in 2024, later reworked as H.R.2594 in 2025, to create an independent EPA-certified organization that would set and enforce minimum cybersecurity standards for medium and large water utilities. That version has remained stalled in committee since April 2025.

In August 2026, Senators Adam Schiff, a California Democrat, and Amy Klobuchar, a Minnesota Democrat, introduced S.5368, the Water Cyber Shield Act of 2026. The bill would amend the Safe Drinking Water Act and the Clean Water Act to give the EPA explicit authority to conduct cybersecurity assessments, require corrective measures, and set security standards in coordination with CISA for drinking water and wastewater systems.

Quiver Quantitative summarizes S.5368 as a proposal to create a cybersecurity program for drinking water and wastewater systems, with a mandate to identify and reduce cyber risks and give federal and state agencies more tools.

Circle of Blue, in a water policy analysis, said the bill was introduced days after an attack attributed to Iranian actors against U.S. water utilities. It also noted that systems would have to prepare risk assessments and response plans, submit them to state authorities for approval, and protect that information from disclosure under the Freedom of Information Act. Govly added that the bill authorizes $300 million a year from fiscal 2027 through 2032 for cybersecurity assistance and infrastructure upgrades in drinking water and wastewater.

The legislative agenda also moved on electric power. Senators Chris Coons, a Delaware Democrat, and Mike Rounds, a South Dakota Republican, introduced the Quantum Grid Utility Assurance and Resilient Defense Act, or Quantum-GUARD Act, to strengthen the electric grid's resilience against cybersecurity threats tied to quantum computing.

Inside Cybersecurity reported that the package would direct FERC to include quantum risks in its review of grid reliability standards, so that critical operators would have to show their cryptographic controls account for attacks by quantum computers. The same coverage said the Department of Energy, through the CESER program, would need to create a dedicated sandbox to test post-quantum cryptography in IT and OT systems before deployment. The analysis also said DOE would have to systematically study quantum-related vulnerabilities in IT and OT across the bulk electric power system.

The Quantum Insider and Tai News agree that the initiative puts post-quantum cryptography at the center of U.S. grid protection. The Wall Street Journal added that the shift is likely to affect international operations as well for energy companies with assets in the United States. In Europe, e-security.bg said one of the first practical requirements would be for utilities to build a detailed inventory of their current use of cryptography and their dependencies before moving to post-quantum standards.

Sources

View all