HR8710119th Congress

National Defense Data Resilience Act

Sponsored By: Representative Subramanyam, Suhas [D-VA-10]

Introduced

Summary

Would require the Department of Defense to build resilient, verifiable data recovery systems for critical military data. It would make the DoD classify data by criticality, set mandatory recovery time objectives, adopt certified recovery technologies, require a DoD-wide recovery strategy within 90 days, and send annual recovery certification reports to congressional defense committees.

Show full summary
  • DoD components and mission planners: Each DoD element would list every recovery time objective and evaluate whether those objectives meet requirements. Critical data RTOs must be set within 180 days and important or necessary data RTOs within 270 days.
  • Cybersecurity and IT teams: Would need immutable backups, logically separated and network-isolated copies, continuous monitoring for tampering, annual recovery exercises that simulate sophisticated nation-state attacks, and independent audits to validate recovery under realistic threats.
  • Vendors and procurement officers: The DoD could adopt only technologies on a certified inventory and would require standards such as immutable storage, full audit trails, and robust recovery capabilities, shaping future buys.

Personalized for You

How does this bill affect your finances?

Personalize government policy and PRIA will tell you what this bill means for your household, plus every other piece of legislation we track. PRIA reads each provision against your financial profile to show you exactly what matters to your wallet.

Bill Overview

Analyzed Economic Effects

1 provisions identified: 1 benefits, 0 costs, 0 mixed.

Stronger Defense data recovery rules

This bill would require the Department of Defense to label its data as critical, important, or necessary. It would require recovery time objectives for critical data within 180 days and for important or necessary data within 270 days. The RTOs would be updated for evolving threats, including threats from the People's Republic of China, and the Secretary would provide annual auditable recovery certification reports to Congress. The bill would require hardened recovery capabilities: immutable and logically separated backups, isolated copies, continuous monitoring, yearly recovery exercises that simulate nation-state attacks, and independent audits. It would also bar using data-recovery technology unless it is on a DoD certified inventory and meets standards like immutable storage and full audit trails. The Secretary would have to send a DoD-wide recovery strategy to Congress within 90 days, in unclassified form with a possible classified annex.

Sponsors & CoSponsors

Sponsor

Subramanyam, Suhas [D-VA-10]

VA • D

Cosponsors

  • Rep. McCormick, Richard [R-GA-7]

    GA • R

    Sponsored 5/7/2026

Roll Call Votes

No roll call votes available for this bill.

View on Congress.gov
Back to Legislation