Recent Bills
- H.R. 10171August 27, 2026
- H.R. 10156August 27, 2026
- H.R. 10172August 27, 2026
- H.R. 10160August 27, 2026
- H.R. 10181August 27, 2026
- H.R. 10176August 27, 2026
- H.Res. 1496August 27, 2026
- H.R. 10164August 27, 2026
- H.R. 10170August 27, 2026
- H.Res. 1494August 27, 2026
- H.R. 10163August 27, 2026
- H.R. 10157August 27, 2026
Committees
- AdministrationU.S. House
- AgricultureU.S. House
- Agriculture, Nutrition, And ForestryU.S. House
- AppropriationsU.S. House
- Armed ServicesU.S. House
- Banking, Housing, And Urban AffairsU.S. House
- BudgetU.S. House
- Commerce, Science, And TransportationU.S. House
- Education and WorkforceU.S. House
- Energy And CommerceU.S. House
- Energy And Natural ResourcesU.S. House
- Environment And Public WorksU.S. House
- EthicsU.S. House
- FinanceU.S. House
- Financial ServicesU.S. House
- Foreign AffairsU.S. House
- Foreign RelationsU.S. House
- Health, Education, Labor, And PensionsU.S. House
- Homeland SecurityU.S. House
- Homeland Security And Governmental Affa…U.S. House
- Indian AffairsU.S. House
- Indian and Insular AffairsU.S. House
- IntelligenceU.S. House
- JudiciaryU.S. House
- Natural ResourcesU.S. House
- Oversight And Government ReformU.S. House
- Permanent Select IntelligenceU.S. House
- RulesU.S. House
- Rules And AdministrationU.S. House
- Science, Space, And TechnologyU.S. House
- Select IntelligenceU.S. Senate
- Small BusinessU.S. House
- Small Business And EntrepreneurshipU.S. House
- Subcommittee on AviationU.S. House
- Subcommittee on Border Security and Enf…U.S. House
- Subcommittee on Coast Guard and Maritim…U.S. House
- Subcommittee on Commodity Markets, Digi…U.S. House
- Subcommittee on Conservation, Research,…U.S. House
- Subcommittee on Counterterrorism and In…U.S. House
- Subcommittee on Cybersecurity and Infra…U.S. House
- Subcommittee on Disability Assistance a…U.S. House
- Subcommittee on Economic Development, P…U.S. House
- Subcommittee on Economic OpportunityU.S. House
- Subcommittee on Emergency Management an…U.S. House
- Subcommittee on Energy and Mineral Reso…U.S. House
- Subcommittee on Federal LandsU.S. House
- Subcommittee on Forestry and Horticultu…U.S. House
- Subcommittee on General Farm Commoditie…U.S. House
- Subcommittee on HealthU.S. House
- Subcommittee on Highways and TransitU.S. House
- Subcommittee on Livestock, Dairy, and P…U.S. House
- Subcommittee on Nutrition and Foreign A…U.S. House
- Subcommittee on Oversight and Investiga…U.S. House
- Subcommittee on Oversight, Investigatio…U.S. House
- Subcommittee on Railroads, Pipelines, a…U.S. House
- Subcommittee on Transportation and Mari…U.S. House
- Subcommittee on Water Resources and Env…U.S. House
- Subcommittee on Water, Wildlife and Fis…U.S. House
- Transportation And InfrastructureU.S. House
- Veterans' AffairsU.S. House
- Ways And MeansU.S. House

HB 165
Utah House•Passed
Summary
HB 165, “Critical Infrastructure Amendments”, was introduced in the House on Jan 7, 2026 by Rep. Walt Brooks (R) with 1 co-sponsor. It last saw action on Mar 17, 2026: Governor Signed in Lieutenant Governor's office for filing.
Record
Text
HB 165 has 1 co-sponsor and 8 roll calls.
hb165/enrolled.txtEnrolled Copy H.B. 1651Critical Infrastructure Amendments2026 GENERAL SESSIONSTATE OF UTAHChief Sponsor: Walt BrooksSenate Sponsor: Keven J. Stratton23 LONG TITLE4 General Description:5This bill enacts provisions regarding foreign adversary threats to critical infrastructure.6 Highlighted Provisions:7This bill:8▸ defines terms;9▸ directs the Utah Cyber Center to develop guidance on foreign adversary threats to critical10 infrastructure;11▸ prohibits use of federally banned equipment in critical infrastructure;12▸ authorizes voluntary security assessments for critical infrastructure involving foreign13 adversary technology;14▸ provides for coordination between the Utah Cyber Center and governmental entities on15 critical infrastructure security;16▸ prohibits governmental entities and critical infrastructure providers from contracting for17 or deploying technology included on a prohibited list maintained by the Utah Cyber18 Center;19▸ requires the Utah Cyber Center to publish and maintain a prohibited list of foreign20 adversary technologies that pose a risk to critical infrastructure;21▸ prohibits entities with access to critical infrastructure from entering into agreements with22 foreign principals that would allow remote access to or control of critical infrastructure;23 and24▸ authorizes the Utah Cyber Center to approve exceptions to the prohibitions under25 specified circumstances.26 Money Appropriated in this Bill:27NoneH.B. 165 Enrolled Copy28 Other Special Clauses:29None30 Utah Code Sections Affected:31 ENACTS:3263A-16-1301, Utah Code Annotated 19533363A-16-1302, Utah Code Annotated 19533463A-16-1303, Utah Code Annotated 19533536 Be it enacted by the Legislature of the state of Utah:37Section 1. Section 63A-16-1301 is enacted to read:38Part 13. Critical Infrastructure Cyber Security3963A-16-1301 . Definitions.40 As used in this part:41 (1) "Critical infrastructure" means systems and assets operated or maintained by a42governmental entity that are vital to the governmental entity's jurisdiction such that the43incapacity or destruction of the systems and assets would have a debilitating impact on44security, economic security, or public health, including:45(a) emergency services communications systems;46(b) electrical power systems;47(c) water and wastewater systems;48(d) transportation management systems;49(e) data centers and networks; and50(f) systems that store or process sensitive data or classified information.51 (2) "Cyber Center" means the Utah Cyber Center created in Section 63A-16-1102.52 (3) "Foreign adversary" means a country listed in 15 C.F.R. Sec. 791.4 as that regulation53existed on January 1, 2026.54 (4) "Foreign principal" means:55(a) the government or an official of the government of a foreign adversary;56(b) a political party or member of a political party or subdivision of a political party of a57foreign adversary;58(c) an entity, including a partnership, association, corporation, organization, or other59combination of persons organized under the laws of or having a principal place of60business in a foreign adversary, or a subsidiary of the entity;61(d) an individual who is domiciled in a foreign adversary and is not a citizen or lawful-2-Enrolled Copy H.B. 16562permanent resident of the United States; or63 (e) an individual, entity, or collection of individuals or entities described in Subsections64(4)(a) through (d) having a controlling interest in a partnership, association,65corporation, organization, trust, or other legal entity or subsidiary formed for the66purpose of owning real property.67 (5) "Governmental entity" means the same as that term is defined in Section 63G-2-103.68 (6) "Information and communications technology" means any technology, system, device,69 application, or service used to create, collect, store, process, transmit, receive, display, or70 exchange information by electronic or digital means, including computers, software,71 networks, telecommunications systems, and related infrastructure.72Section 2. Section 63A-16-1302 is enacted to read:7363A-16-1302 . Foreign adversary threats to critical infrastructure -- Guidance74 and assessments.75 (1) The Cyber Center shall, within available resources and in coordination with federal76 agencies, develop and maintain guidance for governmental entities on protecting critical77 infrastructure from foreign adversary cybersecurity threats.78 (2) The guidance described in Subsection (1) shall include:79 (a) best practices for identifying and assessing security risks when foreign adversary80technology, software, or services are used in connection with critical infrastructure;81 (b) recommended security controls and monitoring procedures for critical infrastructure82that utilizes foreign adversary technology;83 (c) procedures for limiting foreign adversary access to critical infrastructure systems and84data;85 (d) methods for assessing and documenting risks associated with foreign adversary86involvement in critical infrastructure;87 (e) recommendations for transitioning away from foreign adversary technology in88critical infrastructure when feasible and cost effective;89 (f) identification of categories of critical infrastructure that present heightened security90concerns if foreign adversary technology is involved; and91 (g) recommendations for a comprehensive manual operations contingency plan for92critical infrastructure that:93(i) details non-networked, non-automated, and manually executable procedures; and94(ii) is sufficient to sustain core operational functions of the critical infrastructure in95the event of a significant cyber incident that renders automated or networked-3-H.B. 165 Enrolled Copy96control systems unreliable or inoperable.97 (3) The Cyber Center shall:98(a) review and update the guidance described in Subsection (1) at least annually;99(b) make the guidance readily accessible to governmental entities through the division's100website; and101(c) include information on foreign adversary threats to critical infrastructure in briefings102and materials provided to governmental entities on cybersecurity matters.103 (4) A governmental entity that operates or maintains critical infrastructure may request a104security assessment from the Cyber Center if the governmental entity:105(a) is considering procurement of technology, software, or services from a foreign106adversary for use in critical infrastructure; or107(b) identifies that critical infrastructure currently utilizes technology, software, or108services from a foreign adversary.109 (5) The Cyber Center shall prioritize security assessment requests under Subsection (4)110based on:111(a) the sensitivity of the data or systems involved;112(b) the potential impact of a compromise on security, economic security, or public health;113(c) available Cyber Center resources; and114(d) other relevant factors determined by the Cyber Center.115 (6) A security assessment conducted under Subsection (4) may include:116(a) an evaluation of potential security vulnerabilities associated with the foreign117adversary technology, software, or services;118(b) an assessment of potential risks to critical infrastructure systems and data;119(c) an analysis of the potential impact of a compromise of the critical infrastructure on120the governmental entity's operations, public safety, or economic security;121(d) recommendations for security measures or contract provisions to mitigate identified122risks; and123(e) identification of alternative technology, software, or services that may present lower124security risks.125 (7) In conducting a security assessment under Subsection (4), the Cyber Center may:126(a) coordinate with the Department of Public Safety and other relevant governmental127entities; and128(b) coordinate with and utilize resources from federal agencies, including the129Cybersecurity and Infrastructure Security Agency, as available.-4-Enrolled Copy H.B. 165130 (8) If the Cyber Center identifies significant security risks associated with foreign adversary131 technology in critical infrastructure, the Cyber Center may:132 (a) notify the chief information officer and the affected governmental entity of the133identified risks;134 (b) recommend that the governmental entity implement enhanced security monitoring or135controls;136 (c) recommend that the governmental entity develop a plan to transition to alternative137technology; or138 (d) recommend that the matter be referred to appropriate state or federal law139enforcement or security agencies.140 (9) A governmental entity that operates or maintains critical infrastructure shall, when141 reporting a data breach to the Cyber Center under Section 63A-19-405, indicate whether142 the data breach involved technology, software, or services from a foreign adversary.143 (10) Except as provided in Subsection (12), a security assessment or recommendation144 provided under this section is advisory only and does not:145 (a) prohibit a governmental entity from entering into a contract or making a procurement146decision; or147 (b) require a governmental entity to transition away from existing technology, software,148or services.149 (11) Information obtained by the Cyber Center in conducting a security assessment under150 this section is protected in accordance with Title 63G, Chapter 2, Government Records151 Access and Management Act.152 (12) On or after July 1, 2026, a governmental entity or critical infrastructure provider may153 not:154 (a) enter into or renew a contract with a vendor for information and communications155technology that the Cyber Center has included on the prohibited list described in156Subsection (13); or157 (b) otherwise place into service any additional information and communications158technology that the Cyber Center has included on the prohibited list described in159Subsection (13).160 (13)(a) On or after July 1, 2026, the Cyber Center shall publish and maintain a list of161 prohibited companies and information and communications technologies that the162 Cyber Center has assessed pose a risk of providing a foreign adversary with remote163 access to or control of critical infrastructure.-5-H.B. 165 Enrolled Copy164(b) The prohibited list shall include, at a minimum, companies and technologies that:165(i) appear on the Pentagon 1260H list;166(ii) appear on the Federal Communications Commission Covered List; or167(iii) are a re-labeled version of, or are produced by a subsidiary of a company168included in a technology described in Subsection (13)(b)(i) or (ii), and for which169the Cyber Center has identified that a reasonable alternative provider exists.170 (14) Notwithstanding Subsection (12), a governmental entity or critical infrastructure171provider may use a technology included on the prohibited list described in Subsection172(13) if no reasonable alternative exists to address the need relevant to state critical173infrastructure.174Section 3. Section 63A-16-1303 is enacted to read:17563A-16-1303 . Foreign adversary prohibition in critical infrastructure.176 (1) A company, governmental entity, or other entity that constructs, repairs, maintains, or177operates critical infrastructure, or that otherwise has significant access to critical178infrastructure, may not enter into a contract or other agreement relating to critical179infrastructure in this state with a foreign principal from a foreign adversary if the180agreement would allow the foreign principal to directly or remotely access or control181critical infrastructure in this state.182 (2) Notwithstanding Subsection (1), a company, governmental entity, or other entity may183enter into a contract described in Subsection (1) with a foreign principal from a foreign184adversary if no reasonable alternative exists to address the need relevant to state critical185infrastructure.186Section 4. Effective Date.187 This bill takes effect on May 6, 2026.-6-
Critical Infrastructure Amendments
Sponsors
Rep. Walt Brooks (R) sponsors HB 165, and 1 member has co-sponsored it.
Committees
HB 165 went before 3 committees: Rules, Law Enforcement and Criminal Justice and Transportation, Public Utilities, Energy, and Technology.
Transportation, Public Utilities, Energy, and Technology

Transportation, Public Utilities, Energy, and Technology
Referred to · Feb 17, 2026
History
HB 165 has taken 73 actions since Jan 7, 2026, the latest on Mar 17, 2026.
| Chamber | Action | |||
|---|---|---|---|---|
Mar 17, 2026 | — | Governor Signed in Lieutenant Governor's office for filing | ||
Mar 11, 2026 | House | House/ received enrolled bill from Printing in Clerk of the House | ||
Mar 11, 2026 | — | House/ to Governor in Executive Branch - Governor | ||
Mar 6, 2026 | House | Enrolled Bill Returned to House or Senate in Clerk of the House | ||
Mar 6, 2026 | House | House/ enrolled bill to Printing in Clerk of the House |
Votes
HB 165 went to 8 roll calls across both chambers, the latest on Mar 2, 2026 at 68–1.
| Chamber | Question | Yea | Nay | |||
|---|---|---|---|---|---|---|
Mar 2, 2026 | House | House Conference Committee - Final Passage | 68 | 1 | ||
Feb 27, 2026 | Senate | Senate Conference Committee - Final Passage | 24 | 0 | ||
Feb 26, 2026 | Senate | Senate/ passed 3rd reading | 20 | 0 | ||
Feb 25, 2026 | Senate | Senate/ passed 2nd reading | 23 | 0 | ||
Feb 18, 2026 | Senate | Senate Comm - Favorable Recommendation | 6 | 0 |
Source: le.utah.gov · legiscan.com