Search

Search bills, members, committees and pages...

H.R. 8710

U.S. HouseIn House Committee

Summary

H.R. 8710, the National Defense Data Resilience Act, was introduced in the House on May 7, 2026 by Rep. Suhas Subramanyam (D) with 1 co-sponsor. It was referred to Armed Services, and last saw action on May 7, 2026: Referred to the House Committee on Armed Services.


Record

Text

H.R. 8710 has 1 co-sponsor.

hr8710/introduced-in-house.txt
119 HR 8710 IH: National Defense Data Resilience Act
U.S. House of Representatives
2026-05-07
text/xml
EN
Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.
I 119th CONGRESS 2d Session H. R. 8710 IN THE HOUSE OF REPRESENTATIVES May 7, 2026 Mr. Subramanyam (for himself and Mr. McCormick ) introduced the following bill; which was referred to the Committee on Armed Services A BILL
To amend title 10, United States Code, to require the Secretary of Defense to implement resilient capabilities to recover critical Department of Defense data in the event such data is lost, degraded, or destroyed, and for other purposes.
1.
Short title
This Act may be cited as the National Defense Data Resilience Act .
2.
Data recovery requirements and strategy
(a)
Data recovery requirements
Chapter 19 of title 10, United States Code, is amended by inserting after section 391b the following new section:
391c.
Data recovery requirements
(a)
Mandatory recovery time objectives
(1)
The Secretary of Defense shall, with respect to each element of the Department of Defense, carry out the following:
(A)
Designate data as one of the following types, as applicable:
(i)
Critical data.
(ii)
Important data.
(iii)
Necessary data.
(B)
Not later than 180 days after the date of the enactment of this section, establish mandatory recovery time objectives for data so designated as critical data.
(C)
Not later than 270 days after the date of the enactment of this section, establish mandatory recovery time objectives for data so designated as important data or necessary data.
(2)
Each recovery time objective established under paragraph (1) shall satisfy the following requirements:
(A)
Be based upon the type of data to which such objective applies, including with respect to threat exposure.
(B)
Be updated in response to intelligence on evolving threats from state and non-state actors, including the People’s Republic of China.
(3)
Not later than one year after the date of the enactment of this section and annually thereafter, the Secretary of Defense shall, for each element of the Department of Defense, submit to the congressional defense committees an auditable recovery certification report that includes information relating to the following:
(A)
Each recovery time objective that is established under paragraph (1) and applies to such element.
(B)
Whether such objective satisfies the requirements listed in paragraph (2).
(b)
Data recovery capability requirements
(1)
Not later than 180 days after the date of the enactment of this section, the Secretary of Defense shall, for data designated as critical data pursuant to subparagraph (A) of subsection (a)(1), field data recovery capabilities that satisfy the following requirements:
(A)
Prioritize providing critical services in support of national defense.
(B)
Include the following:
(i)
Immutable backups that satisfy the following requirements:
(I)
Preserve logically separated copies of data.
(II)
Are selectively segmented or isolated from external networks by means of software, firewalls, or other controls.
(ii)
Continuous monitoring of backup environments to detect tampering, insider threats, and malicious corruption.
(iii)
Annual recovery exercises that simulate sophisticated nation-state cyberattacks designed to cripple data systems.
(iv)
Audits in which external or internal independent groups mimic tactics, techniques, and procedures of cyberattacks to assess and validate the ability of each element of the Department of Defense to carry out the objectives established under such subsection with respect to realistic threat conditions.
(2)
Not later than 270 days after the date of the enactment of this section, the Secretary of Defense shall, for data designated as important data or necessary data pursuant to subsection (a)(1)(A), field data recovery capabilities described in paragraph (1).
(c)
Approved technology standards
In fielding a data recovery capability under subsection (b), the Secretary of Defense may not adopt technology unless the following requirements are satisfied:
(1)
Such technology is listed in an inventory of the Department of Defense for certified cybersecurity and data protection technology.
(2)
If such technology is technology for recovering or repairing damaged or lost data, such technology provides for the following:
(A)
Immutable storage.
(B)
Robust recovery capabilities.
(C)
Full audit trails.
(D)
Continuous monitoring for data integrity and anomalous activity.
(d)
Definitions
In this section:
(1)
The term critical data means data, so vital to the United States, that the incapacity or destruction of such data would have a debilitating impact on security, national economic security, national public health or safety, or any combination thereof.
(2)
The term data recovery capability means a technology, process, or governance framework to ensure rapid, secure, and verifiable recovery after a destructive cyberattack.
(3)
The term important data means data that is important to the United States and the incapacity or destruction of such data would have a significant impact on security, national economic security, national public health or safety, or any combination thereof.
(4)
The term necessary data means data, the incapacity or destruction of which would have a measurable impact on security, national economic security, national public health or safety, or any combination thereof.
(5)
The term recovery time objective means the maximum allowable time the Secretary of Defense determines necessary to restore critical functions and data following a cyberattack.
.
(b)
Clerical amendment
The table of sections for chapter 19 of title 10, United States Code, is amended by inserting after the item relating to section 391b the following new item:
391c. Data recovery requirements.
.
(c)
Data recovery strategy
(1)
Not later than 90 days after the date of the enactment of this Act, the Secretary of Defense shall submit to the congressional defense committees a data recovery strategy for the Department of Defense that includes information relating to the following:
(A)
Recovery time objectives for such strategy.
(B)
The technology necessary for such objectives.
(C)
Oversight processes with respect to such strategy.
(D)
The funds necessary to carry out such strategy.
(2)
The strategy under paragraph (1) shall be submitted in unclassified form, but may contain a classified annex.
(3)
In this subsection, the term recovery time objective means the maximum allowable time the Secretary of Defense determines necessary to restore critical functions and data following a cyberattack.

Tracker

The tracker indicates the progress of this legislation as it moves through the legislative process.

  1. Introduced2026-05-07
  2. Passed House
  3. Passed Senate
  4. Conference
  5. To President
  6. Became Law

To amend title 10, United States Code, to require the Secretary of Defense to implement resilient capabilities to recover critical Department of Defense data in the event such data is lost, degraded, or destroyed, and for other purposes.

Sponsors

Rep. Suhas Subramanyam (D) sponsors H.R. 8710, and 1 member has co-sponsored it from the day it was introduced.

Committees

H.R. 8710 went before 1 committee: Armed Services.

Armed Services
Armed Services
Referred To · May 7, 2026 · 581 Bills

Actions

H.R. 8710 has taken 2 actions since May 7, 2026.

ChamberAction
May 7, 2026
House
Introduced in House
May 7, 2026
House
Referred to the House Committee on Armed Services.Armed Services Committee

Votes

H.R. 8710 has not gone to a roll call.

Titles

H.R. 8710 goes by 3 titles, 1 of them short titles.

  • National Defense Data Resilience Act — Display Title
  • To amend title 10, United States Code, to require the Secretary of Defense to implement resilient capabilities to recover critical Department of Defense data in the event such data is lost, degraded, or destroyed, and for other purposes. — Official Title as Introduced
  • National Defense Data Resilience Act — Short Title(s) as Introduced

Lobbying

1 client hired 1 firm and 6 registered lobbyists who named H.R. 8710 in 2 quarterly filings, 2026. Reported under the Lobbying Disclosure Act; a filing’s income covers everything its registrant worked that quarter, so the amounts below are the filings’, not this bill’s.

Filed under Energy/Nuclear, Environment/Superfund, Pharmacy, Science/Technology, Taxation/Internal Revenue Code, Transportation, Trade (domestic/foreign).

Clients

Who paid to be heard, by how many filings named the bill.

ClientBusinessStateFirmsFilingsReported
SK AMERICAS, INC.Semiconductors, Energy, Life SciencesNew York12

Firms

Registrants who filed on the bill, by filings.

RegistrantClientsFilingsReported
SK AMERICAS, INC.12

Lobbyists

Named on the filings that cite the bill.

Filings

The documents themselves, on the Senate’s Lobbying Disclosure site, largest reported first.

ClientRegistrantPeriodReportedDocument
SK AMERICAS, INC.SK AMERICAS, INC.2026 first_quarter$1.6M1st Quarter - Report
SK AMERICAS, INC.SK AMERICAS, INC.2026 second_quarter$1.6M2nd Quarter - Report

Classification

The Congressional Research Service files H.R. 8710 under Armed Forces and National Security, one of its 31 policy areas.

CRS Subjects

CRS assigns every bill one policy area from its 31; H.R. 8710’s is Armed Forces and National Security.

hr8710/policy-areas.txt
Armed Forces and National SecurityAgriculture and FoodAnimalsArts, Culture, ReligionCivil Rights and Liberties, Minority IssuesCommerceCongressCrime and Law EnforcementEconomics and Public FinanceEducationEmergency ManagementEnergyEnvironmental ProtectionFamiliesFinance and Financial SectorForeign Trade and International FinanceGovernment Operations and PoliticsHealthHousing and Community DevelopmentImmigrationInternational AffairsLabor and EmploymentLawNative AmericansPublic Lands and Natural ResourcesScience, Technology, CommunicationsSocial WelfareSports and RecreationTaxationTransportation and Public WorksWater Resources Development

Constitutional authority

The clause the sponsor cites as Congress’s power to enact H.R. 8710, as entered in the Congressional Record.

[Congressional Record Volume 172, Number 78 (Thursday, May 7, 2026)][House]From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]By Mr. SUBRAMANYAM:H.R. 8710.Congress has the power to enact this legislation pursuantto the following:Article 1, Section 8[Page H3343]

Source: congress.gov · legiscan.com