S. 5098: Enhancing K–12 Cybersecurity Act
This bill would direct the Cybersecurity and Infrastructure Security Agency (CISA) to create new cybersecurity support programs focused on K–12 schools.
What it would create
The bill would establish two main efforts:
- A School Cybersecurity Information Exchange, which would be a public website for sharing cybersecurity guidance, best practices, training materials, and lessons learned for schools.
- A K–12 Cybersecurity Technology Improvement Program, which would help schools deploy cybersecurity tools, services, and training aimed at reducing risks like ransomware and other attacks.
Who it would cover
The bill applies to:
- Elementary schools
- Secondary schools
- Local educational agencies
- State educational agencies
- Educational service agencies
What CISA would have to do
Under the bill, CISA would be required to work with other federal, state, local, and non-governmental partners to:
- Share cybersecurity information tailored to schools’ needs and resources
- Provide guidance on data protection, remote learning security, and student online privacy
- Maintain a database of cybersecurity tools and services that are funded by the federal government, and tools and services recommended for state or local purchase
- Provide a searchable database of funding opportunities that schools can use to improve cybersecurity
Cyber incident registry
The bill would also create a voluntary registry of cyber incidents affecting school technology systems. Schools could submit information about incidents, such as:
- When the incident was detected or publicly disclosed
- What type of incident it was, such as a breach, malware, or denial-of-service attack
- The effects or size of the incident
- Other information CISA considers relevant
CISA could use this information to track trends, improve coordination, support prevention and response efforts, and identify or investigate attacks.
Privacy protections and reporting
The bill says any public reporting based on the registry must be de-identified and presented in aggregate, and it must protect privacy as required by federal and state law. CISA would also have to publish annual reports on school cyber incidents and on the impact of the improvement program.
Funding
The bill would authorize $10 million per year for fiscal years 2027 and 2028 to carry out these activities.
Relevant Companies
- CRWD — CrowdStrike could see demand for its endpoint security and threat detection tools if schools and school systems buy more cybersecurity services.
- PANW — Palo Alto Networks could be affected if schools adopt more network security, firewall, and cloud security products.
- ZS — Zscaler could benefit if schools increase spending on secure internet access and remote access tools.
- OKTA — Okta could be affected by greater use of identity and access management tools in school systems.
- FTNT — Fortinet could be impacted through increased demand for network security products used by schools and districts.
- CHKP — Check Point Software could be affected by expanded school cybersecurity procurement.
This is an AI-generated summary of the bill text. There may be mistakes.
Sponsors
2 bill sponsors
Actions
2 actions
| Date | Action |
|---|---|
| Jul. 23, 2026 | Introduced in Senate |
| Jul. 23, 2026 | Read twice and referred to the Committee on Homeland Security and Governmental Affairs. |
Corporate Lobbying
0 companies lobbying
None found.
* Note that there can be significant delays in lobbying disclosures, and our data may be incomplete.