42 U.S.C. § 18725
Verified against govinfo.gov as of June 20, 2026View official text on govinfo.gov ↗
- (a)The Secretary may require, as the Secretary determines appropriate, a recipient of any award or other funding under this division—
- (1)to submit to the Secretary, prior to the issuance of the award or other funding, a cybersecurity plan that demonstrates the cybersecurity maturity of the recipient in the context of the project for which that award or other funding was provided; and
- (2)establish a plan for maintaining and improving cybersecurity throughout the life of the proposed solution of the project.
- (b)A cybersecurity plan described in subsection (a) shall, at a minimum, describe how the recipient described in that subsection—
- (1)plans to maintain cybersecurity between networks, systems, devices, applications, or components—
- (2)will perform ongoing evaluation of cybersecurity risks to address issues as the issues arise throughout the life of the proposed solution;
- (3)will report known or suspected network or system compromises of the project to the Secretary; and
- (4)will leverage applicable cybersecurity programs of the Department, including cyber vulnerability testing and security engineering evaluations.
- (c)Each recipient described in subsection (a) should—
- (d)The Office of Cybersecurity, Energy Security, and Emergency Response of the Department shall review each cybersecurity plan submitted under subsection (a) to ensure integration with Department research, development, and demonstration programs.
- (e)Information provided to, or collected by, the Federal Government pursuant to this section the disclosure of which the Secretary reasonably foresees could be detrimental to the physical security or cybersecurity of any electric utility or the bulk-power system—
- (1)shall be exempt from disclosure under section 552(b)(3) of title 5; and
- (2)shall not be made available by any Federal agency, State, political subdivision of a State, or Tribal authority pursuant to any Federal, State, political subdivision of a State, or Tribal law, respectively, requiring public disclosure of information or records.