This bill enacts provisions regarding foreign adversary threats to critical infrastructure.
This bill:
AI-generated summary, not yet reviewed by Better Utah staff. Please consult the bill text.
New rules for protecting Utah's critical systems — power grids, water systems, emergency communications, data centers, and government networks — from foreign adversary threats would take effect under this bill. It would direct the Utah Cyber Center to develop and annually update security guidance for government agencies, offer voluntary security assessments when foreign adversary technology is involved in critical infrastructure, and publish a list of prohibited technologies drawn from existing federal ban lists (such as the Pentagon's 1260H list and the FCC's Covered List); starting July 1, 2026, government entities and critical infrastructure providers would be barred from buying, renewing contracts for, or newly deploying anything on that list, unless no reasonable alternative exists. The bill would also prohibit any company or government entity with significant access to critical infrastructure from entering into agreements that would let a foreign adversary's government, political party, business, or citizen remotely access or control those systems, again with an exception if no reasonable alternative is available. Additionally, agencies reporting data breaches to the Cyber Center would be required to disclose whether foreign adversary technology was involved.
Current version: HB0165S04 (Substitute)
Introduction
Jan 20
House Rules
House Committee
Feb 2
House Floor Vote
Feb 10
Senate Rules
Feb 17
Senate Committee
Feb 18
Senate 2nd Reading
Feb 25
Senate 3rd Reading
Feb 26
House Concurrence
Feb 26
Governor Signed
Mar 17
IntroductionJan 20
House Rules
House CommitteeFeb 2
House Floor VoteFeb 10
Senate RulesFeb 17
Senate CommitteeFeb 18
Senate 2nd ReadingFeb 25
Senate 3rd ReadingFeb 26
House ConcurrenceFeb 26
Governor SignedMar 17
This bill enacts provisions regarding foreign adversary threats to critical infrastructure.
This bill:
AI-generated summary, not yet reviewed by Better Utah staff. Please consult the bill text.
New rules for protecting Utah's critical systems — power grids, water systems, emergency communications, data centers, and government networks — from foreign adversary threats would take effect under this bill. It would direct the Utah Cyber Center to develop and annually update security guidance for government agencies, offer voluntary security assessments when foreign adversary technology is involved in critical infrastructure, and publish a list of prohibited technologies drawn from existing federal ban lists (such as the Pentagon's 1260H list and the FCC's Covered List); starting July 1, 2026, government entities and critical infrastructure providers would be barred from buying, renewing contracts for, or newly deploying anything on that list, unless no reasonable alternative exists. The bill would also prohibit any company or government entity with significant access to critical infrastructure from entering into agreements that would let a foreign adversary's government, political party, business, or citizen remotely access or control those systems, again with an exception if no reasonable alternative is available. Additionally, agencies reporting data breaches to the Cyber Center would be required to disclose whether foreign adversary technology was involved.
Motion: Favorable Recommendation
Motion: Favorable Recommendation
Governor Signed
Lieutenant Governor's office for filing
House/ to Governor
Executive Branch - Governor
House/ received enrolled bill from Printing
Clerk of the House
House/ enrolled bill to Printing
Clerk of the House
Enrolled Bill Returned to House or Senate
Clerk of the House
Last updated Aug 29, 2026, 5:26 PM