Wednesday, September 16, 2026Independent tracking of the National Defense Authorization Act

The hub for the National Defense Authorization Act — status, history, and analysis

Title XV: Cyberspace-related Matters

Sec. 1504Inclusion of critical infrastructure and operational technology security in combatant command planning and readiness exercises

TL;DR

The Secretary of Defense shall direct the commanders of the combatant commands, consistent with the authorities provided under sections 164 and 167b of title 10, United States Code, to incorporate critical infrastructure security and operational technology security…

Statutory text

(a) Requirement. The Secretary of Defense shall direct the commanders of the combatant commands, consistent with the authorities provided under sections 164 and 167b of title 10, United States Code, to incorporate critical infrastructure security and operational technology security considerations into—(1)planning activities conducted to execute national defense strategies; and(2)joint and combined planning, training, and readiness exercises.

(b) Scope of activities. The activities described in subsection (a) shall, at a minimum, include—(1)assessment of vulnerabilities and resilience of critical infrastructure and operational technology systems that support military operations, defense support to civil authorities, and homeland defense missions;(2)coordination with relevant Federal departments and agencies, State, local, Tribal, and territorial authorities, and private sector owners and operators, as appropriate; and(3)integration of cyber, operational technology, and physical effects relevant to disruption, degradation, or compromise of such systems.