Skip to main content
HR 6066 114th Congress House

Cybersecurity Responsibility and Accountability Act of 2016

Official title: To enforce Federal cybersecurity responsibility and accountability.

Introduced: September 19, 2016 See on congress.gov
Science, Technology, Communications Computer security and identity theftComputers and information technologyCongressional oversightEmployment and training programs
More subjectsShow fewer subjects
Government employee pay, benefits, personnel managementGovernment information and archivesGovernment studies and investigations
This bill died when the 114th Congress ended
It never became law before the 114th Congress (2015–2016) adjourned, and bills don't carry over to the next Congress. It would have to be reintroduced. You can still save it for reference, but it won't receive updates.
 Everywhere this bill has been 4 steps
Introduced
In committee
Reported out
Passed House
Passed Senate
To President
Became law
Sep 21, 2016
Ordered to be Reported by Voice Vote.
Sep 21, 2016
Committee Consideration and Mark-up Session Held.
Sep 19, 2016
Referred to the Committee on Oversight and Government Reform, and in addition to the Committee on Science, Space, and Technology, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.
Sep 19, 2016
Introduced in House
 Ask about this bill AI · grounded in the bill text

Have a question about what this bill does? Ask in plain English; the answer is drawn from the bill's actual text and official record, and it'll tell you when something isn't in the text rather than guess.

AI answers can be imperfect; always confirm against the full bill text.

 Latest action September 21, 2016

Ordered to be Reported by Voice Vote.

 Plain-English summary Congressional Research Service

Cybersecurity Responsibility and Accountability Act of 2016

This bill requires the National Institute of Standards and Technology (NIST) to incorporate additional cybersecurity requirements in its computer standards for agency information systems and provide the Office of Management and Budget (OMB) with a process for agencies to implement those standards.

NIST must also: (1) support development of information security training and certification for agency heads, (2) address agency-identified information security challenges and knowledge gaps, (3) assess information security statutory requirements, and (4) develop security standards for national security systems.

The OMB must require the heads of agencies (currently, agencies generally) to: (1) report on the adequacy of their information security procedures, (2) provide for independent evaluations of information security practices, and (3) notify Congress and affected individuals of data breaches. Intelligence community agencies affected by data breaches must notify NIST.

Chief information officers of agencies must collaborate with their agency head to designate chief information security officers (positions with job responsibilities to be developed by the OMB and NIST) to replace their current senior agency information security officers.

Agencies must develop mandatory annual information security training and certification to ensure that agency heads understand federal cybersecurity policy regarding: (1) agency systems, (2) cyber-attacks and data breaches, and (3) not using private email servers or messaging systems for official communications.

Agency heads must certify that their agencies meet information security standards and provide reasons for not meeting any standards.

Agency heads must also develop annual plans to implement information security recommendations of the Government Accountability Office (GAO) and inspectors general. If an agency head fails to implement such a recommendation, the reasons for the failure must be provided to the OMB for approval.

For each OMB-defined "major cybersecurity incident" (e.g., an incident involving classified information) that an agency experiences, the agency head must transmit an inspector general-performed independent evaluation to the OMB, the Department of Homeland Security, NIST, Congress, and the GAO. If the evaluation determines that the incident occurred because the agency head failed to comply sufficiently with NIST certification standards or recommendations of the GAO or agency inspectors general, then the OMB must hold the agency head accountable through an enforcement action, which may include actions under the budgetary or appropriations process, a recommendation for the President to remove or demote the agency head, or actions to ensure that the agency head does not receive cash or pay awards or bonuses for one year.

 Bill text 1 version

Source documents hosted by congress.gov.

 Committees of jurisdiction 2
Cite this page click to expand
APA
U.S. Congress. (2026). H.R. 6066: Cybersecurity Responsibility and Accountability Act of 2016. 114th Congress. Open America. https://openamerica.io/bill/114-HR-6066/
MLA
"H.R. 6066: Cybersecurity Responsibility and Accountability Act of 2016." 114th Congress, 2026, Open America, https://openamerica.io/bill/114-HR-6066/.
Bluebook (legal)
H.R. 6066, 114th Cong. (2026), https://openamerica.io/bill/114-HR-6066/.
Markdown link
[H.R. 6066: Cybersecurity Responsibility and Accountability Act of 2016](https://openamerica.io/bill/114-HR-6066/)
Report a problem