Risk-Informed Spending for Cybersecurity Act
Have a question about what this bill does? Ask in plain English; the answer is drawn from the bill's actual text and official record, and it'll tell you when something isn't in the text rather than guess.
Risk-Informed Spending for Cybersecurity Act
This bill requires the Office of Management and Budget, in coordination with the Cybersecurity and Infrastructure Security Agency, to develop a standard model for creating a risk-based budget for cybersecurity spending.
The risk-based budget must (1) be developed by identifying and prioritizing cybersecurity risks and vulnerabilities through analysis of threat intelligence, incident data, and tactics, techniques, procedures, and capabilities of cyber threats; and (2) allocate resources based on the risks identified and prioritized.
Within two years of the development of the model, federal agencies must begin using the model to develop annual cybersecurity and information technology budget requests.
Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
- Introduced in Senate Formatted Text PDF Formatted XML
Cite this page
U.S. Congress. (2026). S. 4785: Risk-Informed Spending for Cybersecurity Act. 116th Congress. Open America. https://openamerica.io/bill/116-S-4785/
"S. 4785: Risk-Informed Spending for Cybersecurity Act." 116th Congress, 2026, Open America, https://openamerica.io/bill/116-S-4785/.
S. 4785, 116th Cong. (2026), https://openamerica.io/bill/116-S-4785/.
[S. 4785: Risk-Informed Spending for Cybersecurity Act](https://openamerica.io/bill/116-S-4785/)