Skip to main content
S 2666 117th Congress Senate

Sanction and Stop Ransomware Act of 2021

Official title: A bill to address threats relating to ransomware, and for other purposes.

Introduced: August 5, 2021 See on congress.gov
This bill died when the 117th Congress ended
It never became law before the 117th Congress (2021–2022) adjourned, and bills don't carry over to the next Congress. It would have to be reintroduced. You can still save it for reference, but it won't receive updates.
 Everywhere this bill has been 2 steps
Introduced
In committee
Reported out
Passed House
Passed Senate
To President
Became law
Aug 5, 2021
Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
Aug 5, 2021
Introduced in Senate
 Ask about this bill AI · grounded in the bill text

Have a question about what this bill does? Ask in plain English; the answer is drawn from the bill's actual text and official record, and it'll tell you when something isn't in the text rather than guess.

AI answers can be imperfect; always confirm against the full bill text.

 Latest action August 5, 2021

Read twice and referred to the Committee on Homeland Security and Governmental Affairs.

 Plain-English summary Congressional Research Service

Sanction and Stop Ransomware Act of 2021

This bill addresses ransomware threats to national security.

Specifically, the bill

  • requires the promulgation of mandatory cybersecurity standards for critical infrastructure entities;
  • requires the instituting of regulatory requirements for cryptocurrency exchanges operating within the United States to reduce the anonymity of users and accounts suspected of ransomware activity;
  • deems ransomware threats to critical infrastructure a national intelligence priority component to the National Intelligence Priorities Framework; and
  • authorizes monitoring of the internet, including the dark web, for evidence of a compromise to critical infrastructure.

The Department of State shall annually

  • designate as a state sponsor of ransomware any country the government which has provided support for ransomware demand schemes (including by providing safe haven for individuals engaged in such schemes), and
  • submit to Congress a report listing the designated countries.

The National Intelligence Agency shall submit a report to specified congressional committees on the implications of the ransomware threat to national security.

The Cybersecurity and Infrastructure Security Agency (CISA) shall establish ransomware operation reporting capabilities to facilitate the submission of timely, secure, and confidential ransomware notifications by federal agencies and covered entities to CISA. In addition, CISA shall establish a public awareness campaign related to the cybersecurity services of the government.

The bill also establishes the Information System and Network Security Fund. Any amounts in the fund may be distributed to eligible entities for a specific network security purpose, including to enable network recovery from an event affecting network cybersecurity.

 Bill text 1 version

Source documents hosted by congress.gov.

 Committees of jurisdiction 1
Cite this page click to expand
APA
U.S. Congress. (2026). S. 2666: Sanction and Stop Ransomware Act of 2021. 117th Congress. Open America. https://openamerica.io/bill/117-S-2666/
MLA
"S. 2666: Sanction and Stop Ransomware Act of 2021." 117th Congress, 2026, Open America, https://openamerica.io/bill/117-S-2666/.
Bluebook (legal)
S. 2666, 117th Cong. (2026), https://openamerica.io/bill/117-S-2666/.
Markdown link
[S. 2666: Sanction and Stop Ransomware Act of 2021](https://openamerica.io/bill/117-S-2666/)
Report a problem