The National Defense Data Resilience Act requires the Department of Defense to establish and implement robust capabilities to recover critical data that may be lost, damaged, or destroyed in cyberattacks. The Secretary of Defense must categorize all department data as critical, important, or necessary, and establish recovery time objectives for each category within 180 to 270 days of the law's enactment, with these objectives updated annually based on evolving threats from state and non-state actors including China. The DOD must deploy specific recovery technologies including immutable backups, continuous monitoring systems, and annual recovery exercises simulating nation-state cyberattacks within the same timeframe, and can only use technologies certified in the department's approved cybersecurity inventory. The Secretary must submit a comprehensive data recovery strategy to Congress within 90 days detailing recovery objectives, required technology, oversight processes, and necessary funding, and must provide annual auditable certification reports to the congressional defense committees confirming compliance. The legislation does not specify funding amounts but requires the DOD to identify all necessary resources in its strategy submission.
Take Action
Your position
Add a comment
to comment on this bill.
Annotate the text
Highlight any passage on the Summary or Full Text tab to attach a note. Annotations appear on the Annotations tab.