H.R. 5062: Pipeline Security Act
Sponsor
Julie Johnson
Democrat · TX-32
Pipeline security needs one agency clearly in charge
Why it matters
The gas in your car and the fuel that heats your home move through pipelines that can be hacked or attacked. H.R. 5062 writes into law that TSA owns pipeline security, and sets a 180-day clock for a plan to staff it with cyber experts.
H.R. 5062, the Pipeline Security Act, adds a new section to the 9/11 Commission Act of 2007 stating that TSA is responsible for protecting pipelines and pipeline facilities from cyberattacks, terrorism, and other security threats. Congress would put in writing which agency answers for pipeline security, rather than leaving it to agency practice. TSA would consult with the Cybersecurity and Infrastructure Security Agency (CISA) as appropriate, but TSA stays in the lead.
The bill then spells out what that job includes. TSA would write and update security guidelines built on the NIST cybersecurity framework, the voluntary standard many companies already use. It could issue security directives or regulations when it decides they are needed, share threat intelligence with governments and industry, rank which pipelines face the greatest risk, and inspect pipeline operations, including the facilities companies themselves flag as critical.
The rest of the bill is about follow-through. Within 180 days, TSA must produce a personnel strategy that assesses how much cybersecurity expertise it needs, lays out a plan to hire or build it, and estimates the resources required. Within one year, it must hold at least one industry day with pipeline stakeholders. It reports to three congressional committees at least every two years, and the Government Accountability Office reviews how the law is working after two years.
The bill carries no new funding and no new penalties. It relies on TSA's existing budget and its existing power to issue directives, so how much changes on the ground depends on whether the personnel strategy is actually funded.
Bill Progress
Latest Action · Nov 12, 2025
Placed on House floor schedule, Calendar No. 327.
H.R. 5062 Bill Summary
What H.R. 5062 actually does.
TSA is written into law as the pipeline security lead
The TSA Administrator must maintain responsibility for securing pipelines and pipeline facilities against cyberattacks, terrorism, and other security threats, consulting with the CISA Director as appropriate.
Security guidelines follow the NIST cyber framework
TSA must develop and update pipeline security guidelines with input from federal, state, local, Tribal, and territorial governments and industry, consistent with the National Institute of Standards and Technology's cybersecurity framework and future updates to it.
TSA can issue binding directives when it sees a need
TSA may issue additional security directives or regulations it determines necessary, and must share guidelines, directives, and threat intelligence with government partners and industry as appropriate.
Pipelines get risk-ranked and inspected
TSA must identify and rank the relative security risks across pipelines, assess how companies carry out security policies, plans, and training, and inspect pipeline operations, including facilities owners designate as critical.
A cyber staffing plan due in 180 days
TSA must develop a personnel strategy that assesses the cybersecurity expertise it needs, includes a plan to expand that expertise inside the agency, and estimates necessary resources. The strategy goes to the House Homeland Security Committee and two Senate committees.
Industry day, recurring reports, and a GAO check
TSA must hold at least one industry day with pipeline stakeholders within one year, report to Congress at least every two years, and the Government Accountability Office must review implementation within two years.
Who benefits from H.R. 5062?
Drivers and households who rely on pipeline fuel
Pipelines move much of the gasoline, diesel, jet fuel, and natural gas Americans use. A shutdown like Colonial's in 2021 shows up quickly at the pump and in home heating.
Pipeline owners and operators
Companies get one clearly designated federal agency to answer to, guidelines tied to a cyber framework many already use, and a guaranteed industry day to raise concerns within a year.
TSA's pipeline security team
The agency gets a clear statutory mandate and a required staffing assessment that can support future budget requests for cybersecurity talent.
Congressional overseers
Three committees get a personnel strategy within 180 days, reports at least every two years, and an independent GAO review after two years.
Who is affected by H.R. 5062?
Pipeline owners and operators
They remain subject to TSA inspections of their security policies, plans, practices, and training, and to any new directives or regulations TSA decides are necessary.
Transportation Security Administration
TSA takes on specific statutory duties and deadlines, including a staffing strategy, an industry day, and recurring reports, without new money attached.
Cybersecurity and Infrastructure Security Agency
CISA is not the lead agency. Its Director is consulted as appropriate on TSA's pipeline work and the personnel strategy.
Government Accountability Office
GAO must review how the law is being implemented within two years of enactment.
HR5062 Legislative Journey
House: Committee Action
Nov 12, 2025
Reported by the Committee on Homeland Security. H. Rept. 119-376.
House: Vote: 22-0
Sep 3, 2025
Ordered to be Reported by the Yeas and Nays: 22 - 0.
House: Committee Action
Aug 29, 2025
Referred to the Subcommittee on Transportation and Maritime Security.
About the Sponsor
Julie Johnson
Democrat, Texas' 32nd congressional district · 1 years in Congress
Committees: House Administration, Joint Committee of Congress on the Library, Homeland Security
View full profile →
Cosponsors (2)
This bill has 2 cosponsors: 1 Democrat, 1 Republican, reflecting bipartisan support. Cosponsors represent 2 states: California, Florida.
Committee Sponsors
Homeland Security Committee
1 of 33 committee members cosponsored
15 Democrats across this committee haven't cosponsored yet. Mobilize their constituents
What laws does H.R. 5062 change?
1 changes
Sections Amended
Section 1(b) of Implementing Recommendations of the 9/11 Commission Act of 2007
inserting after the item relating to section 1558 the following new item: ``Sec
H.R. 5062 Quick Facts
- Committee
- Homeland Security
- Chamber
- House
- Policy
- Transportation and Public Works
- Introduced
- Aug 29, 2025
Placed on House floor schedule, Calendar No. 327.
Nov 12, 2025
Official Sources
Official congressional page for H.R. 5062, with bill text, actions, and the Homeland Security Committee report (H. Rept. 119-376).
Congressional Budget Office estimate of the bill's cost, covering the new reporting requirements and GAO review.
TSA's current pipeline cybersecurity directives, the binding authority the bill confirms TSA can use.
The existing TSA guidelines the bill directs the agency to develop and keep updated with government and industry input.
The NIST framework that TSA's pipeline security guidelines would have to stay consistent with under the bill.
GAO's review of TSA's pipeline and rail cyber directives, including the post-Colonial Pipeline response.
TSA's cyber risk resources for smaller pipeline and surface transportation operators.
H.R. 5062 Common Questions
Who is responsible for pipeline security in the United States?
The Transportation Security Administration, the same agency that runs airport screening. H.R. 5062 would write that role into law, with TSA consulting the Cybersecurity and Infrastructure Security Agency (CISA) as appropriate.
Would H.R. 5062 have prevented the Colonial Pipeline hack?
No bill can promise that. H.R. 5062 focuses on who is in charge and whether they have the staff: TSA must assess its cybersecurity expertise needs and plan to expand them within 180 days, and it can inspect pipelines and rank their risks.
Can TSA force pipeline companies to follow security rules?
Yes. The bill lets TSA issue security directives or regulations whenever it determines they are necessary, and to inspect how companies carry them out, including facilities owners flag as critical.
What cybersecurity standard would pipeline guidelines follow?
The NIST cybersecurity framework, a widely used voluntary standard from the National Institute of Standards and Technology. TSA's guidelines would have to stay consistent with it and its future updates.
Does the Pipeline Security Act cost taxpayers anything?
It authorizes no new spending and adds no fines. TSA would absorb the duties in its current budget, though its 180-day staffing strategy must estimate the resources it actually needs.
How would Congress know if TSA is doing the job?
TSA must report to the House Homeland Security Committee and two Senate committees at least every two years, and the Government Accountability Office must review the law's implementation within two years.
Do pipeline companies get a say in the rules?
Yes. TSA must develop guidelines with input from governments and industry, and hold at least one industry day with pipeline stakeholders within a year of enactment.
Has H.R. 5062 passed the House?
Not yet. The Homeland Security Committee advanced it unanimously, according to the sponsor's office, and it was placed on the House calendar in November 2025. It still needs a House floor vote and Senate action.
Based on H.R. 5062 bill text
Full Bill Text
Get notified when H.R. 5062 moves
Committee votes, floor action, cosponsor changes — straight to your inbox.
Bill alerts + Legisletter's monthly briefing. Unsubscribe anytime.
Transportation and Public Works Bills
9 related bills we're tracking
Stronger Communities through Better Transit Act
Referred to the Subcommittee on Highways and Transit.
May 16, 2025
SHIPS for America Act of 2025
Referred to the Subcommittee on Coast Guard and Maritime Transportation.
May 1, 2025
ALERT Act
Received in the Senate and Read twice and referred to the Committee on Commerce, Science, and Transportation.
Apr 15, 2026
PART Act
Forwarded by Subcommittee to Full Committee by Voice Vote.
Feb 10, 2026
ROTOR Act
On motion to suspend the rules and pass the bill Failed by the Yeas and Nays: (2/3 required): 264 - 133 (Roll no. 72).
Feb 24, 2026
SELF DRIVE Act of 2026
Forwarded by Subcommittee to Full Committee by the Yeas and Nays: 12 - 11.
Feb 10, 2026
BASICS Act
Referred to the House Committee on Transportation and Infrastructure.
Feb 9, 2026
She DRIVES Act
Placed on Senate Legislative Calendar under General Orders. Calendar No. 141.
Jul 31, 2025
To amend title 23, United States Code, and the Infrastructure Investment and Jobs Act with respect to vehicle roadside crashes, work zone safety, and for other purposes.
Referred to the Subcommittee on Highways and Transit.
Apr 24, 2025
Trending Right Now
Bills gaining momentum across Congress
ASAP Act
Ordered to be Reported in the Nature of a Substitute by the Yeas and Nays: 40 - 0.
Sep 16, 2026
Federal Firearms Licensee Protection Act of 2025
Referred to the House Committee on the Judiciary.
Mar 3, 2025
Therapeutic Fraud Prevention Act of 2025
Referred to the House Committee on Energy and Commerce.
May 7, 2025
Tracking Transportation and Public Works in Congress? Monitor bills, track cosponsor momentum, and launch advocacy campaigns — all from one advocacy platform.