§2. Enhanced cybersecurity for EBT cards
This section establishes cybersecurity requirements for electronic benefit transfer (EBT) cards and digital services under the Supplemental Nutrition Assistance Program (SNAP). (As background, SNAP provides nutrition benefits via EBT cards redeemable for eligible foods, which have been vulnerable to skimming and cloning fraud.)
Directs the Secretary of Agriculture to promulgate regulations within two years of enactment—reviewed and updated every five years thereafter—to ensure EBT cybersecurity measures align with private-sector and federal standards for payment cards and mobile technologies.
Requires states to (1) operate required user interfaces from a Secretary-maintained list (e.g., web portal, mobile application, application programming interface for no-fee third-party access, and text messaging, voice telephone, and nondigital options for 10 years), which must be available in required languages, accessible 99% of the time, and include mobile-friendly web portals; (2) offer households opt-in access via these interfaces to timely transaction notices, 12 months of searchable transaction history (including amounts, merchants, locations), fraud reporting, and notifications of potential reimbursement funds for repeat fraud victims; (3) enable households to check certification and recertification status via these interfaces; and (4) issue chip-enabled EBT cards (i.e., using secure, cloning-resistant technology) within two years after the regulations are finalized.