<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" bill-type="olc" dms-id="H6B60FFC8163C4F578E5DC7C3A68DAFD6" key="H" public-private="public"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>115 HR 5517 IH: Enhance Cybersecurity for Small Manufacturers Act of 2018</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2018-04-13</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress display="yes">115th CONGRESS</congress><session display="yes">2d Session</session><legis-num display="yes">H. R. 5517</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20180413">April 13, 2018</action-date><action-desc><sponsor name-id="P000613">Mr. Panetta</sponsor> (for himself and <cosponsor name-id="G000579">Mr. Gallagher</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HSY00">Committee on Science, Space, and Technology</committee-name>, and in addition to the <committee-name committee-id="HAS00">Committee on Armed Services</committee-name>, for a period to be subsequently determined by the Speaker, in each case for consideration of such
			 provisions as fall within the jurisdiction of the committee concerned</action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To improve assistance provided by the Hollings Manufacturing Extension Partnership to small
			 manufacturers in the defense industrial supply chain on matters relating
			 to cybersecurity, and for other purposes.</official-title></form>
	<legis-body id="H601E1A0D5DC94CC68A885E66933D70C8" style="OLC">
 <section id="HCC48B1E62FDC4B27BCBF2C231494195D" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Enhance Cybersecurity for Small Manufacturers Act of 2018</short-title></quote>.</text> </section><section id="H4FB9C0F0E7F247DEAF83603EC2F9E6BB"><enum>2.</enum><header>Findings</header><text display-inline="no-display-inline">Congress finds the following:</text>
 <paragraph id="HCE737CCF96EB4D6894F0A64B5D2ABA08"><enum>(1)</enum><text>According to the Bureau of Labor Statistics, there are more than 347,000 manufacturing establishments in the United States, of which 72 percent have fewer than 20 employees and 99 percent have fewer than 500 employees.</text>
 </paragraph><paragraph id="H8FB723CD4C224B269C4F4A5CBDE24510"><enum>(2)</enum><text>Independent studies from the National Defense Industry Association, the Defense Science Board, the Alliance for Manufacturing Foresight, and the McKinsey Global Institute have highlighted—</text>
 <subparagraph id="H1BFF3D7837694F53A1D1DE5A1C9B28BC"><enum>(A)</enum><text>the centrality of small manufacturers to United States manufacturing supply chains for domestic economic growth;</text>
 </subparagraph><subparagraph id="H84F28AAC8E4345C3850EE94FCC97503E"><enum>(B)</enum><text>the vulnerability of such manufacturers to the defense industrial base for national security; and</text> </subparagraph><subparagraph id="HD5E951E14F674BE180FDCA6B1EED3A6C"><enum>(C)</enum><text>the vulnerability of such manufacturers to cybersecurity threats and breaches.</text>
 </subparagraph></paragraph><paragraph id="HBF2D5902EDF0449B86FAB1A1EFCEB680"><enum>(3)</enum><text>As of December 31, 2017, Department of Defense suppliers must comply with new, tougher cybersecurity requirements to ensure adequate security to protect controlled unclassified information relevant to defense manufacturing supply chains. The requirements call for defense suppliers to implement and create a plan of action to respond to the guidance developed by the National Institute of Standards and Technology.</text>
 </paragraph><paragraph id="H5DAED8ED223447BF8A6B576C45D66DA6"><enum>(4)</enum><text>The Department of Commerce has found significant cybersecurity vulnerability of small manufacturers. A survey of 9,000 contract facilities documented that 6,650 small facilities lagged behind medium and large firms across a broad range of 20 cybersecurity indicators. For several indicators, fewer than half of small firms had cybersecurity measures in place.</text>
 </paragraph><paragraph id="H53F606877DDD4126B0E2F22F51B0853E"><enum>(5)</enum><text>Over the past 5 years the national network of centers operating as part of the Hollings Manufacturing Extension Partnership has worked closely with the Department of Defense to bolster the resilience of the defense industrial base supply chain. Since 2013, such centers have completed more than 2,500 projects with 1,650 companies that are suppliers to the Department of Defense.</text>
 </paragraph><paragraph id="H1FCB2A7530774951848C254A07C9A9FC"><enum>(6)</enum><text>In 2017, the Hollings Manufacturing Extension Partnership interacted with more than 1,000 small manufacturers on the cybersecurity requirements of the Department of Defense. This work by the Hollings Manufacturing Extension Partnership has revealed a significant lack of awareness of the Department of Defense cybersecurity requirements and a deficiency of financial and technical resources required to manage cybersecurity risks. If cybersecurity vulnerabilities remain unaddressed, defense supply chains face a higher likelihood of serious and exploitable vulnerabilities, as well as a substantial reduction in the number of suppliers compliant with Department of Defense requirements, and thereby ineligible to provide products and services to the Department of Defense.</text>
 </paragraph><paragraph id="H7EB5F76526E045AAB2C3A7A0922F9B99"><enum>(7)</enum><text>The Hollings Manufacturing Extension Partnership is well positioned to aid suppliers of the Department of Defense in complying with cybersecurity requirements of the Department to ensure adequate security to protect controlled unclassified information relevant to defense manufacturing supply chains.</text>
			</paragraph></section><section id="HA64955F5B72E45D5854C15DF69A9D25D"><enum>3.</enum><header>Assistance for small manufacturers in the defense industrial supply chain on matters relating to
			 cybersecurity</header>
 <subsection id="H49F267454A3A4AB6A77F1FF942F0A449"><enum>(a)</enum><header>Definitions</header><text>In this section:</text> <paragraph id="HB51004D6E57D43A4A5DF36B45161D34E"><enum>(1)</enum><header>Center</header><text>The term <quote>Center</quote> has the meaning given such term in section 25(a) of the National Institute of Standards and Technology Act (<external-xref legal-doc="usc" parsable-cite="usc/15/278k">15 U.S.C. 278k(a)</external-xref>).</text>
 </paragraph><paragraph id="H37639C1C38B844D8A2A2798496273E63"><enum>(2)</enum><header>Director</header><text display-inline="yes-display-inline">The term <quote>Director</quote> means the Director of the National Institute of Standards and Technology.</text> </paragraph><paragraph id="HB4A8B6A1450642BB94C61D3771749682"><enum>(3)</enum><header>Resources</header><text>The term <quote>resources</quote> means guidelines, tools, best practices, standards, methodologies, and other ways of providing information.</text>
 </paragraph><paragraph id="H3100ACCAEAC24EA4B6497CA2888D1893"><enum>(4)</enum><header>Small business concern</header><text>The term <quote>small business concern</quote> means a small business concern as that term is used in section 3 of the Small Business Act (<external-xref legal-doc="usc" parsable-cite="usc/15/632">15 U.S.C. 632</external-xref>).</text>
 </paragraph><paragraph id="H6264F98FA96348DD8FF88CA02EC214A6"><enum>(5)</enum><header>Small manufacturer</header><text>The term <quote>small manufacturer</quote> means a small business concern that is a manufacturer.</text> </paragraph><paragraph id="HA9960772D0374E8BAB8141B404E9514D"><enum>(6)</enum><header>State</header><text display-inline="yes-display-inline">The term <quote>State</quote> means each of the several States, Territories, and possessions of the United States, the District of Columbia, and the Commonwealth of Puerto Rico.</text>
				</paragraph></subsection><subsection id="HB903533175EB4D809DD213CB46ACD1D1"><enum>(b)</enum><header>Dissemination of cybersecurity resources</header>
 <paragraph id="H4996E027DFED43CF974F7B00D19B0C64"><enum>(1)</enum><header>In general</header><text>The Director of the National Institute of Standards and Technology, in partnership with the Secretary of Defense and acting through the Hollings Manufacturing Extension Partnership, shall take such actions as may be necessary to address a widespread lack of awareness of cybersecurity threats among small manufacturers in the defense industrial supply chain.</text>
 </paragraph><paragraph id="H446D87FE29D3407BA53D3128B4498A2C"><enum>(2)</enum><header>National reach</header><text>The Director shall ensure that efforts to increase awareness under paragraph (1) are carried out in each State, by disseminating clear and concise resources to help reduce cybersecurity risks faced by small manufacturers described in paragraph (1).</text>
 </paragraph><paragraph id="H6C5C276B29294626B4AFC9C5645B3B7E"><enum>(3)</enum><header>Sector focus</header><text>The Director shall carry out this subsection with a focus on such industry sectors as the Director considers critical, in consultation with the Secretary of Defense.</text>
 </paragraph><paragraph id="HC1F2B1564BA543B18E392E0C332C3420"><enum>(4)</enum><header>Outreach events</header><text>Under paragraph (1), the Director shall conduct outreach. Such outreach may include live events with a physical presence and outreach conducted through Internet websites.</text>
 </paragraph></subsection><subsection id="H254DAB5B0EC6453AB34E212D7149179E"><enum>(c)</enum><header>Voluntary cybersecurity self-Assessments</header><text>The Director shall provide, through the Hollings Manufacturing Extension Partnership, assistance to help small manufacturers conduct voluntary self-assessments in order to understand operating environments, cybersecurity requirements, and existing vulnerabilities.</text>
			</subsection><subsection id="H2A5903B9602341478360873EF78DF6C5"><enum>(d)</enum><header>Transfer of research findings and expertise</header>
 <paragraph id="H74A09CB6240943968D4825C48FEEF392"><enum>(1)</enum><header>In general</header><text>The Director shall provide for the transfer of technology and techniques developed at the National Institute of Standards and Technology to Centers, and through such Centers, to small manufacturers throughout the United States to implement security measures that are adequate to protect covered defense information, including controlled unclassified information.</text>
 </paragraph><paragraph id="H68F9EAA5A38040A786695C17F87503AE"><enum>(2)</enum><header>Use of other Federal expertise and capabilities</header><text>The Director shall use, when appropriate, the expertise and capabilities that exist in Federal agencies other than the Institute, and federally sponsored laboratories.</text>
 </paragraph><paragraph id="HCA17E22637CE45E48873D542655AFF77"><enum>(3)</enum><header>Agreements</header><text>In carrying out this subsection, the Centers may enter into agreements with private industry, institutes of higher education, or a State, United States territory, local, or tribal government to ensure breadth and depth of coverage to the United States defense industrial base and to leverage resources.</text>
 </paragraph></subsection><subsection id="HDE050009D10D49B49F9618CE0EF8CC33"><enum>(e)</enum><header>Defense acquisition workforce cyber training program</header><text>The Secretary of Defense, in consultation with the Director, shall establish a cyber counseling certification program, or approve a similar existing program, to certify small business professionals and other relevant acquisition staff within the Department of Defense to provide cyber planning assistance to small manufacturers in the defense industrial supply chain.</text>
			</subsection></section></legis-body></bill>


