<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-ALL24528-JXL-0N-S6G"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>118 S4651 IS: Securing America’s Federal Equipment in Supply Chains Act</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2024-07-10</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>118th CONGRESS</congress><session>2d Session</session><legis-num>S. 4651</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20240710">July 10, 2024</action-date><action-desc><sponsor name-id="S287">Mr. Cornyn</sponsor> (for himself and <cosponsor name-id="S380">Mr. Peters</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSGA00">Committee on Homeland Security and Governmental Affairs</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To require agencies to use information and communications technology products obtained from original equipment manufacturers or authorized resellers, and for other purposes.</official-title></form><legis-body><section id="S1" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Securing America’s Federal Equipment in Supply Chains Act</short-title></quote> or the <quote><short-title>SAFE Supply Chains Act</short-title></quote>.</text></section><section commented="no" display-inline="no-display-inline" id="idb6e9fd8e116548ffa6ab518733a1b041"><enum>2.</enum><header>Agency use of IT products</header><subsection id="idd374ae57dc9c4c7bbcf120d2660fcb56"><enum>(a)</enum><header>Definitions</header><text>In this section:</text><paragraph commented="no" display-inline="no-display-inline" id="idd27306b4e08b4963804bf6ac40193c6b"><enum>(1)</enum><header>Agency</header><text>The term <term>agency</term> has the meaning given the term in section 3502 of title 44, United States Code.</text></paragraph><paragraph id="id9aaf796f500645a3b50d4aab788e155f" commented="no" display-inline="no-display-inline"><enum>(2)</enum><header>Appropriate congressional committees</header><text>The term <term>appropriate congressional committees</term> means the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Oversight and Accountability of the House of Representatives.</text></paragraph><paragraph id="idFD3DDD80D720442EB4D9736615D2C6F4"><enum>(3)</enum><header>Authorized reseller</header><text>The term <term>authorized reseller</term> means a reseller, after market manufacturer, supplier, or distributor of a covered product with a direct or prime contractual arrangement with, or the express written authority of, the original equipment manufacturer of the covered product to manufacture, buy, stock, repackage, sell, resell, repair, service, otherwise support, or distribute the covered product.</text></paragraph><paragraph id="id0CB761D157744BED87CF966BE1BC98E8"><enum>(4)</enum><header>Covered product</header><text>The term <term>covered product</term>—</text><subparagraph id="id64908A5CD66D41AFABE6377B40BEE4D1"><enum>(A)</enum><text>means an information and communications technology end-use hardware product or component, including software and firmware that comprise the end-use hardware product or component; and</text></subparagraph><subparagraph commented="no" id="idC23FAF6E710A468290103DFCD293F485"><enum>(B)</enum><text>does not include—</text><clause commented="no" id="id23D35BCC109247EF8CDF472CB3AE3F0C"><enum>(i)</enum><text>other software; or</text></clause><clause commented="no" id="idC0F0A10A05CF48D1AC74AA99AE464D89"><enum>(ii)</enum><text>an end-use hardware product—</text><subclause commented="no" id="idF96C321CACD548269B58797ADB1DFF8B"><enum>(I)</enum><text>in which there is embedded information and communications technology; and</text></subclause><subclause commented="no" id="id94D48EF5BAE74C4CB8E514CC4DA6BF24"><enum>(II)</enum><text>the principal function of which is not the creation, manipulation, storage, display, receipt, or transmission of electronic data and information.</text></subclause></clause></subparagraph></paragraph><paragraph commented="no" id="idA991A1E8DA704E739C24F46B583D2D82"><enum>(5)</enum><header>End-use product</header><text>The term <term>end-use product</term> means a product ready for use by the maintainer, integrator, or end user of the product.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id9AB7557E07394CAA8F8157A628FF1232"><enum>(6)</enum><header>Information and communications technology</header><text>The term <term>information and communications technology</term>—</text><subparagraph commented="no" display-inline="no-display-inline" id="id1CED97E024EC44728A109D6FAA8F8000"><enum>(A)</enum><text>has the meaning given the term in section 4713 of title 41, United States Code; and</text></subparagraph><subparagraph display-inline="no-display-inline" commented="no" id="idE47ADE0326324956A179D0B0A4231587"><enum>(B)</enum><text>includes information and communications technologies covered by definitions contained in the Federal Acquisition Regulation, including definitions added after the date of the enactment of this Act by the Federal Acquisition Regulatory Council pursuant to notice and comment.</text></subparagraph></paragraph><paragraph id="idb711438b1c4344bc8b0b93e90d469153"><enum>(7)</enum><header>Original equipment manufacturer</header><text>The term <term>original equipment manufacturer</term> means a company that manufactures a covered product that the company—</text><subparagraph commented="no" display-inline="no-display-inline" id="ida1af54bf88314b64b1cb4c8d2a546c57"><enum>(A)</enum><text display-inline="yes-display-inline">designed from self-sourced or purchased components; and</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idccccaf6a8d5a4dbda633518f473de509"><enum>(B)</enum><text display-inline="yes-display-inline">sells under the name of the company.</text></subparagraph></paragraph></subsection><subsection id="idbb045702c7f3465898d182edf25a6aea"><enum>(b)</enum><header>Prohibition on procurement and use</header><text>Subject to subsection (c) and notwithstanding sections 1905 through 1907 of title 41, United States Code, the head of an agency may not procure or obtain, renew a contract to procure or obtain, or use a covered product that is procured from an entity other than—</text><paragraph commented="no" display-inline="no-display-inline" id="id2e1883d0c52443bb8b9d0ba7f3ded8d7"><enum>(1)</enum><text display-inline="yes-display-inline">an original equipment manufacturer; or</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="iddc5b080fd9cf4f318f95c8fbebf00421"><enum>(2)</enum><text display-inline="yes-display-inline">an authorized reseller.</text></paragraph></subsection><subsection id="idbe2fbe777ac7457890d700a538a7bf9f"><enum>(c)</enum><header>Waiver</header><paragraph commented="no" display-inline="no-display-inline" id="id538ad593631248d28319d9f190f49472"><enum>(1)</enum><header display-inline="yes-display-inline">In general</header><text>Upon written notice to the Director of the Office of Management and Budget, the head of an agency may waive the prohibition under subsection (b) with respect to a covered product if the head of the agency determines that—</text><subparagraph commented="no" display-inline="no-display-inline" id="idf18e3ae68be34ae9b0f1565993458332"><enum>(A)</enum><text display-inline="yes-display-inline">the waiver is necessary in the interest of national security; or</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id83339771c26b4407aea7f7fd99b72116"><enum>(B)</enum><text display-inline="yes-display-inline">procuring, obtaining, or using the covered product is necessary—</text><clause commented="no" display-inline="no-display-inline" id="ide51aaff0141c49c587f2607b5038d731"><enum>(i)</enum><text display-inline="yes-display-inline">for the purpose of scientifically valid research (as defined in section 102 the Education Sciences Reform Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/20/9501">20 U.S.C. 9501</external-xref>)); or</text></clause><clause commented="no" display-inline="no-display-inline" id="id3aaca2585b6846c4aa46e51bd3a64d84"><enum>(ii)</enum><text>to avoid jeopardizing the performance of mission critical functions.</text></clause></subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id2f042c22a03b4facbaf7f58813834c0d"><enum>(2)</enum><header>Notice</header><text display-inline="yes-display-inline">The notice described in paragraph (1)—</text><subparagraph commented="no" display-inline="no-display-inline" id="id417aba4c576b40198dd82cbc32971de5"><enum>(A)</enum><text display-inline="yes-display-inline">shall—</text><clause commented="no" display-inline="no-display-inline" id="id0aef012fad7442d090657f38ed9ab175"><enum>(i)</enum><text display-inline="yes-display-inline">specify, with respect to the waiver under paragraph (1)—</text><subclause commented="no" display-inline="no-display-inline" id="ide23c37a32d274dd4b8c7b1b1e9719278"><enum>(I)</enum><text display-inline="yes-display-inline">the justification for the waiver;</text></subclause><subclause commented="no" display-inline="no-display-inline" id="id45de671acfbc4c76b4b9bd5f7e941296"><enum>(II)</enum><text display-inline="yes-display-inline">any security mitigations that have been implemented; and</text></subclause><subclause commented="no" display-inline="no-display-inline" id="ide4b31ba50b8d428aaafd95fba0a94d1b"><enum>(III)</enum><text display-inline="yes-display-inline">with respect to a waiver that necessitates a security mitigation, the plan of action and milestones to avoid future waivers for subsequent similar purchases; and</text></subclause></clause><clause commented="no" display-inline="no-display-inline" id="id8d029a082be14149aef5a75f7c69c29c"><enum>(ii)</enum><text>be submitted in an unclassified form; and</text></clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idc934dd4b946448b192dc889d50e99e35"><enum>(B)</enum><text>may include a classified annex.</text></subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ida037b1ccd7674ad79f8108aebf4b7fcc"><enum>(3)</enum><header>Duration</header><text>With respect to a waiver for the purpose of research, as described in paragraph (1)(B)(i), the waiver shall be effective for the duration of the research identified in the waiver.</text></paragraph></subsection><subsection id="idfcf956a13c4d451fa4832f59af7e082a"><enum>(d)</enum><header>Reports to congress</header><paragraph id="idc0c9a5c890184d15aa88dd28fceb4232"><enum>(1)</enum><header>In general</header><text>Not later than 1 year after the date of enactment of this Act, and annually thereafter until the date that is 6 years after the date of enactment of this Act, the Director of the Office of Management and Budget shall submit to the appropriate congressional committees a report that lists—</text><subparagraph id="id39e9242f4f7c4a199995bde8f063b3f1"><enum>(A)</enum><text>the number and types of covered products for which a waiver under subsection (c)(1) was granted during the 1-year period preceding the date of the submission of the report; and</text></subparagraph><subparagraph id="id75be416b264d41f3862981d61a0fe1d8"><enum>(B)</enum><text>the legal authority under which each waiver described in subparagraph (A) was granted, such as whether the waiver was granted pursuant to subparagraph (A) or (B) of subsection (c)(1).</text></subparagraph></paragraph><paragraph id="idfbbc422211bb49c99f2be43d89b995da"><enum>(2)</enum><header>Classification of report</header><text>Each report submitted under this subsection—</text><subparagraph commented="no" display-inline="no-display-inline" id="id3ebaa5ae58674ef8baa8bf89535ca3a1"><enum>(A)</enum><text display-inline="yes-display-inline">shall be submitted in unclassified form; and</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idba8515826c5f4b51afc94a8f8406aa97"><enum>(B)</enum><text display-inline="yes-display-inline">may include a classified annex that contains the information described in paragraph (1)(B).</text></subparagraph></paragraph></subsection><subsection id="idb7745d32aef44ddfa552171d80498a89"><enum>(e)</enum><header>Effective date</header><text>This section shall take effect on the date that is 1 year after the date of enactment of this Act.</text></subsection></section></legis-body></bill> 

