<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" dms-id="H37EF65CE832243D1AD434914E8EBC9B2" public-private="public" key="H" bill-type="olc"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>119 HR 4126 IH: Aviation Risk Mitigation and Security Act</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2025-06-25</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress display="yes">119th CONGRESS</congress><session display="yes">1st Session</session><legis-num display="yes">H. R. 4126</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20250625">June 25, 2025</action-date><action-desc><sponsor name-id="C001132">Mr. Crane</sponsor> introduced the following bill; which was referred to the <committee-name committee-id="HHM00">Committee on Homeland Security</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To direct the Transportation Security Administration to carry out covert testing and risk mitigation improvement of aviation security operations, and for other purposes.</official-title></form><legis-body id="H8EDD7C7D2D2E48D9B8F30E865911072E" style="OLC"> 
<section id="H061CB82EEFE44613A3880413BCC35AC4" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Aviation Risk Mitigation and Security Act</short-title></quote> or the <quote><short-title>ARMS Act</short-title></quote>.</text></section> <section id="HC5E8BCA0815A4C46A800713953A83B3B"><enum>2.</enum><header>TSA covert testing and risk mitigation improvement</header> <subsection id="H58594FA83AC1464BB7AE46390F6FFD18"><enum>(a)</enum><header>In general</header><text>Not later than 180 days after the date of the enactment of this Act, the Administrator of the Transportation Security Administration (TSA) shall establish the following to strengthen aviation security operations:</text> 
<paragraph id="H890E252EAA88477F8A84369B22D2BA79" commented="no"><enum>(1)</enum><text display-inline="yes-display-inline">In accordance with subsection (b), a system for conducting risk-informed, headquarters-based covert testing project scenarios for aviation security operations, including relating to airport passenger and baggage security screening operations, that can yield statistically valid data that can be utilized to identify and assess the nature and extent of any vulnerabilities to such operations that are not mitigated by current security operations.</text></paragraph> <paragraph id="HA157998ABC064BFBB4A51E38E2614774" commented="no"><enum>(2)</enum><text display-inline="yes-display-inline">A long-term headquarters-based covert testing program, employing static but risk-informed threat vectors, based on annual risk assessments of emerging threats, designed to assess the effectiveness of aviation security operations on an annual basis.</text></paragraph></subsection> 
<subsection id="H5ABF018962D340828668D2E617726480"><enum>(b)</enum><header>Methodology</header><text>The Administrator of the TSA shall conduct the risk-informed, headquarters-based covert testing project scenarios for aviation security operations under paragraph (1) of subsection (a) based on annual risk assessments of emerging threats. The Administrator shall—</text> <paragraph id="H7743829C81C84FD4A3E3B02CA2A0399A" commented="no"><enum>(1)</enum><text display-inline="yes-display-inline">conduct not fewer than three such covert testing project scenarios to identify any systemic vulnerabilities in aviation security operations, and ensure that each Category X airport in the United States is included in such covert testing project scenarios at least once per fiscal year; and</text></paragraph> 
<paragraph id="H71DC5010232E43B494FE3863DF4C27C2" commented="no"><enum>(2)</enum><text display-inline="yes-display-inline">document the methodology, assumptions, and rationale guiding the selection and execution of such covert testing project scenarios to ensure statistical validity and actionable results.</text></paragraph></subsection> <subsection id="H01D5D6E7CF1849D2B17AA9EA0AF944B7"><enum>(c)</enum><header>Mitigation</header> <paragraph id="H5442349F66F54B4BB222598F29815A82" commented="no"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">The Administrator of the TSA shall establish a process to address and mitigate any vulnerabilities to aviation security operations identified and assessed pursuant to the covert testing project scenarios conducted under paragraph (1) of subsection (a).</text></paragraph> 
<paragraph id="H2E877B5740AF49C7A8C88FDEB4F59D2F"><enum>(2)</enum><header>Analysis</header><text>Not later than 90 days after identifying a vulnerability referred to in paragraph (1), the Administrator of the TSA shall conduct a root cause analysis to determine the origin and contributing factors relating to such vulnerability.</text></paragraph> <paragraph id="H0194E75A0ECE4A69BE33C0B61CDF8459" commented="no"><enum>(3)</enum><header>Determination</header><text>Not later than 150 days after conducting the analysis under paragraph (2), the Administrator of the TSA shall make a determination regarding whether or not to mitigate the vulnerability referred to in such paragraph, and shall prioritize mitigating such vulnerability based on the ability to reduce risk. If the Administrator determines—</text> 
<subparagraph id="H17CC3DEFB4E84454B0DA69C93BD223EC" commented="no"><enum>(A)</enum><text>to not mitigate such vulnerability, the Administrator shall document the justification relating thereto; or</text></subparagraph> <subparagraph id="H26843783F5F94CCC83DD8786DE6170FA" commented="no"><enum>(B)</enum><text>to mitigate such vulnerability, the Administrator shall establish and document—</text> 
<clause id="HBE90B0291D6C4C7AA43908711FB2EFC2" commented="no"><enum>(i)</enum><text>key milestones appropriate for the level of effort required to so mitigate such vulnerability; and</text></clause> <clause id="H1B0A4E26678C4B2BA19F817999E47FBE" commented="no"><enum>(ii)</enum><text>a date by which measures to so mitigate such vulnerability shall be implemented by the TSA.</text></clause></subparagraph></paragraph> 
<paragraph id="H4B76B438EFDB4B7E850EEFADA67639B6" commented="no"><enum>(4)</enum><header>Retesting</header><text>Not later than 180 days after the date on which measures to mitigate a vulnerability are completed by the TSA pursuant to paragraph (3)(B)(ii), and to the extent applicable, the Administrator of the TSA shall conduct a covert testing project scenario in accordance with subsection (a)(1) for the aviation security operation with respect to which such vulnerability was identified to assess the effectiveness of such measures to mitigate such vulnerability.</text></paragraph></subsection> <subsection id="H5741DF7484124AFC90C8D517C696315C"><enum>(d)</enum><header>Annual reporting</header> <paragraph id="H2A4BD21A8CEE416B9EAD5BE2FF717D09" commented="no"><enum>(1)</enum><header>Compilation of test results</header><text display-inline="yes-display-inline">Not later than November 30 of the first full fiscal year that begins after the date of the enactment of this Act and annually thereafter, the Administrator of the TSA, in consultation with the Secretary of Homeland Security, shall produce a report detailing the results of all covert testing project scenarios for aviation security operations under subsection (a)(1) conducted in the immediately preceding fiscal year by the TSA. Each such report shall—</text> 
<subparagraph id="H27207D5219574E129BBCD73D0BB23EED" commented="no"><enum>(A)</enum><text>be submitted in unclassified form, but may contain a classified annex in accordance with paragraph (2); and</text></subparagraph> <subparagraph id="H272084BD3649403E8F12334130AC90F2" commented="no"><enum>(B)</enum><text>include—</text> 
<clause id="H41BBC9DA9071486B82AA7BA8895679E2" commented="no"><enum>(i)</enum><text>a summary of all vulnerabilities to aviation security operations that were identified and the respective dates of such identifications;</text></clause> <clause id="H8606662B7B0F426280A42B12E12E221C" commented="no"><enum>(ii)</enum><text>the status of mitigation efforts under subsection (c), including key milestones and expected completion dates;</text></clause> 
<clause id="H882E12684A88468DB17E4C46AE88BC43" commented="no"><enum>(iii)</enum><text>the results of retesting under such subsection on previously mitigated vulnerabilities;</text></clause> <clause id="H59703DF959C64E64B4F91645FEF3412E" commented="no"><enum>(iv)</enum><text>justifications for vulnerabilities that remain unmitigated under such subsection, and a determination of whether full mitigation is feasible; and</text></clause> 
<clause id="HB4634F7C326C4D6E82CDF8959CA66D33" commented="no"><enum>(v)</enum><text>an assessment of security improvements based on covert testing data trends.</text></clause></subparagraph></paragraph> <paragraph id="H56CB300D1BC44C4B8F576C1EC859A46F"><enum>(2)</enum><header>Submission to Congress</header><text display-inline="yes-display-inline">The Administrator of the TSA shall submit to the Committee on Homeland Security of the House of Representatives and the Committee on Commerce, Science, and Transportation of the Senate each report required under paragraph (1) together with the Transportation Security Administration’s annual budget request. Each such report may include classified and sensitive security information, and any such information shall be submitted as a classified annex.</text></paragraph> 
<paragraph id="HE34099C3A9FC45349B703D8B653BEFAD" commented="no"><enum>(3)</enum><header>Public disclosure of covert testing performance at Category X airports</header> 
<subparagraph id="H6F83F839183C4741878ADEC529059CEE" commented="no"><enum>(A)</enum><header>In general</header><text display-inline="yes-display-inline">Not later than November 30 of the first full fiscal year that begins after the date of the enactment of this Act and annually thereafter, the Administrator of the TSA shall publish, and maintain on a publicly accessible website of the TSA, a summary of performance data acquired as a result of covert testing project scenarios conducted at Category X airports under subsection (b)(1) during the immediately preceding fiscal year. Each such summary shall—</text> <clause id="HEABC9F83A8EF41B1BBB146699993C076" commented="no"><enum>(i)</enum><text>include, at a minimum—</text> 
<subclause id="HB66452ED8BA1446EAFE377B8313AB9E3" commented="no"><enum>(I)</enum><text>the total number of tests carried out as part of such covert testing project scenarios conducted at Category X airports;</text></subclause> <subclause id="H377F28ECC14C4BC4B96894E22216DF8F" commented="no"><enum>(II)</enum><text display-inline="yes-display-inline">the aggregate pass rate and failure rate, expressed as percentages, for all such covert tests, calculated across all tested locations and covert testing project scenarios; and</text></subclause> 
<subclause id="H8CF60887ED8543999D169F0A4A5A97A3" commented="no"><enum>(III)</enum><text>general observations or trend data regarding changes in performance compared to the prior fiscal year; and</text></subclause></clause> <clause id="HA73213DA85344123B09CC1D6B56D18C6" commented="no"><enum>(ii)</enum><text display-inline="yes-display-inline">not include test scenario details, methodologies, or airport-specific data that could compromise aviation security operations.</text></clause></subparagraph> 
<subparagraph id="H2D364B1448224C26B70D534AFFB7A11D" commented="no"><enum>(B)</enum><header>Exception</header><text>Clause (ii) of subparagraph (A) shall not apply with respect to summary-level statistics regarding the overall performance of TSA screening operations at Category X airports for purposes of public availability of the annual summaries under such subparagraph.</text></subparagraph></paragraph></subsection> <subsection id="HCB920C3B153C44C7A8C384A06EDDF7BC" commented="no"><enum>(e)</enum><header>GAO review</header><text>Not later than three years after the date of the enactment of this Act, the Comptroller General of the United States shall submit to the Administrator of the TSA, the Committee on Homeland Security of the House of Representatives, and the Committee on Commerce, Science, and Transportation of the Senate a report on the effectiveness of the TSA’s processes for conducting covert testing that yields statistically valid data that can be utilized to assess the nature and extent of any vulnerabilities to aviation security operations that are not effectively mitigated by current security operations.</text></subsection></section> 
</legis-body></bill>

