<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-HLA25388-XPJ-SC-18C"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>119 S1705 IS: Chip Security Act</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2025-05-08</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes"> II</distribution-code><congress>119th CONGRESS</congress><session>1st Session</session><legis-num>S. 1705</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20250508">May 8, 2025</action-date><action-desc><sponsor name-id="S374">Mr. Cotton</sponsor> introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSBK00">Committee on Banking, Housing, and Urban Affairs</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To require the Secretary of Commerce to issue standards with respect to chip security mechanisms for integrated circuit products, and for other purposes. </official-title></form><legis-body><section id="id388de1dadb1e4b08ad6cadf001adb547" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Chip Security Act</short-title></quote>.</text></section><section commented="no" display-inline="no-display-inline" id="idf95ae963309f44d29cad6a0082c597b6"><enum>2.</enum><header>Sense of Congress</header><text display-inline="no-display-inline">It is the sense of Congress that—</text><paragraph id="idd81116e9979d45dc9b27aeadc13db1ce"><enum>(1)</enum><text>technology developed in the United States should serve as the foundation for the global ecosystem of artificial intelligence to advance the foreign policy and national security objectives of the United States and allies and partners of the United States;</text></paragraph><paragraph id="id5f073895e43c45069970155eac9fef1b"><enum>(2)</enum><text>the United States can foster goodwill, strengthen relationships, and support innovative research around the world by providing allies and partners of the United States with advanced computing capabilities;</text></paragraph><paragraph id="idd92403dcd0804d088d86a6d61cfded0a"><enum>(3)</enum><text>advanced integrated circuits and computing hardware that is exported from the United States must be protected from diversion, theft, and other unauthorized use or exploitation in order to bolster the competitiveness of the United States and protect the national security of the United States;</text></paragraph><paragraph id="ide8ff6953349945c28651463b8f75f0aa"><enum>(4)</enum><text>implementing chip security mechanisms will improve compliance with the export control laws of the United States, assist allies and partners with guarding computing hardware, and enhance protections from bad actors looking to access, divert, or tamper with advanced integrated circuits and computing hardware; and</text></paragraph><paragraph id="id56c0eb1f6eff4181b0197507e24fc9dd"><enum>(5)</enum><text>implementing chip security mechanisms may help with the detection of smuggling or exploitation of advanced integrated circuits and computing hardware, thereby allowing for increased flexibility in export controls and opening the door for more international partners to receive streamlined and larger shipments of advanced computing hardware.</text></paragraph></section><section commented="no" display-inline="no-display-inline" id="id28738a829cf8442393f593834582be2a"><enum>3.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act:</text><paragraph commented="no" display-inline="no-display-inline" id="id6c74f18909ea4e8fa799cfc71f4478ff"><enum>(1)</enum><header>Appropriate congressional committees</header><text display-inline="yes-display-inline">The term <term>appropriate congressional committees</term> means—</text><subparagraph commented="no" display-inline="no-display-inline" id="idc66edf6b31344a9996e0db8f5ae89ff5"><enum>(A)</enum><text display-inline="yes-display-inline">the Committee on Banking, Housing, and Urban Affairs of the Senate; and</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id1cefe04ddc4a4261b880bd1fd1cb8c86"><enum>(B)</enum><text>the Committee on Foreign Affairs of the House of Representatives.</text></subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="iddcf385d47f3c4b0abae6617d5da36462"><enum>(2)</enum><header>Chip Security Mechanism</header><text display-inline="yes-display-inline">The term <term>chip security mechanism</term> means a software-, firmware-, or hardware-enabled security mechanism or a physical security mechanism.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ide6ede9228baa4de68e03131196a865be"><enum>(3)</enum><header>Covered integrated circuit product</header><text display-inline="yes-display-inline">The term <term>covered integrated circuit product</term> means—</text><subparagraph commented="no" display-inline="no-display-inline" id="id83041d9e80c9425bba32b91d1e86421b"><enum>(A)</enum><text display-inline="yes-display-inline">an integrated circuit classified under Export Control Classification Number 3A090 or 3A001.z; </text></subparagraph><subparagraph id="id7EDFB5A8360844A79BB87CF77AC45471" commented="no" display-inline="no-display-inline"><enum>(B)</enum><text display-inline="yes-display-inline">a computer or other product classified under Export Control Classification Number 4A090 or 4A003.z; or</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idde9a747155f4401b8cd7bdd84c36df54"><enum>(C)</enum><text display-inline="yes-display-inline">an integrated circuit or computer or a product containing an integrated circuit or computer that is classified under an Export Control Classification Number that is a successor or substantially similar to the numbers listed in subparagraphs (A) and (B).</text></subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="idd4201b791de54f5bbe5563bc1c12cc1a"><enum>(4)</enum><header>Export</header><text>The term <term>export</term> has the meaning given that term in section 1742(3) of the Export Control Reform Act of 2018 (<external-xref legal-doc="usc" parsable-cite="usc/50/4801">50 U.S.C. 4801(3)</external-xref>).</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id386b7fa363134f5394ddc828676e3270"> <enum>(5)</enum> <header>In-country transfer</header> <text>The term <term>in-country transfer</term> has the meaning given that term in section 1742(6) of the Export Control Reform Act of 2018 (<external-xref legal-doc="usc" parsable-cite="usc/50/4801">50 U.S.C. 4801(6)</external-xref>).</text>
 </paragraph><paragraph commented="no" display-inline="no-display-inline" id="idb22e0be16a64468199acd6dc80899823"><enum>(6)</enum><header>Reexport</header><text>The term <term>reexport</term> has the meaning given that term in section 1742(9) of the Export Control Reform Act of 2018 (<external-xref legal-doc="usc" parsable-cite="usc/50/4801">50 U.S.C. 4801(9)</external-xref>).</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id6e70fa320daa4b80bb874cd7bcd515c6"><enum>(7)</enum><header>Secretary</header><text>The term <term>Secretary</term> means the Secretary of Commerce.</text></paragraph></section><section commented="no" display-inline="no-display-inline" id="id3e0d63f4114148209d3e0851340966d1" section-type="subsequent-section"><enum>4.</enum><header display-inline="yes-display-inline">Requirements for security mechanisms for export of integrated circuit products</header><subsection commented="no" display-inline="no-display-inline" id="idDD64954D171F4E9BBFDD4570E1AF6E19"><enum>(a)</enum><header>Primary requirements for chip security mechanisms</header><paragraph commented="no" display-inline="no-display-inline" id="id6C74C88A5F554AF297226A6A45C58270"><enum>(1)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">Not later than 180 days after the date of the enactment of this Act, the Secretary shall require any covered integrated circuit product to be outfitted with chip security mechanisms that implement location verification, using techniques that are feasible and appropriate on such date of enactment, before it is exported, reexported, or in-country transferred to or in a foreign country.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id3222882d652c4ba58f62d6d073022f08"><enum>(2)</enum><header>Notification requirement</header><text>Not later than 180 days after the date of the enactment of this Act, the Secretary shall require any person that has received a license or other authorization under the Export Control Reform Act of 2018 (<external-xref legal-doc="usc" parsable-cite="usc/50/4811">50 U.S.C. 4811 et seq.</external-xref>) to export, reexport, or in-country transfer a covered integrated circuit product to promptly report to the Under Secretary of Industry and Security, if the person obtains credible information that the product—</text><subparagraph commented="no" display-inline="no-display-inline" id="id1291a78e10dc461fa97312655ceae51c"><enum>(A)</enum><text display-inline="yes-display-inline">is in a location other than the location specified in the application for the license or other authorization; </text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id0d880c30cc4844baa3cb4c4245603316"><enum>(B)</enum><text>has been diverted to a user other than the user specified in the application; or</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id398dfea9d57c4a188e95bb58d0bf1acc"><enum>(C)</enum><text>has been subjected to tampering or an attempt at tampering, including efforts to disable, spoof, manipulate, mislead or circumvent location verification mechanisms or other chip security mechanisms.</text></subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="idfd332233da4e4c158f01c53481d6187b"><enum>(b)</enum><header>Development of secondary requirements for chip security mechanisms</header><paragraph commented="no" display-inline="no-display-inline" id="id92ddf1c5e5c747199e8e87bcbb78a0cd"><enum>(1)</enum><header display-inline="yes-display-inline">Assessment</header><subparagraph commented="no" display-inline="no-display-inline" id="id48362cc54e36408cb3d7fa4b79f2e103"><enum>(A)</enum><header display-inline="yes-display-inline">In general</header><text>Not later than one year after the date of the enactment of this Act, the Secretary shall, in coordination with the Secretary of Defense—</text><clause commented="no" display-inline="no-display-inline" id="id57217db19d824d85af779d744016bdfa"><enum>(i)</enum><text display-inline="yes-display-inline">conduct an assessment to identify what additional mechanisms, if any, should be added to the primary chip security mechanisms required under subsection (a)(1)—</text><subclause commented="no" display-inline="no-display-inline" id="id4adde4fa4a944e6e8422989c1ff2ac9f"><enum>(I)</enum><text display-inline="yes-display-inline">to enhance compliance with the requirements of the Export Control Reform Act of 2018;</text></subclause><subclause commented="no" display-inline="no-display-inline" id="id1b21667fa2bd4c209c1437c3f4de1d90"><enum>(II)</enum><text>to prevent, hinder, and detect the unauthorized use, access, or exploitation of covered integrated circuit products;</text></subclause><subclause commented="no" display-inline="no-display-inline" id="ida8a9e329177e4422913ac8f1e8111cf4"><enum>(III)</enum><text>to identify and monitor smuggling intermediaries; and</text></subclause><subclause commented="no" display-inline="no-display-inline" id="id5dbff4b75a6e4d729285599bc8f0a540"><enum>(IV)</enum><text>to achieve any national security or foreign policy objective of the United States that the Secretary considers appropriate; and</text></subclause></clause><clause commented="no" display-inline="no-display-inline" id="id0753819763d94748804b7e2492d9437a"><enum>(ii)</enum><text display-inline="yes-display-inline">if the Secretary identifies any such mechanism, develop requirements for outfitting covered integrated circuit products with that mechanism.</text></clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id8aef5ca267ce43ba958bad96a3e7dfb4"><enum>(B)</enum><header>Elements</header><text>The assessment required by paragraph (1) shall include—</text><clause commented="no" display-inline="no-display-inline" id="id695c5917127b4d2aa3d3cb15667adc69"><enum>(i)</enum><text display-inline="yes-display-inline">an examination of the feasibility, reliability, and effectiveness of—</text><subclause commented="no" display-inline="no-display-inline" id="idd0c405236d62427ab09f6628b88e78d8"><enum>(I)</enum><text display-inline="yes-display-inline">methods and strategies that prevent the tampering, disabling, or other manipulating of covered integrated circuit products;</text></subclause><subclause commented="no" display-inline="no-display-inline" id="id11c2a830a39e493a93a13cbab2a55696"><enum>(II)</enum><text display-inline="yes-display-inline">workload verification methods;</text></subclause><subclause commented="no" display-inline="no-display-inline" id="id94cccd0775ac494c842714f30f13d526"><enum>(III)</enum><text display-inline="yes-display-inline">methods to modify the functionality of covered integrated circuit products that have been illicitly acquired; and</text></subclause><subclause commented="no" display-inline="no-display-inline" id="id8f010f57c0924d7fae97a44042b8ee26"><enum>(IV)</enum><text display-inline="yes-display-inline">any other method the Secretary determines appropriate for the prevention of unauthorized use, access, or exploitation of covered integrated circuit products;</text></subclause></clause><clause commented="no" display-inline="no-display-inline" id="id153000d7d3c14422a99a3d3faae95df4"><enum>(ii)</enum><text display-inline="yes-display-inline">an analysis of—</text><subclause commented="no" display-inline="no-display-inline" id="id4ea0119703bb45039ab2da81f083372b"><enum>(I)</enum><text display-inline="yes-display-inline">the potential costs associated with implementing each method examined under clause (i), including an analysis of—</text><item commented="no" display-inline="no-display-inline" id="ida71fd4a6061e49eb96e4d1e5cf733bf7"><enum>(aa)</enum><text display-inline="yes-display-inline">the potential impact of the method on the performance of covered integrated circuit products; and</text></item><item commented="no" display-inline="no-display-inline" id="idaa2abc5ebe384c67a5b8e0c71fdf7579"><enum>(bb)</enum><text display-inline="yes-display-inline">the potential for the introduction of new vulnerabilities into the products;</text></item></subclause><subclause commented="no" display-inline="no-display-inline" id="id148163cdcc8446a39cc3f0613d1dab63"><enum>(II)</enum><text display-inline="yes-display-inline">the potential benefits of implementing the methods examined under clause (i), including an analysis of the potential increase—</text><item commented="no" display-inline="no-display-inline" id="id6d502b601ec2478eb3341e6299399e50"><enum>(aa)</enum><text display-inline="yes-display-inline">in compliance of covered integrated circuit products with the requirements of the Export Control Reform Act of 2018; and</text></item><item commented="no" display-inline="no-display-inline" id="id6a9754c53e7642d39c9c9e3c2c630bfd"><enum>(bb)</enum><text display-inline="yes-display-inline">in detecting, hindering, and preventing unauthorized use, access, or exploitation of the products; and</text></item></subclause><subclause commented="no" display-inline="no-display-inline" id="id31953a401c074614b1f9b52019805884"><enum>(III)</enum><text display-inline="yes-display-inline">the susceptibility of the methods examined under clause (i) to tampering, disabling, or other forms of manipulation; and</text></subclause></clause><clause commented="no" display-inline="no-display-inline" id="idab51a77496aa4bef85cf54f08efe23ca"><enum>(iii)</enum><text display-inline="yes-display-inline">an estimate of the expected costs to implement at-scale methods to tamper with, disable, or manipulate a covered integrated circuit product, or otherwise circumvent the methods examined under clause (i).</text></clause></subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id67cccbaab4a64010bb41048121fd196f"><enum>(2)</enum><header>Report to Congress</header><subparagraph commented="no" display-inline="no-display-inline" id="id942df3d0e4a9450fba40b7d0bab8f77e"><enum>(A)</enum><header>In general</header><text display-inline="yes-display-inline">Not later than one year after the date of the enactment of this Act, the Secretary, in coordination with the Secretary of Defense, shall submit to the appropriate congressional committees a report on the results of the assessment required by paragraph (1), including—</text><clause commented="no" display-inline="no-display-inline" id="idef156ac956b34d89b33a638a2b094337"><enum>(i)</enum><text display-inline="yes-display-inline">an identification of the chip security mechanisms, if any, to be included in the requirements for secondary chip security mechanisms; and</text></clause><clause commented="no" display-inline="no-display-inline" id="ide9e35e934f324d4b899fa420de9d27df"><enum>(ii)</enum><text display-inline="yes-display-inline">if applicable, a roadmap for the timely implementation of the secondary chip security mechanisms. </text></clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="iddcf18d961be44bc3a8de12a16dab37b6"><enum>(B)</enum><header>Form</header><text>The report required by paragraph (1) shall be submitted in unclassified form, but may include a classified annex. </text></subparagraph></paragraph><paragraph id="idF303687765B640FBADA04065747F9959"><enum>(3)</enum><header>Implementation</header><text display-inline="yes-display-inline"><?xm-replace_text text?></text><subparagraph commented="no" display-inline="no-display-inline" id="ideda2f8678be14c098a9d2976e88662a5"><enum>(A)</enum><header>In general</header><text display-inline="yes-display-inline">If any mechanisms are determined by the Secretary to be appropriate, the Secretary shall, not later than 2 years after the date on which the Secretary completes the assessment required by paragraph (1), require any covered integrated circuit product to be outfitted with the secondary chip security mechanisms identified pursuant to paragraph (1)(A) before the product is exported, reexported, or in-country transferred to or in a foreign country. </text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id6C87DEF2DD5E4F189CD5340BD1F0E93C"><enum>(B)</enum><header>Privacy</header><text display-inline="yes-display-inline">In implementing requirements for secondary chip security mechanisms under subparagraph (A), the Secretary shall prioritize confidentiality. </text></subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="id00eb0273063e4e0b9279921b0ca40322"><enum>(c)</enum><header>Enforcement authority</header><text>In carrying out this section, the Secretary may—</text><paragraph commented="no" display-inline="no-display-inline" id="id7054cc7601b84949a9fa57f4e995bfd6"><enum>(1)</enum><text display-inline="yes-display-inline">verify, in a manner the Secretary determines appropriate, the ownership and location of a covered integrated circuit product that has been exported, reexported, or in-country transferred to or in a foreign country; </text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id52bb50d6f6e3428b87d58c4eb2b4de45"><enum>(2)</enum><text>maintain a record of covered integrated circuit products and include in the record the location and current end-user of each such product; and</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id5d71e22a3818472d8b8e02697c926b4c"><enum>(3)</enum><text>require any person who has been granted a license or other authorization under the Export Control Reform Act of 2018 to export, reexport, or in-country transfer a covered integrated circuit product to provide the information needed to maintain the record. </text></paragraph></subsection><subsection id="id90A20A5186304DEB978089CA5A81E0D6" commented="no"><enum>(d)</enum><header>Annual assessment and report on new chip security mechanisms</header><text display-inline="yes-display-inline">Not later than 2 years after the date of the enactment of this Act, and annually thereafter for 3 years, the Secretary shall—</text><paragraph commented="no" display-inline="no-display-inline" id="id4e2967e5aaf2449cafee77431e6e9011"><enum>(1)</enum><text display-inline="yes-display-inline">in coordination with the Secretary of Defense, conduct an assessment of new chip security mechanisms that have been developed in the year preceding the date of the assessment; and</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id4d755363d9a94178820be30e0e82a940"><enum>(2)</enum><text display-inline="yes-display-inline">submit to the appropriate congressional committees a report that includes—</text><subparagraph commented="no" display-inline="no-display-inline" id="idb1bcd684eea44e5bbf0f72966108f865"><enum>(A)</enum><text>a summary of the results of the assessment required by paragraph (1);</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id4655462710704dbaa7b9d9fd5b862a5e"><enum>(B)</enum><text display-inline="yes-display-inline">an evaluation of whether any of the new mechanisms assessed under paragraph (1) should be added to or replace any of the existing requirements for secondary chip security mechanisms developed under subsection (b)(1); and</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id3378fe64c8014ed5b73c673f86290c8d"><enum>(C)</enum><text display-inline="yes-display-inline">any recommendations for modifications to relevant export controls to allow for more flexibility with respect to the countries to or in which covered integrated circuit products may be exported, reexported, or in-country transferred if the products include chip security mechanisms that meet the requirements developed under subsection (b)(1).</text></subparagraph></paragraph></subsection></section></legis-body></bill> 

