<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" dms-id="H3EBDB824BB7641B89F36FE4AE069A0D0" public-private="public" key="H" bill-type="olc"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>117 HR 2236 IH: Cyber Shield Act of 2021</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2021-03-26</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress display="yes">117th CONGRESS</congress><session display="yes">1st Session</session><legis-num display="yes">H. R. 2236</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20210326">March 26, 2021</action-date><action-desc><sponsor name-id="L000582">Mr. Lieu</sponsor> introduced the following bill; which was referred to the <committee-name committee-id="HIF00">Committee on Energy and Commerce</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To establish a voluntary program to identify and promote internet-connected products that meet industry-leading cybersecurity and data security standards, guidelines, best practices, methodologies, procedures, and processes, and for other purposes.</official-title></form><legis-body id="H0A757C02F15B42588BF7F136AEC2F8BA" style="OLC"><section id="H9B3D098AB7264EC881513D9492BF36E3" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Cyber Shield Act of 2021</short-title></quote>.</text></section><section id="HFEF729BB808346A78C144999304362BE"><enum>2.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act—</text><paragraph id="H98F0D311B4C445EDA461F78B31360B3F"><enum>(1)</enum><text>the term <term>Advisory Committee</term> means the Cyber Shield Advisory Committee established by the Secretary under section 3(a);</text></paragraph><paragraph id="H6D1FD73689374B3D80949BA66453B758"><enum>(2)</enum><text>the term <term>benchmarks</term> means standards, guidelines, best practices, methodologies, procedures, and processes;</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="H7D21F0184ACD47038896DAD0584576F6"><enum>(3)</enum><text>the term <term>covered product</term> means a consumer-facing physical object that can—</text><subparagraph commented="no" display-inline="no-display-inline" id="H4F2B27882DC6430EA4C3A8181AE5F4AA"><enum>(A)</enum><text>connect to the internet or other network; and</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="HF40758B797484F7CB774F1A73EF7D9FD"><enum>(B)</enum><clause commented="no" display-inline="yes-display-inline" id="H6E77A3F3C62A4557A9ABA5063423D36D"><enum>(i)</enum><text>collect, send, or receive data; or</text></clause><clause commented="no" display-inline="no-display-inline" id="HE4F693522B384483A0C297D7707770C8" indent="up1"><enum>(ii)</enum><text>control the actions of a physical object or system;</text></clause></subparagraph></paragraph><paragraph id="HA7A428A3BE014EE9AF4FB3873ED7B989"><enum>(4)</enum><text>the term <term>Cyber Shield program</term> means the voluntary program established by the Secretary under section 4(a)(1); and</text></paragraph><paragraph id="H6A683B42B32D4870BE96A74585EF90F1"><enum>(5)</enum><text>the term <term>Secretary</term> means the Secretary of Commerce.</text></paragraph></section><section id="HE29821835DA14D07B4B62CD415182372"><enum>3.</enum><header>Cyber Shield Advisory Committee</header><subsection id="HEEE37DA8225F4B5382D34BA1643A312C"><enum>(a)</enum><header>Establishment</header><text>Not later than 90 days after the date of enactment of this Act, the Secretary shall establish the Cyber Shield Advisory Committee.</text></subsection><subsection id="HDBBF2D22FE1E479EAA50B479D91339CA"><enum>(b)</enum><header>Duties</header><paragraph id="H0F1F41575D15475B88C7BBF45478FCA7"><enum>(1)</enum><header>In general</header><text>Not later than 1 year after the date of enactment of this Act, the Advisory Committee shall provide recommendations to the Secretary regarding—</text><subparagraph id="H9A14BB24FD3941968A17862AF5AAA5ED"><enum>(A)</enum><text>the format and content of the Cyber Shield labels required to be established under section 4; and</text></subparagraph><subparagraph id="HA5E21F3BEE054797B01CE59E6AEDE977"><enum>(B)</enum><text>the process for identifying, establishing, reporting on, adopting, maintaining, and promoting compliance with the voluntary cybersecurity and data security benchmarks required to be established under section 4.</text></subparagraph></paragraph><paragraph id="H3AA9567343D84CBCBAFC0194703E30CC"><enum>(2)</enum><header>Public availability of recommendations</header><text>The Advisory Committee shall publish, and provide the public with an opportunity to comment on, the recommendations provided to the Secretary under paragraph (1).</text></paragraph></subsection><subsection id="HBD4974B2772D479AA31238FD60A11256"><enum>(c)</enum><header>Members, chair, and duties</header><paragraph id="HA83EDFD3E8C34ACDB644198B32EFEA5B"><enum>(1)</enum><header>Appointment</header><subparagraph id="H753A565F17874472A5C1C893ACD8CB08"><enum>(A)</enum><header>In general</header><text>The Advisory Committee shall be composed of members appointed by the Secretary from among individuals who are specially qualified to serve on the Advisory Committee based on the education, training, or experience of those individuals.</text></subparagraph><subparagraph id="H90261026ECD945509008F84C22DDF811"><enum>(B)</enum><header>Representation</header><text>Members appointed under subparagraph (A) shall include—</text><clause id="HF6D0E2E6ABCE4D53840F09863A383E1D"><enum>(i)</enum><text>representatives of the covered products industry, including small, medium, and large businesses;</text></clause><clause id="HE27E1B2E98E741EAAB4BD348B5BFB23F"><enum>(ii)</enum><text>cybersecurity experts, including independent cybersecurity researchers that specialize in areas such as cryptanalysis, hardware and software security, wireless and network security, cloud security, and data privacy;</text></clause><clause id="H6E1A3288CAB34361A95D4703A297010B"><enum>(iii)</enum><text>public interest advocates;</text></clause><clause id="H600F741F3E0E42318B8913970B6FEC6F"><enum>(iv)</enum><text>a liaison from the Information Security and Privacy Advisory Board established under section 21(a) of the National Institute of Standards and Technology Act (<external-xref legal-doc="usc" parsable-cite="usc/15/278g-4">15 U.S.C. 278g–4(a)</external-xref>) who is a member of that Board as described in paragraph (3) of such section 21(a);</text></clause><clause id="H253331E77D6E429BBAFD5851159455EA"><enum>(v)</enum><text>Federal employees with expertise in certification, covered devices, or cybersecurity, including employees of—</text><subclause id="H0B52997CD4A14E398D6C6E6594C65662"><enum>(I)</enum><text>the Department of Commerce;</text></subclause><subclause id="H7D9393DC77D84C0FB1CA62EDA91DEA19"><enum>(II)</enum><text>the National Institute of Standards and Technology;</text></subclause><subclause id="HE4F023ED92CB40B99D1E9AD2AB6D51EE"><enum>(III)</enum><text>the Federal Trade Commission;</text></subclause><subclause id="H1DB033A9B1C345538E6C5D9534381894"><enum>(IV)</enum><text>the Federal Communications Commission; and</text></subclause><subclause id="H54B89BC88899495B92BB58BA4490D705"><enum>(V)</enum><text>the Consumer Product Safety Commission; and</text></subclause></clause><clause id="HFD927C7F80DA42DFA6C65B87228DBCA4"><enum>(vi)</enum><text>an expert who shall ensure that, subject to subsection (e), the Advisory Committee conforms to and complies with the requirements under the Federal Advisory Committee Act (5 U.S.C. App.).</text></clause></subparagraph><subparagraph id="HAC9065A226AC492FB82F7B4ED5EB7328"><enum>(C)</enum><header>Limitation</header><text>In appointing members under subparagraph (A), the Secretary shall ensure that—</text><clause id="H93231AED6B5F46DA9E1AA173FC3F34DB"><enum>(i)</enum><text>each interest group described in clauses (i), (ii), (iii), and (v) of subparagraph (B) is proportionally represented on the Advisory Committee, including—</text><subclause id="H09090D8C9F924D04B1FE1CAF4A19415D"><enum>(I)</enum><text>businesses of each size described in clause (i) of that subparagraph;</text></subclause><subclause id="H53E499C6B68E4D22B706271D677055AF"><enum>(II)</enum><text>Federal employees with expertise in each subject described in clause (v) of that subparagraph; and</text></subclause><subclause id="HE599B6F0D4E943B3856B3FA75D6701F0"><enum>(III)</enum><text>Federal employees from each agency described in subclauses (I) through (V) of clause (v) of that subparagraph; and</text></subclause></clause><clause id="H074D99842478414AAA355C99015D1998"><enum>(ii)</enum><text>no single interest group described in clauses (i), (ii), (iii), and (v) of subparagraph (B) is represented by a majority of the members of the Advisory Committee.</text></clause></subparagraph></paragraph><paragraph id="HB36A733EF90C4CBBB1FD2B761EF928CB"><enum>(2)</enum><header>Chair</header><text>The Secretary shall designate a member of the Advisory Committee to serve as Chair.</text></paragraph><paragraph id="H1666C3FD35294EFAA17C62DF2C99B2AB"><enum>(3)</enum><header>Pay</header><text>Members of the Advisory Committee shall serve without pay, except that the Secretary may allow a member, while attending meetings of the Advisory Committee or a subcommittee of the Advisory Committee, per diem, travel, and transportation expenses authorized under section 5703 of title 5, United States Code.</text></paragraph></subsection><subsection id="H0EF152842E3044C9A2A08068D97F643A"><enum>(d)</enum><header>Support staff; administrative services</header><paragraph id="H07E93424D7D54EF09DF62342E74D1576"><enum>(1)</enum><header>Support staff</header><text>The Secretary shall provide support staff for the Advisory Committee.</text></paragraph><paragraph id="H50ADC72EEC704C478B4BDC4B0DF94472"><enum>(2)</enum><header>Administrative services</header><text>Upon the request of the Advisory Committee, the Secretary shall provide any information, administrative services, and supplies that the Secretary considers necessary for the Advisory Committee to carry out the duties and powers of the Advisory Committee.</text></paragraph></subsection><subsection id="HFDD3BC3166DF47DFBD284CE15695AB89"><enum>(e)</enum><header>No termination</header><text>Section 14 of the Federal Advisory Committee Act (5 U.S.C. App.) shall not apply to the Advisory Committee.</text></subsection><subsection id="HDBDB90AD5227405FA22B9BE7FEAFE0CE"><enum>(f)</enum><header>Authorization of appropriations</header><text>There are authorized to be appropriated such sums as may be necessary to carry out this section.</text></subsection></section><section id="HC3A994A29CA04BC3B9A89A5DB8DE77C4"><enum>4.</enum><header>Cyber Shield program</header><subsection id="HA280D2C20AAD4A1ABD47AD7CEC6E6DE2"><enum>(a)</enum><header>Establishment of program</header><paragraph id="HE2E3F17C7D3F4577946CB5D8FF0E02C2"><enum>(1)</enum><header>In general</header><text>The Secretary shall establish a voluntary program to identify and certify covered products through voluntary certification and labeling of, and other forms of communication about, covered products and subsets of covered products that meet industry-leading cybersecurity and data security benchmarks to enhance cybersecurity and protect data.</text></paragraph><paragraph id="H485C1CA6032D459D95B05C2D28CEA6ED"><enum>(2)</enum><header>Labels</header><text>Labels applied to covered products under the Cyber Shield program—</text><subparagraph id="H6D8C5C73F64A407FBD05798950A95626"><enum>(A)</enum><text>shall be digital and, if feasible, physical and affixed to the covered product or packaging; and</text></subparagraph><subparagraph id="H2E8314F47AA246EEA91F857B82F08F4D"><enum>(B)</enum><text>may be in the form of different grades that display the extent to which a covered product meets the industry-leading cybersecurity and data security benchmarks.</text></subparagraph></paragraph></subsection><subsection id="HDF88804D95A140C8B3B37517284A1929"><enum>(b)</enum><header>Consultation</header><text>Not later than 90 days after the date of enactment of this Act, the Secretary shall establish a process for consulting interested parties, the Secretary of Health and Human Services, the Commissioner of Food and Drugs, the Secretary of Homeland Security, and the heads of other Federal agencies in carrying out the Cyber Shield program.</text></subsection><subsection id="HFD70D54721FA4088AA7A9A83E9179AE1"><enum>(c)</enum><header>Duties</header><text>In carrying out the Cyber Shield program, the Secretary—</text><paragraph id="HBE82F081ABB647258695277FBB853EE8"><enum>(1)</enum><text>shall—</text><subparagraph id="HC2CFC2960E4A4CBFB6455B4A38926962"><enum>(A)</enum><text>by convening and consulting interested parties and the heads of other Federal agencies, establish and maintain cybersecurity and data security benchmarks for covered products with the Cyber Shield label to ensure that those covered products perform better than counterparts of those covered products that do not have the Cyber Shield label; and</text></subparagraph><subparagraph id="H3F54005BB3BF4738BD5940859CED40D0"><enum>(B)</enum><text>in carrying out subparagraph (A)—</text><clause id="H3E18C3F5383D4779AAABA3F5F18DEEAB"><enum>(i)</enum><text>engage in an open public review and comment process;</text></clause><clause id="HE423570EDC9B4C64AC03A56BCED82608"><enum>(ii)</enum><text>in consultation with the Advisory Committee, identify and apply cybersecurity and data security benchmarks to different subsets of covered products based on, with respect to each such subset—</text><subclause id="H0D43F16FF302426CBB5562A8BB53718A"><enum>(I)</enum><text>any cybersecurity and data security risk relating to covered products in the subset;</text></subclause><subclause id="H3A0766C20ACC47AE9AC79C4434D2A78F"><enum>(II)</enum><text>the sensitivity of the information collected, transmitted, or stored by covered products in the subset;</text></subclause><subclause id="H2CAA95D1A5C84B11868CAE51F6FD1850"><enum>(III)</enum><text>the functionality of covered products in the subset;</text></subclause><subclause id="HCEDBD29FD8F84F5F9B6A5A6238F7CA89"><enum>(IV)</enum><text>the security practices and testing procedures used in developing and manufacturing covered products in the subset;</text></subclause><subclause id="H00FE8CF40AE941858E1E1FB3E1D9654E"><enum>(V)</enum><text>the level of expertise, qualifications, and professional accreditation of the staff employed by the manufacturers of covered products in the subset who are responsible for cybersecurity of the covered products; and</text></subclause><subclause id="H7E863094157E4C4A8E746193328D94F3"><enum>(VI)</enum><text>any other criteria the Advisory Committee and Secretary determine is necessary and appropriate; and</text></subclause></clause><clause id="H33C84D699D884D269494A12EACBA13BB"><enum>(iii)</enum><text>to the extent possible, incorporate existing cybersecurity and data security benchmarks, such as the baseline of cybersecurity features defined in the document entitled <quote>Core Cybersecurity Feature Baseline for Securable IoT Devices: A Starting Point for IoT Device Manufacturers</quote>, published by the National Institute of Standards and Technology in July 2019, or any successor thereto;</text></clause></subparagraph></paragraph><paragraph id="H4E12CC71DAB54804AD9CA6A113255008"><enum>(2)</enum><text>may not establish any cybersecurity and data security benchmark under paragraph (1) that is arbitrary, capricious, an abuse of discretion, or otherwise not in accordance with law;</text></paragraph><paragraph id="HC1700D64F592456C99B80C1A7D58B617"><enum>(3)</enum><text>shall permit a manufacturer or distributor of a covered product to display a Cyber Shield label reflecting the extent to which the covered product meets the cybersecurity and data security benchmarks established under paragraph (1);</text></paragraph><paragraph id="H53962E333916442A97B8A053EE64A7A5"><enum>(4)</enum><text>shall promote technologies, practices, and policies that—</text><subparagraph id="H6B224030494E49BEA99D602309D9EF59"><enum>(A)</enum><text>are compliant with the cybersecurity and data security benchmarks established under paragraph (1); and</text></subparagraph><subparagraph id="H2ECD17C9361C4B53BBD4C898F85EE0CB"><enum>(B)</enum><text>the Secretary determines are the preferred technologies, practices, and policies in the marketplace for—</text><clause id="HD54B7C382AEA47AA8F5F6E71D5857459"><enum>(i)</enum><text>enhancing cybersecurity;</text></clause><clause id="H0C460E4BF66546A287A06324589210FC"><enum>(ii)</enum><text>ensuring that cybersecurity is incorporated in all aspects of the life cycle of a covered product; and</text></clause><clause id="H740D220C7C1E4FE0BA9DAB89DF48BAB0"><enum>(iii)</enum><text>protecting data;</text></clause></subparagraph></paragraph><paragraph id="H83B18EA77E5E4FD692F543522E4FAB42"><enum>(5)</enum><text>shall work to enhance public awareness of the Cyber Shield label, including through public outreach, education, research and development, and other means;</text></paragraph><paragraph id="HA615D9E59C164318B6B5064A539D2BD3"><enum>(6)</enum><text>shall preserve the integrity of the Cyber Shield label;</text></paragraph><paragraph id="H076C50FA93F9407D9436257FE2E53C23"><enum>(7)</enum><text>if helpful in fulfilling the obligation under paragraph (6), may elect to not treat a covered product as a covered product certified under the Cyber Shield program until the covered product meets appropriate conformity standards, which may include—</text><subparagraph id="H01465F4769A648D4AA65AF1EF2611992"><enum>(A)</enum><text>standards relating to testing by an accredited third-party certifying laboratory or other entity in accordance with the Cyber Shield program; and</text></subparagraph><subparagraph id="HBA471F60A2C6459D85368F86B9A7B0E1"><enum>(B)</enum><text>certification by the laboratory or entity described in subparagraph (A) that the covered product meets the applicable cybersecurity and data security benchmarks established under paragraph (1);</text></subparagraph></paragraph><paragraph id="HDE05E0A13FCA42CFA9EB0AF815BACCDD"><enum>(8)</enum><text>not less frequently than annually after the date on which the Secretary establishes cybersecurity and data security benchmarks for a covered product category under paragraph (1), shall review, and, if appropriate, update the cybersecurity and data security benchmarks, for that covered product category;</text></paragraph><paragraph id="H1C86E4A2893545098A1910B3C6F3BB92"><enum>(9)</enum><text>shall solicit comments from interested parties and the Advisory Committee before establishing or revising a Cyber Shield covered product category or cybersecurity and data security benchmark (or before the effective date of the establishment or revision of a covered product category or cybersecurity and data security benchmark);</text></paragraph><paragraph id="H6EBF950588304ADB8E9223380468D7F2"><enum>(10)</enum><text>upon adoption of a new or revised covered product category or cybersecurity and data security benchmark, shall provide reasonable notice to interested parties of any changes (including effective dates) to covered product categories or cybersecurity and data security benchmarks, along with—</text><subparagraph id="H7221F2B1D67D4A90ADDDE47381357813"><enum>(A)</enum><text>an explanation of the changes; and</text></subparagraph><subparagraph id="H7DF4DE6B3FD549269C492213E80B78E1"><enum>(B)</enum><text>as appropriate, responses to comments submitted by interested parties;</text></subparagraph></paragraph><paragraph id="H15C525A7C6C9482B94709903A8B3BA59"><enum>(11)</enum><text>shall provide appropriate lead time before the applicable effective date for a new or a significant revision to a covered product category or cybersecurity and data security benchmark, taking into account the timing requirements of the manufacturing, marketing, and distribution process for any covered product addressed; and</text></paragraph><paragraph id="HC106771952AA4B49966F75DC372A01F1"><enum>(12)</enum><text>may remove the certification of a covered product as a covered product certified under the Cyber Shield program if the manufacturer of the certified covered product falls out of conformity with the benchmarks established under paragraph (1) for the covered product, as determined by the Secretary.</text></paragraph></subsection><subsection id="H490889E617D34EB3AA37BE0BCE4F6507"><enum>(d)</enum><header>Deadlines</header><text>Not later than 2 years after the date of enactment of this Act, the Secretary shall establish cybersecurity and data security benchmarks for covered products under subsection (c)(1), which shall take effect not later than 60 days after the date on which the Secretary establishes the cybersecurity and data security benchmarks.</text></subsection><subsection id="H00448624B5324CBDA566B56318C33070"><enum>(e)</enum><header>Administration</header><text>The Secretary, in consultation with the Advisory Committee, may enter into a contract with a third party to administer the Cyber Shield program if—</text><paragraph id="HF98F778498544773BE45AA4206C436A7"><enum>(1)</enum><text>the third party is an impartial administrator; and</text></paragraph><paragraph id="HC25AD66116B140EEB023435930EFDD03"><enum>(2)</enum><text>entering into the contract improves the cybersecurity and data security of covered products.</text></paragraph></subsection><subsection id="H1B7DB0D85CA742818E6ED75322ED568A"><enum>(f)</enum><header>Program evaluation</header><paragraph id="H62319E75FAA84DFAA35EB44F29720AAC"><enum>(1)</enum><header>In general</header><text>Not later than 3 years after the date on which the Secretary establishes cybersecurity and data security benchmarks for covered products under subsection (c)(1), and not less frequently than every 3 years thereafter, the Inspector General of the Department of Commerce shall—</text><subparagraph id="HD00D3C645DA74621B7E75CD49CE41F73"><enum>(A)</enum><text>evaluate the Cyber Shield program; and</text></subparagraph><subparagraph id="HD5EC6177142D4A3195D98CC95FE2110F"><enum>(B)</enum><text>submit a report on the results of the evaluation carried out under subparagraph (A) to—</text><clause id="H3F1C28DA590946ACBA628C503075CBCC"><enum>(i)</enum><text>the Committee on Commerce, Science, and Transportation of the Senate; and</text></clause><clause id="H74B207FF0B704F149492DCAE43A9F663"><enum>(ii)</enum><text>the Committee on Energy and Commerce of the House of Representatives.</text></clause></subparagraph></paragraph><paragraph id="H38E989F6E1594429985878E9736E2A4F"><enum>(2)</enum><header>Requirements</header><text>In conducting an evaluation under paragraph (1)(A), the Inspector General of the Department of Commerce shall—</text><subparagraph id="HAD3E8E884B6A43FCAC42F7208B969A0F"><enum>(A)</enum><text>with respect to the cybersecurity and data security benchmarks established under subsection (c)(1)—</text><clause id="H69302E6AA3C842B08F9FB18665311558"><enum>(i)</enum><text>evaluate the extent to which the cybersecurity and data security benchmarks address cybersecurity and data security threats; and</text></clause><clause id="HC23550CAF7A842DEB6DFB6DC3A46318D"><enum>(ii)</enum><text>assess how the cybersecurity and data security benchmarks have evolved to meet emerging cybersecurity and data security threats;</text></clause></subparagraph><subparagraph id="H4E24896DAAB0465E9A26653F89A26341"><enum>(B)</enum><text>conduct covert testing of covered products to evaluate the integrity of certification testing under the Cyber Shield program;</text></subparagraph><subparagraph id="H4DFF2A21634A46BCBB0E3147A6EC287E"><enum>(C)</enum><text>assess the costs to businesses that manufacture covered products of participating in the Cyber Shield program;</text></subparagraph><subparagraph id="H45CD9C5A34E54DBFA5B3DA1E780070DD"><enum>(D)</enum><text>evaluate the level of participation in the Cyber Shield program by businesses that manufacture covered products;</text></subparagraph><subparagraph id="HBE55CB38026C432A8C4F381DC1F69213"><enum>(E)</enum><text>assess the level of public awareness and consumer awareness of the Cyber Shield label;</text></subparagraph><subparagraph id="HB66F67A1E1D242308E66DB86DE60AF9E"><enum>(F)</enum><text>determine whether any private sector or international cybersecurity certification programs comparable to the Cyber Shield program exist; and</text></subparagraph><subparagraph id="HE875495ED7084902B911AB2F47C1D865"><enum>(G)</enum><text>if any private sector or international cybersecurity certification programs described in subparagraph (F) exist, evaluate how each such private sector or international cybersecurity certification program interacts with and compares to the Cyber Shield program.</text></subparagraph></paragraph></subsection><subsection id="H9953CE613185481C8E2F643A0A95201C"><enum>(g)</enum><header>Authorization of appropriations</header><text>There are authorized to be appropriated such sums as may be necessary to carry out this section.</text></subsection></section><section id="H4101959DBEEC4266A032A65889025D28"><enum>5.</enum><header>Cyber shield digital covered product portal</header><subsection id="H7C80EE5C4C59476D93D356FBBE9654B7"><enum>(a)</enum><header>In general</header><text>The Secretary shall make publicly available on the website of the Department of Commerce in a searchable format—</text><paragraph id="H50E294C4442E43B185CEE3A8E4EACD23"><enum>(1)</enum><text>a web page providing information about the Cyber Shield program;</text></paragraph><paragraph id="H86B65A24843148D58807F048D9221839"><enum>(2)</enum><text>a database of covered products certified under the Cyber Shield program; and</text></paragraph><paragraph id="H52495DA639CB40D49B93E9C861DFEA81"><enum>(3)</enum><text>contact information for each manufacturer of a covered product certified under the Cyber Shield program that may be used by consumers to contact the manufacturer regarding questions or complaints.</text></paragraph></subsection><subsection id="HA186D65FA71E42FA88A44448FE7B756A"><enum>(b)</enum><header>Requirements</header><text>The database established under subsection (a)(2) shall include—</text><paragraph id="H80C764F8F50C404ABA9BC4E419D49B57"><enum>(1)</enum><text>the cybersecurity and data security benchmarks established under section 4(c)(1) for each covered product category; and</text></paragraph><paragraph id="H72D9A92767A841E9BD7A0EA93FC3FAAC"><enum>(2)</enum><text>for each covered product certified under the Cyber Shield program—</text><subparagraph id="H596290588AD5411A9D4A4F5C728A6F9C"><enum>(A)</enum><text>the certification for the covered product;</text></subparagraph><subparagraph id="HEDB871EFBCCF49A4A563DFF8E4211B9B"><enum>(B)</enum><text>the name and manufacturer of the covered product;</text></subparagraph><subparagraph id="H5CA597DAF5A34F1DB68B3D975A962F1B"><enum>(C)</enum><text>the contact information for the manufacturer of the covered product;</text></subparagraph><subparagraph id="HABACAF3674614E9A9FE4EE73D284A587"><enum>(D)</enum><text>the functionality of the covered product;</text></subparagraph><subparagraph id="H02497BE7E1374C7C9B38ABF266C8F73B"><enum>(E)</enum><text>the location of any applicable privacy policy; and</text></subparagraph><subparagraph id="H108D1302A4554C75A18861F8FA5BBBB8"><enum>(F)</enum><text>any other information that the Secretary determines to be necessary and appropriate.</text></subparagraph></paragraph></subsection></section><section id="HB31FE18576F442E185068C2924F9CE76"><enum>6.</enum><header>Rule of construction</header><text display-inline="no-display-inline">The decision of a manufacturer of a covered product to not participate in the Cyber Shield program shall not affect the liability of the manufacturer for a cybersecurity or data security breach of that covered product.</text></section></legis-body></bill> 

