<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Reported-in-House" dms-id="H1466658D75054689ABEF7C58E517319A" public-private="public" key="H" bill-type="olc"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>117 HR 4611 RH: DHS Software Supply Chain Risk Management Act of 2021</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2021-07-21</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">IB</distribution-code><calendar display="yes">Union Calendar No. 85</calendar><congress display="yes">117th CONGRESS</congress><session display="yes">1st Session</session><legis-num display="yes">H. R. 4611</legis-num><associated-doc role="report" display="yes">[Report No. 117–120]</associated-doc><current-chamber display="yes">IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20210721">July 21, 2021</action-date><action-desc><sponsor name-id="T000486">Mr. Torres of New York</sponsor> (for himself and <cosponsor name-id="G000597">Mr. Garbarino</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HHM00" added-display-style="italic" deleted-display-style="strikethrough">Committee on Homeland Security</committee-name></action-desc></action><action><action-date>September 14, 2021</action-date><action-desc>Reported with an amendment, committed to the Committee of the Whole House on the State of the Union, and ordered to be printed</action-desc><action-instruction>Strike out all after the enacting clause and insert the part printed in italic</action-instruction><action-instruction>For text of introduced bill, see copy of bill as introduced on July 21, 2021</action-instruction></action><action display="yes"><action-desc display="yes"><pagebreak></pagebreak></action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To direct the Secretary of Homeland Security to issue guidance with respect to certain information and communications technology or services contracts, and for other purposes.<pagebreak></pagebreak></official-title></form><legis-body display-enacting-clause="yes-display-enacting-clause" changed="added" style="OLC" committee-id="HHM00" reported-display-style="italic" id="HD3330428A3154BB48E287215A6CF244A"><section id="H593A5D0340C54E8794BECE0C083380A5" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>DHS Software Supply Chain Risk Management Act of 2021</short-title></quote>.</text></section><section id="H946CB4F760964AB48D5BB263A12E4729"><enum>2.</enum><header>Department of Homeland Security guidance with respect to certain information and communications technology or services contracts</header><subsection id="H47588AF82C684762BB37FFE85B9944F3"><enum>(a)</enum><header>Guidance</header><text display-inline="yes-display-inline">The Secretary of Homeland Security, acting through the Under Secretary, shall issue guidance with respect to new and existing covered contracts.</text></subsection><subsection id="H599CBDFE6F694918B4E000EFED6E2365"><enum>(b)</enum><header>New covered contracts</header><text>In developing guidance under subsection (a), with respect to each new covered contract, as a condition on the award of such a contract, each contractor responding to a solicitation for such a contract shall submit to the covered officer—</text><paragraph id="H19BB965551334CD080A7751612E3330F"><enum>(1)</enum><text>a planned bill of materials when submitting a bid proposal; and</text></paragraph><paragraph id="H1B5B70EEC36A46358793526EE9B3F1E8"><enum>(2)</enum><text>the certification and notifications described in subsection (e).</text></paragraph></subsection><subsection id="H32047BF38B144F7FB9C1E45856CD0B47"><enum>(c)</enum><header>Existing covered contracts</header><text>In developing guidance under subsection (a), with respect to each existing covered contract, each contractor with an existing covered contract shall submit to the covered officer—</text><paragraph id="HF3A552A8284C49D586FAEB82C03B13EA"><enum>(1)</enum><text>the bill of materials used for such contract, upon the request of such officer; and</text></paragraph><paragraph id="H469115DFE0C94A98A99CAF8643973985"><enum>(2)</enum><text>the certification and notifications described in subsection (e).</text></paragraph></subsection><subsection id="HB1695F1622814034B79D748AB57163D9"><enum>(d)</enum><header>Updating bill of materials</header><text>With respect to a covered contract, in the case of a change to the information included in a bill of materials submitted pursuant to subsections (b)(1) and (c)(1), each contractor shall submit to the covered officer the update to such bill of materials, in a timely manner. </text></subsection><subsection id="HDDA0055FDB124047A7019E6EFFE2AADA"><enum>(e)</enum><header>Certification and notifications</header><text>The certification and notifications referred to in subsections (b)(2) and (c)(2), with respect to a covered contract, are the following:</text><paragraph id="H3A179BBAF38F48F58581867D0C62756C" display-inline="no-display-inline"><enum>(1)</enum><text display-inline="yes-display-inline">A certification that each item listed on the submitted bill of materials is free from all known vulnerabilities or defects affecting the security of the end product or service identified in—</text><subparagraph id="H96AF99EAD2EB41F0AAACD4E2C7EB38ED"><enum>(A)</enum><text>the National Institute of Standards and Technology National Vulnerability Database; and</text></subparagraph><subparagraph id="H4FEEA8071235421197D65D2F4A588AD8"><enum>(B)</enum><text display-inline="yes-display-inline">any database designated by the Under Secretary, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency, that tracks security vulnerabilities and defects in open source or third-party developed software.</text></subparagraph></paragraph><paragraph id="HBBF0D13976714FC9ACEA6D8E8733938F"><enum>(2)</enum><text>A notification of each vulnerability or defect affecting the security of the end product or service, if identified, through—</text><subparagraph id="HB57B6B8899BD486C986C22B55502FCB9"><enum>(A)</enum><text display-inline="yes-display-inline">the certification of such submitted bill of materials required under paragraph (1); or</text></subparagraph><subparagraph id="H751ACD2DFDB641B9885C01EB44D0307A"><enum>(B)</enum><text>any other manner of identification.</text></subparagraph></paragraph><paragraph id="H6F2A09DB6645427581545E71E14B198B"><enum>(3)</enum><text display-inline="yes-display-inline">A notification relating to the plan to mitigate, repair, or resolve each security vulnerability or defect listed in the notification required under paragraph (2).</text></paragraph></subsection><subsection id="HC7797B3596BD48A3AA893FC54B21862B"><enum>(f)</enum><header>Enforcement</header><text display-inline="yes-display-inline">In developing guidance under subsection (a), the Secretary shall instruct covered officers with respect to—</text><paragraph id="HCE97A86E94EB4322859E1B05BD7602D8"><enum>(1)</enum><text>the processes available to such officers enforcing subsections (b) and (c); and</text></paragraph><paragraph id="HBB49C3164536468799A4DE1508EC8D3E"><enum>(2)</enum><text>when such processes should be used.</text></paragraph></subsection><subsection id="H144EA114DF64497A920C115BC3A59CC9"><enum>(g)</enum><header>Effective date</header><text>The guidance required under subsection (a) shall take effect on the date that is 180 days after the date of the enactment of this section.</text></subsection><subsection id="H163420E3A0F4478DAE298464C6E3A4E3"><enum>(h)</enum><header>GAO report</header><text display-inline="yes-display-inline">Not later than 1 year after the date of the enactment of this Act, the Comptroller General of the United States shall submit to the Secretary, the Committee on Homeland Security of the House of Representatives, and the Committee on Homeland Security and Governmental Affairs of the Senate a report that includes—</text><paragraph id="H1CF69721CF8F4E50838467F141798F66"><enum>(1)</enum><text>a review of the implementation of this section;</text></paragraph><paragraph id="HD0759FA0409F45A08F78A26221B25A9E"><enum>(2)</enum><text>information relating to the engagement of the Department of Homeland Security with industry; </text></paragraph><paragraph id="HC74E662921BF4560854586BF82DB2007"><enum>(3)</enum><text display-inline="yes-display-inline">an assessment of how the guidance issued pursuant to subsection (a) complies with Executive Order 14208 (86 Fed. Reg. 26633; relating to improving the nation’s cybersecurity); and</text></paragraph><paragraph id="H54045E8B0E1B46AFB42D7C8C88A9C844"><enum>(4)</enum><text display-inline="yes-display-inline">any recommendations relating to improving the supply chain with respect to covered contracts. </text></paragraph></subsection><subsection id="H9CC6D6B2707142158CEDBF3DE69423FA"><enum>(i)</enum><header>Definitions</header><text>In this section:</text><paragraph id="H90BEC583549B49F2B1ED61B6FC95B33C"><enum>(1)</enum><header>Bill of materials</header><text display-inline="yes-display-inline">The term <quote>bill of materials</quote> means a list of the parts and components (whether new or reused) of an end product or service, including, with respect to each part and component, information relating to the origin, composition, integrity, and any other information as determined appropriate by the Under Secretary.</text></paragraph><paragraph id="H29AFF16B64134C1FB7B349F13E724CF8"><enum>(2)</enum><header>Covered contract</header><text display-inline="yes-display-inline">The term <quote>covered contract</quote> means a contract relating to the procurement of covered information and communications technology or services for the Department of Homeland Security.</text></paragraph><paragraph id="H81DA674431E9427B9A5B2BB108122B79" commented="no"><enum>(3)</enum><header>Covered information and communications technology or services</header><text display-inline="yes-display-inline">The term <quote>covered information and communications technology or services</quote> means the terms—</text><subparagraph id="H94EF31F6ED6640CE9AA82FD73ABBA7E7"><enum>(A)</enum><text><quote>information technology</quote> (as such term is defined in section 11101(6) of title 40, United States Code);</text></subparagraph><subparagraph id="H184F499737EE4125A752C15651865EAB"><enum>(B)</enum><text><quote>information system</quote> (as such term is defined in section 3502(8) of title 44, United States Code);</text></subparagraph><subparagraph id="H15B7C68246954816868731AD63E849B9"><enum>(C)</enum><text><quote>telecommunications equipment</quote> (as such term is defined in section 3(52) of the Communications Act of 1934 (<external-xref legal-doc="usc" parsable-cite="usc/47/153">47 U.S.C. 153(52)</external-xref>)); and</text></subparagraph><subparagraph id="H4B318E17DC584DA0BC814CDE1D3D8289"><enum>(D)</enum><text><quote>telecommunications service</quote> (as such term is defined in section 3(53) of the Communications Act of 1934 (<external-xref legal-doc="usc" parsable-cite="usc/47/153">47 U.S.C. 153(53)</external-xref>)).</text></subparagraph></paragraph><paragraph id="H3704220D4DE64B78A1D9A4016E962F4E"><enum>(4)</enum><header>Covered officer</header><text display-inline="yes-display-inline">The term <quote>covered officer</quote> means—</text><subparagraph id="H6DB0483BF76E4D44A6F1CBE61B9920A1"><enum>(A)</enum><text>a contracting officer of the Department; and</text></subparagraph><subparagraph id="HBF70BAF7E73E47A0BCA339F79987E841"><enum>(B)</enum><text display-inline="yes-display-inline">any other official of the Department as determined appropriate by the Under Secretary.</text></subparagraph></paragraph><paragraph id="H3F22B3E668224926BE48384966A535CE"><enum>(5)</enum><header>Software</header><text display-inline="yes-display-inline">The term <quote>software</quote> means computer programs and associated data that may be dynamically written or modified during execution.</text></paragraph><paragraph id="H5E027E1074824FEE983905B857D385E2"><enum>(6)</enum><header>Under Secretary</header><text display-inline="yes-display-inline">The term <quote>Under Secretary</quote> means the Under Secretary for Management of the Department of Homeland Security.</text></paragraph></subsection></section></legis-body><endorsement display="yes"><action-date>September 14, 2021</action-date><action-desc>Reported with an amendment, committed to the Committee of the Whole House on the State of the Union, and ordered to be printed</action-desc></endorsement></bill> 

