<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-BAG21250-HKN-WC-TVS"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>117 S1419 IS: Protecting Critical Boards and Electronics Through Transparency and Enduring Reinvestment Act of 2021</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2021-04-28</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>117th CONGRESS</congress><session>1st Session</session><legis-num>S. 1419</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20210428">April 28, 2021</action-date><action-desc><sponsor name-id="S399">Mr. Hawley</sponsor> introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSAS00">Committee on Armed Services</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To require the Secretary of Defense to support and provide incentives for domestic manufacturing of printed circuit boards, to identify national security risks in printed circuit boards imported from certain foreign countries, and for other purposes.</official-title></form><legis-body><section id="S1" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Protecting Critical Boards and Electronics Through Transparency and Enduring Reinvestment Act of 2021</short-title></quote> or the <quote><short-title>PCBETTER Act of 2021</short-title></quote>. </text></section><section id="id11466caedc1747afb7cca27edc4aec8f"><enum>2.</enum><header>Establishment of Electronics Supply Chain Fund and assistance and incentives for domestic manufacturing of printed circuit boards</header><subsection id="id69e49ea38afa44059836f1b70bf7bc4e"><enum>(a)</enum><header>Establishment of Electronics Supply Chain Fund</header><text>There is established in the Treasury of the United States a trust fund to be known as the <quote>Electronics Supply Chain Fund</quote> (in this section the <quote>Fund</quote>).</text></subsection><subsection id="id4A8FAA0A638A4D269210DE9042413FDB"><enum>(b)</enum><header>Contents of Fund</header><paragraph id="id52912E9016C24F70A6E1D6A0ACE2F706"><enum>(1)</enum><header>In general</header><text>The Fund shall consists of such amounts as may be appropriated for deposit in the Fund.</text></paragraph><paragraph id="ide85e85cf09f84926a5fdb4ed2ce47e84"><enum>(2)</enum><header>Availability</header><subparagraph id="id425f6329a91a4dd986a875c453eb0f75"><enum>(A)</enum><header>In general</header><text>Amounts deposited in the Fund shall remain available through the end of the tenth fiscal year beginning after the date on which funds are first appropriated to the Fund.</text></subparagraph><subparagraph id="id5c63852c073e4a9f9857b548e408a7db"><enum>(B)</enum><header>Remainder to treasury</header><text>Any amounts remaining in the Fund after the date specified in subparagraph (A) shall be deposited in the general fund of the Treasury.</text></subparagraph></paragraph></subsection><subsection id="id716ad2b2e90d4637bcc9160a46be5c76"><enum>(c)</enum><header>Use of fund</header><text>Amounts deposited in the Fund shall be available to the Secretary of Defense—</text><paragraph id="id5b3e54310d2a4a679150138d4c7e38c8"><enum>(1)</enum><text>to fund the construction, expansion, or modernization of facilities to develop or manufacture semiconductors, microelectronics, advanced electronic packaging, and printed circuit boards;</text></paragraph><paragraph id="id32F2D4AB568147ACBAD85EFA72BBB41F"><enum>(2)</enum><text>to carry out subsection (d); and</text></paragraph><paragraph id="id26fe30016d0147ffa65f28b9d13cef7a"><enum>(3)</enum><text>to carry out section 4(a).</text></paragraph></subsection><subsection id="id26b56a6dc0854656b3c2c8f0e1fc8ab5"><enum>(d)</enum><header>Specific activities required</header><text>Using amounts from the Fund, the Secretary of Defense, in consultation with the Secretary of Commerce, the Secretary of Homeland Security, the Director of National Intelligence, and such other officials as the Secretary of Defense considers appropriate, shall—</text><paragraph id="idb97856b8d99a406a86d49576d2d1d81e"><enum>(1)</enum><text>promote and deploy technology, including microelectronics, printed circuit boards, semiconductors, and related technologies so as to create a commercially competitive electronics industry in the United States capable of meeting United States national security needs;</text></paragraph><paragraph id="id0eef9a0f8e2a4b0283cfdb791b37ae11"><enum>(2)</enum><text>establish production and manufacturing sites for the technologies described in paragraph (1); and</text></paragraph><paragraph id="idf60c52a7ab3644b099eae1d172b32004"><enum>(3)</enum><text>establish security standards necessary for the implementation of—</text><subparagraph id="id2e3b0dede0a544aa8238a01e4b8d37bb"><enum>(A)</enum><text>this Act;</text></subparagraph><subparagraph id="id8fcbc9d190b24fd2af0f4a58be41eccb"><enum>(B)</enum><text>section 889 of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 (<external-xref legal-doc="public-law" parsable-cite="pl/115/232">Public Law 115–232</external-xref>; 132 Stat. 1917);</text></subparagraph><subparagraph id="iddf6342fa15524b4dad2e7e70b6eeaff4"><enum>(C)</enum><text>section 224 of the National Defense Authorization Act for Fiscal Year 2020 (<external-xref legal-doc="public-law" parsable-cite="pl/116/92">Public Law 116–92</external-xref>; <external-xref legal-doc="usc" parsable-cite="usc/10/2302">10 U.S.C. 2302</external-xref> note); and</text></subparagraph><subparagraph id="id375c1b3372724297909f752f8ef0aeda"><enum>(D)</enum><text>section 841 of the William M. (Mac) Thornberry National Defense Authorization Act for Fiscal Year 2021 (<external-xref legal-doc="public-law" parsable-cite="pl/116/283">Public Law 116–283</external-xref>).</text></subparagraph></paragraph></subsection><subsection id="id2f12b6925c2a4542bd50f7dc9c468e75"><enum>(e)</enum><header>Printed circuit board manufacturing as qualifying capability</header><text>The Secretary of Defense shall consider printed circuit board manufacturing as a qualifying capability when making funds available for the construction, expansion, or modernization of domestic development or manufacturing capabilities for semiconductors or electronic packaging.</text></subsection></section><section id="ida53a03ec8db141d9961529532f9f9700"><enum>3.</enum><header>Requirement that certain providers of systems to Department of Defense disclose the source of printed circuit boards when sourced from certain countries</header><subsection id="id433c76b6a0d64533ae08e2278c869786"><enum>(a)</enum><header>Disclosure</header><text>The Secretary of Defense shall require any provider of a covered system to provide to the Department of Defense, along with delivery of the covered system, a list of the printed circuit boards in the covered system that includes, for each printed circuit board, an attestation of whether—</text><paragraph id="idb2e1848f375f4f8a8906c29ae605ff15"><enum>(1)</enum><text>the printed circuit board was partially or fully manufactured and assembled in a covered nation;</text></paragraph><paragraph id="id4ed63ccee30d4d7f923efd973c952ef4"><enum>(2)</enum><text>the printed circuit board was fully manufactured and assembled outside of a covered nation; or</text></paragraph><paragraph id="idf764435e9a1040199f5b6fadf7984633"><enum>(3)</enum><text>the provider cannot determine where the printed circuit board was manufactured and assembled.</text></paragraph></subsection><subsection id="idfd8a45616b464dd3adea08fcc16568ff"><enum>(b)</enum><header>Regulations</header><text>Not later than 90 days after the date of the enactment of this Act, the Secretary shall promulgate such regulations as are necessary to carry out this section.</text></subsection><subsection id="id5de0ebc71240442cb5aca391cd99d331"><enum>(c)</enum><header>Definitions</header><text>In this section:</text><paragraph id="id1aed820fc4c44b96bf825b744db5721e"><enum>(1)</enum><text>The term <term>covered nation</term> includes the following:</text><subparagraph id="idbcfb442cf3684c819bc2d4c2744c519f"><enum>(A)</enum><text>The People's Republic of China.</text></subparagraph><subparagraph id="idb1d5c5fc0b9f49d9bb95f358bb96836b"><enum>(B)</enum><text>The Russian Federation.</text></subparagraph><subparagraph id="id59166ea9e71d4951a6b901a36d7ae2cc"><enum>(C)</enum><text>The Democratic People's Republic of North Korea.</text></subparagraph><subparagraph id="idc486f0f378ab4b5eb46f57939816c5ad" commented="no" display-inline="no-display-inline"><enum>(D)</enum><text>The Islamic Republic of Iran. </text></subparagraph></paragraph><paragraph id="id231d5f0ba8974cd39875fe806004f689"><enum>(2)</enum><text>The term <term>covered system</term> means any item, including commercial items and commercially available off-the-shelf items, notwithstanding section 3452 of title 10, United States Code, as redesignated by section 1821(a)(1) of the William M. (Mac) Thornberry National Defense Authorization Act for Fiscal Year 2021 (<external-xref legal-doc="public-law" parsable-cite="pl/116/283">Public Law 116–283</external-xref>), or sections 1906 and 1907 of title 41, United States Code, that— </text><subparagraph id="id392977fdc1564f688aef3b42415f891e"><enum>(A)</enum><text>has an electronic component;</text></subparagraph><subparagraph id="ide28c45b0a9f9451ea9c74e0a1d03ad55"><enum>(B)</enum><text>is provided to the Department of Defense under a contract that exceeds the simplified acquisition threshold; and</text></subparagraph><subparagraph id="idf431f423e5974b22af429a75f54cf07a"><enum>(C)</enum><text>transmits or stores information including—</text><clause id="id77643d2c538648589f991272bf9e412d"><enum>(i)</enum><text>telecommunications;</text></clause><clause id="id7af15b6d0bad44b1bf0a1bc6428742c8"><enum>(ii)</enum><text>data communications and storage, including servers, switches, and networking systems, but excluding personal data storage devices, personal computers, desktop computers, tablets, and handheld equipment;</text></clause><clause id="id00beec957ae74da9902fd9987022959f"><enum>(iii)</enum><text>information technology security systems; and</text></clause><clause id="id2bfc0485e2924c6bbee7efcd5436deef"><enum>(iv)</enum><text>any other system that the Secretary determines should be covered.</text></clause></subparagraph></paragraph><paragraph id="idd881149ae57e45d491b2840473f4f8dc"><enum>(3)</enum><text>The term <term>manufactured and assembled</term>, with respect to a printed circuit board, includes all actions from the printing of the printed circuit board from raw materials to the integration of the completed printed circuit board in an end item or component of an end item.</text></paragraph></subsection></section><section id="id6dbda8e58f744e8fbd2be1601dd85753"><enum>4.</enum><header>Department of Defense testing of vulnerability of systems with printed circuit boards from certain countries and remediation and prevention of such vulnerabilities</header><subsection id="idda34c29c4ffd4782919b808a2fb54fb6"><enum>(a)</enum><header>Testing</header><paragraph id="idbdb671f8f9ac45ad8678af8dacfe87e8"><enum>(1)</enum><header>Program establishment required</header><text>Not later than one year after the date of the enactment of this Act, the Secretary of Defense shall establish a program to test systems owned or operated by the Department of Defense for vulnerabilities to foreign interference, sabotage, espionage, and attack.</text></paragraph><paragraph id="idca9f8821d51240559ec6a6576052477f"><enum>(2)</enum><header>Required testing for certain systems</header><text>Through the program established under paragraph (1), the Secretary shall test each system of the Department that contains at least one printed circuit board for which a disclosure was made pursuant to section 3(a) and an attestation was made with respect to paragraph (1) or (3) of such section.</text></paragraph><paragraph id="idfc8addda4995447cb89f9a3f61cdedf4"><enum>(3)</enum><header>Methods</header><text>The Secretary shall ensure that the program established under paragraph (1) uses, to the maximum extent practicable, best-in-breed testing and detection methods used by commercial industry, including—</text><subparagraph id="id6a6196f9260446e6ab570b006f0f4d5f"><enum>(A)</enum><text>penetration testing;</text></subparagraph><subparagraph id="id43eb957806744997bc5bef05340136f2"><enum>(B)</enum><text>red teaming; and</text></subparagraph><subparagraph id="id712c4f92b5f042b99b463fa5fc0a72c0"><enum>(C)</enum><text>inventory auditing.</text></subparagraph></paragraph></subsection><subsection id="idcb7a5c048e62498e880827f1dc7f35df"><enum>(b)</enum><header>Remediation</header><paragraph id="idbe3934deaea84580804377b11318a242"><enum>(1)</enum><header>Designation</header><text>Whenever informed of a vulnerability in a system under the program established under subsection (a)(1), the Secretary shall designate a senior official of the Department to remediate the vulnerability as soon as practicable.</text></paragraph><paragraph id="idb28eae0e216f437abddbd6eef2d8cf6e"><enum>(2)</enum><header>Requirements</header><text>Remediation under paragraph (1) shall include those measures that the designated official determines necessary to lower the risk to acceptable levels, including—</text><subparagraph id="id6751f0b6e8534b50866f843f8d4de7cd"><enum>(A)</enum><text>adding hardware or software to isolate and contain any malicious printed circuit board;</text></subparagraph><subparagraph id="idb871dd4153784310b12a432b7b550127"><enum>(B)</enum><text>destruction, deactivation, or replacement of the system containing the vulnerability; or</text></subparagraph><subparagraph id="idb8eda4b5183946c3b4e7efd10820095b"><enum>(C)</enum><text>physical modification of the system containing the vulnerability through the insertion of a trusted printed circuit board or other hardware that does not contain known vulnerabilities.</text></subparagraph></paragraph><paragraph id="idad1306a197de444fb5495681eede9789"><enum>(3)</enum><header>Assignment of costs</header><subparagraph id="id420e36abdf3f489a8db06f5b63f73788"><enum>(A)</enum><header>Determination</header><text>Whenever a vulnerability is found in a system from a contractor through the program established under subsection (a)(1), the Secretary of Defense shall determine whether the contractor should reasonably have discovered the vulnerability prior to delivery of the system to the Department.</text></subparagraph><subparagraph id="iddfef2ca9e46340ee8891d98dbbf72501"><enum>(B)</enum><header>Payment by contractor</header><text>If, pursuant to subparagraph (A), the Secretary determines that a contractor should reasonably have discovered the vulnerability prior to delivery to the Department, the Secretary may withhold future payments to the contractor in an amount not to exceed the amount expended by the Department on remediation of the affected system.</text></subparagraph><subparagraph id="idcbc83cddc5034fa1a5c9ec4b752e5513"><enum>(C)</enum><header>Presumption</header><clause id="id5C158DA0511647569ECC1FB0192C3992"><enum>(i)</enum><header>In general</header><text>If the Secretary determines that a vulnerability identified through the program established under subsection (a)(1) is the result of any printed circuit board that the contractor imported from the People’s Republic of China after December 31, 2021, the Secretary shall presume that the contractor reasonably should have discovered the vulnerability prior to delivery to the Department.</text></clause><clause id="id7CA246E78B1F46B196BD07A6FB606633"><enum>(ii)</enum><header>Rebuttal allowed</header><text>The contractor may rebut a presumption under clause (i) with a showing of technical impossibility.</text></clause></subparagraph></paragraph></subsection><subsection id="id3d9953148d334c31a976b02fb2e3e834"><enum>(c)</enum><header>Prevention</header><text>Not later than one year after the date of the enactment of this Act, the Secretary shall promulgate such regulations as the Secretary considers necessary to require contractors selling goods or services to the Department that include printed circuit boards to undertake such due diligence as the Secretary considers appropriate to prevent the occurrence of vulnerabilities in such goods and services, including—</text><paragraph id="idbfef915a5c054589bd422199e94a3cb5"><enum>(1)</enum><text>certification of the ownership, management, and security of subcontractors;</text></paragraph><paragraph id="id31234040ba9b4659bdfedaa33b1ae113"><enum>(2)</enum><text>conducting penetration testing, red teaming exercises, and other simulated attacks against the good or service; and</text></paragraph><paragraph id="idf7a877b6229a4cc89d76464ef3116ca9"><enum>(3)</enum><text>compliance with the Cybersecurity Maturity Model Certification, or successor model certification.</text></paragraph></subsection><subsection id="idf6094e3d56f741b2b0c73c40206285da"><enum>(d)</enum><header>Annual reports</header><paragraph id="id2CD544D7078C433C92BD71568A69485B"><enum>(1)</enum><header>In general</header><text>Not later than December 31 of each year, the Secretary of Defense shall submit to the congressional defense committees a report on the activities carried out under this section during the preceding fiscal year.</text></paragraph><paragraph id="idA410004EBDC24331B60E34E776C91DEC"><enum>(2)</enum><header>Contents</header><text>Each report submitted under paragraph (1) shall include, for the period covered by the report, the following:</text><subparagraph id="idea9b624de4b84b4aab210850421a0568"><enum>(A)</enum><text>The number of systems tested for vulnerabilities.</text></subparagraph><subparagraph id="ideb165e10ee4f4a7f9ecc836950eb992a"><enum>(B)</enum><text>The number of systems identified as having a vulnerability.</text></subparagraph><subparagraph id="idd1fbe76e64ae45b39265585d6c61b8c1"><enum>(C)</enum><text>The number of systems that the Department has yet to test under this section.</text></subparagraph><subparagraph id="id82c5992671304b25a0a674ba6c9c3f19"><enum>(D)</enum><text>The identity of any contractors that have been identified as failing to reasonably discover a vulnerability in a good or service provided to the Department of Defense.</text></subparagraph><subparagraph id="id9760ec6b943d485c89a1d65897782717"><enum>(E)</enum><text>Such other information as the Secretary considers appropriate. </text></subparagraph></paragraph></subsection><subsection id="ida0a0023bca054f6da1fc287402af7776"><enum>(e)</enum><header>Congressional defense committees defined</header><text>In this section, the term <term>congressional defense committees</term> has the meaning given that term in section 101(a) of title 10, United States Code. </text></subsection></section></legis-body></bill> 

