<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" dms-id="H9BAB71C1A8E54497880C120E313A2707" public-private="public" key="H" bill-type="olc"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>118 HR 4462 IH: Election Security Assistance Act</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2023-07-03</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress display="yes">118th CONGRESS</congress><session display="yes">1st Session</session><legis-num display="yes">H. R. 4462</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20230703">July 3, 2023</action-date><action-desc><sponsor name-id="M000194">Ms. Mace</sponsor> introduced the following bill; which was referred to the <committee-name committee-id="HHA00">Committee on House Administration</committee-name>, and in addition to the Committees on <committee-name committee-id="HHM00">Homeland Security</committee-name>, and <committee-name committee-id="HIG00">Intelligence (Permanent Select)</committee-name>, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned</action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To direct the Secretary of Homeland Security and the Director of National Intelligence to submit a joint report on foreign threats to elections in the United States and to establish procedures to test for and monitor cybersecurity vulnerabilities in certain equipment used in the administration of elections for Federal office, and for other purposes.</official-title></form><legis-body id="H512120ACED8D4A2695AB08A2EE5604FB" style="OLC"><section id="HB8585234A10449449F518C472CB9CC3E" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Election Security Assistance Act</short-title></quote>.</text></section><section id="HABDE71425F08435C9616459EEC671B0E" display-inline="no-display-inline" section-type="subsequent-section"><enum>2.</enum><header>Reports to Congress on foreign threats to elections</header><subsection id="HB5C1EC79D0864FEC9739843C5E479448"><enum>(a)</enum><header>In general</header><text>Not later than 30 days after the date of enactment of this Act, and 30 days after the end of each fiscal year thereafter, the Secretary of Homeland Security and the Director of National Intelligence, in coordination with the heads of the appropriate Federal entities, shall submit a joint report to the appropriate congressional committees and the chief State election official of each State on foreign threats to elections in the United States, including physical and cybersecurity threats.</text></subsection><subsection id="HEEB0F332009644E7891B284C5AC9CCE8"><enum>(b)</enum><header>Voluntary participation by States</header><text>The Secretary shall solicit and consider voluntary comments from all State election agencies. Participation by an election agency in the report under this section shall be voluntary and at the discretion of the State.</text></subsection><subsection id="H63669461E20C4B15AB27412D999EEACC"><enum>(c)</enum><header>Appropriate Federal entities</header><text>In this section, the term <term>appropriate Federal entities</term> means—</text><paragraph id="HB956FBEDCD1647FEA3386E68FDAE165C"><enum>(1)</enum><text>the Department of Commerce, including the National Institute of Standards and Technology;</text></paragraph><paragraph id="HBAC4D7F823BD4D2B86CF4E3545A35B1C"><enum>(2)</enum><text>the Department of Defense;</text></paragraph><paragraph id="HF3415A7EBC8A4BABA841A5473F5E23D3"><enum>(3)</enum><text>the Department of Homeland Security, including the component of the Department that reports to the Under Secretary responsible for overseeing critical infrastructure protection, cybersecurity, and other related programs of the Department;</text></paragraph><paragraph id="HFA6E93C04CDE406DB4C9755F8E0E4742"><enum>(4)</enum><text>the Department of Justice, including the Federal Bureau of Investigation;</text></paragraph><paragraph id="HEF7094F6D4214DF6A1B64698E8F3EF96"><enum>(5)</enum><text>the Election Assistance Commission; and</text></paragraph><paragraph id="H38F6D9C3A8F64F5EB2BE760A03E55485"><enum>(6)</enum><text>the Office of the Director of National Intelligence, the National Security Agency, and such other elements of the intelligence community (as defined in section 3 of the National Security Act of 1947 (<external-xref legal-doc="usc" parsable-cite="usc/50/3003">50 U.S.C. 3003</external-xref>)) as the Director of National Intelligence determines are appropriate.</text></paragraph></subsection><subsection id="H4FC68B4567AD4FA4BBCD95801E6C1FB8"><enum>(d)</enum><header>Other definitions</header><text>In this section—</text><paragraph display-inline="no-display-inline" id="HB260FF315AE94B91898201F7F8CAD0C8"><enum>(1)</enum><text display-inline="yes-display-inline">the term <term>appropriate congressional committees</term> means—</text><subparagraph id="HE5A5306A54954F82A7406B1C9514CFEE"><enum>(A)</enum><text>the Committee on Rules and Administration, the Committee on Homeland Security and Governmental Affairs, the Select Committee on Intelligence, and the Committee on Foreign Relations of the Senate; and</text></subparagraph><subparagraph id="HBB2A6AEA61EA428F911F92913CEB5E6E"><enum>(B)</enum><text display-inline="yes-display-inline">the Committee on House Administration, the Committee on Homeland Security, the Permanent Select Committee on Intelligence, and the Committee on Foreign Affairs of the House of Representatives;</text></subparagraph></paragraph><paragraph id="HA6D5624770394F0BA2040BCB52C02FCC"><enum>(2)</enum><text>the term <term>chief State election official</term> means, with respect to a State, the individual designated by the State under section 10 of the National Voter Registration Act of 1993 (<external-xref legal-doc="usc" parsable-cite="usc/52/20509">52 U.S.C. 20509</external-xref>) to be responsible for coordination of the State’s responsibilities under such Act;</text></paragraph><paragraph id="HEBEBB16A63B6459191976457FC406DCA"><enum>(3)</enum><text display-inline="yes-display-inline">the term <term>election agency</term> means any component of a State or any component of a unit of local government of a State that is responsible for administering Federal elections;</text></paragraph><paragraph id="HF1E75B1391734ED1939665D9283BA39F"><enum>(4)</enum><text>the term <term>Secretary</term> means the Secretary of Homeland Security; and</text></paragraph><paragraph id="H5DDEA02B3EC243CE9EB8C856C47CC5A2"><enum>(5)</enum><text display-inline="yes-display-inline">the term <term>State</term> has the meaning given such term in section 901 of the Help America Vote Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/52/21141">52 U.S.C. 21141</external-xref>).</text></paragraph></subsection></section><section id="H1F9270F3EC9C458DA51E5A5598B2BA95"><enum>3.</enum><header>Process to test for and monitor cybersecurity vulnerabilities in election equipment</header><subsection id="HE677EDFED4FC40448E29F03DB6F59758" commented="no"><enum>(a)</enum><header>Process for covered voting systems</header><paragraph id="H0502A85BEC42445FA223B56971F42913"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">The Director of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security and the Election Assistance Commission (in consultation with the Technical Guidelines Development Committee and the Standards Board of the Commission), shall jointly establish a voluntary process to test for and monitor covered voting systems for cybersecurity vulnerabilities. Such process shall include the following:</text><subparagraph id="HC68D7907AB104A87A268A38164E2C359" commented="no"><enum>(A)</enum><text>Mitigation strategies and other remedies.</text></subparagraph><subparagraph id="HBF113F04141F418EB7BC8EE9491C4C66" commented="no"><enum>(B)</enum><text display-inline="yes-display-inline">Notice to the Commission and appropriate entities of the results of testing conducted pursuant to such process.</text></subparagraph></paragraph><paragraph id="H9A3FB403F05C4A6DA2DF75CF4BC6843B"><enum>(2)</enum><header>Implementation</header><text>The Director shall implement the process established under paragraph (1) at the request of the Commission.</text></paragraph></subsection><subsection id="H56AC7C96031440D98EA739F2A136491A"><enum>(b)</enum><header>Labeling for voting systems</header><text display-inline="yes-display-inline">The Commission (in consultation with the Technical Guidelines Development Committee and the Standards Board of the Commission), shall establish a process to provide for the deployment of appropriate labeling available through the website of the Commission to indicate that covered voting systems passed the most recent cybersecurity testing pursuant to the process established under subsection (a).</text></subsection><subsection id="HFD0DDD806E014B0FA18FC2F32BC1B61C"><enum>(c)</enum><header>Rules of construction</header><text display-inline="yes-display-inline">The process established under subsection (a), including the results of any testing carried out pursuant to this section, shall not affect—</text><paragraph id="H538CE80D8FBC421E8747A5E0E8906EEC"><enum>(1)</enum><text>the certification status of equipment used in the administration of an election for Federal office under the Help America Vote Act of 2002; or</text></paragraph><paragraph id="H369FF55CC40A41F09CB49B4FA7190D35"><enum>(2)</enum><text>the authority of the Commission to so certify such equipment under such Act.</text></paragraph></subsection><subsection id="HAC72F930D1FC460F9069B700F0B25A7F"><enum>(d)</enum><header>Definition</header><text display-inline="yes-display-inline">In this section, the term <term>covered voting systems</term> means equipment used in the administration of an election for Federal office that is certified in accordance with versions of Voluntary Voting System Guidelines under the Help America Vote Act of 2002 under which such equipment is not required to be tested for cybersecurity vulnerabilities.</text></subsection></section><section id="HB2AAF12294E24EAA9A923822A65707C0" display-inline="no-display-inline" section-type="subsequent-section"><enum>4.</enum><header>Duty of Secretary of Homeland Security to notify State and local officials of election cybersecurity incidents</header><subsection id="H8DBC846C60CA48759DED4D32F5F5C648"><enum>(a)</enum><header>Duty To share information with Department of Homeland Security</header><text display-inline="yes-display-inline">If a Federal entity receives information about an election cybersecurity incident, the Federal entity shall promptly share that information with the Department of Homeland Security, unless the head of the entity (or a Senate-confirmed official designated by the head) makes a specific determination in writing that there is good cause to withhold the particular information.</text></subsection><subsection id="H32D98E83EC3C4910954EE8ECE3BA8615"><enum>(b)</enum><header>Response to receipt of information by Secretary of Homeland Security</header><paragraph id="H5DFB39521FC74FE8A17D0BD1635380D3"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">Upon receiving information about an election cybersecurity incident under subsection (a), the Secretary of Homeland Security, in consultation with the Attorney General, the Director of the Federal Bureau of Investigation, and the Director of National Intelligence, shall promptly (but in no case later than 96 hours after receiving the information) review the information and make a determination whether each of the following apply:</text><subparagraph id="H8F0297E965434C9889C06D9361CB23DE"><enum>(A)</enum><text>There is credible evidence that the incident occurred.</text></subparagraph><subparagraph id="H9F47A8BE4A794A58B65F4F092AC98C3E"><enum>(B)</enum><text>There is a basis to believe that the incident resulted, could have resulted, or could result in voter information systems or voter tabulation systems being altered or otherwise affected.</text></subparagraph></paragraph><paragraph id="HECAD0B42F45745FEAD951B8695803C81"><enum>(2)</enum><header>Duty to notify State and local officials</header><subparagraph id="HAE224A39BF504128AF318DA08C7F4F64"><enum>(A)</enum><header>Duty described</header><text>If the Secretary makes a determination under paragraph (1) that subparagraphs (A) and (B) of such paragraph apply with respect to an election cybersecurity incident, not later than 96 hours after making the determination, the Secretary shall provide a notification of the incident to each of the following:</text><clause id="H0C9FD98EB62B49548657F6D622C461F6"><enum>(i)</enum><text>The chief executive of the State involved.</text></clause><clause id="H07D7EA22CA15485994D58A4A2890525A"><enum>(ii)</enum><text>The State election official of the State involved.</text></clause><clause id="H0107975BE90E4801A38BDFA3FBBA8169"><enum>(iii)</enum><text>The local election official of the election agency involved.</text></clause></subparagraph><subparagraph id="HF9FBCE1A682449828363D50119462344"><enum>(B)</enum><header>Treatment of classified information</header><clause id="HED296B7B694741A599019FE6467EFF5F"><enum>(i)</enum><header>Efforts to avoid inclusion of classified information</header><text display-inline="yes-display-inline">In preparing a notification provided under this paragraph to an individual described in clause (i), (ii), or (iii) of subparagraph (A), the Secretary shall attempt to avoid the inclusion of classified information.</text></clause><clause id="H536E9B79391E4D188A46E361C5D2B6A8"><enum>(ii)</enum><header>Providing guidance to State and local officials</header><text display-inline="yes-display-inline">To the extent that a notification provided under this paragraph to an individual described in clause (i), (ii), or (iii) of subparagraph (A) includes classified information, the Secretary (in consultation with the Attorney General and the Director of National Intelligence) shall indicate in the notification which information is classified.</text></clause></subparagraph></paragraph><paragraph id="H359B67B96FB64D9ABA3A22AD78E7C14D"><enum>(3)</enum><header>Exception</header><subparagraph id="H43A2A77D662B4D0FA4156547385B84D6"><enum>(A)</enum><header>In general</header><text display-inline="yes-display-inline">If the Secretary, in consultation with the Attorney General and the Director of National Intelligence, makes a determination that it is not possible to provide a notification under paragraph (1) with respect to an election cybersecurity incident without compromising intelligence methods or sources or interfering with an ongoing investigation, the Secretary shall not provide the notification under such paragraph.</text></subparagraph><subparagraph id="H2FF7B41B3C1B484582DBB25DD32EBEA7"><enum>(B)</enum><header>Ongoing review</header><text display-inline="yes-display-inline">Not later than 30 days after making a determination under subparagraph (A) and every 30 days thereafter, the Secretary shall review the determination. If, after reviewing the determination, the Secretary makes a revised determination that it is possible to provide a notification under paragraph (2) without compromising intelligence methods or sources or interfering with an ongoing investigation, the Secretary shall provide the notification under paragraph (2) not later than 96 hours after making such revised determination.</text></subparagraph></paragraph><paragraph id="H5D155C720D064ECFB633D410E720888C"><enum>(4)</enum><header>Coordination with Election Assistance Commission</header><text display-inline="yes-display-inline">The Secretary shall make determinations and provide notifications under this subsection in the same manner, and subject to the same terms and conditions relating to the role of the Election Assistance Commission, in which the Director of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security makes determinations as to the necessity of an advisory and the issuance of an advisory under section 3(a) and the provision of notification under section 3(b).</text></paragraph></subsection><subsection id="HF3530216CA1A41AB81B43AD6AA5E5652"><enum>(c)</enum><header>Definitions</header><text>In this section, the following definitions apply:</text><paragraph id="H8DA25D41F99044FE8AC467F7252A2BB9"><enum>(1)</enum><header>Election agency</header><text display-inline="yes-display-inline">The term <term>election agency</term> means any component of a State, or any component of a unit of local government in a State, which is responsible for the administration of elections for Federal office in the State.</text></paragraph><paragraph commented="no" id="H3641EFA2AE54491EBDC8DF4E764D7876"><enum>(2)</enum><header>Election cybersecurity incident</header><text display-inline="yes-display-inline">The term <term>election cybersecurity incident</term> means an occurrence that actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information on an information system of election infrastructure (including a vote tabulation system), or actually or imminently jeopardizes, without lawful authority, such an information system of election infrastructure.</text></paragraph><paragraph id="H9DD1AD646FC24DDEA4A78994ADD670DF"><enum>(3)</enum><header>Federal election</header><text display-inline="yes-display-inline">The term <term>Federal election</term> means any election (as defined in section 301(1) of the Federal Election Campaign Act of 1971 (<external-xref legal-doc="usc" parsable-cite="usc/52/30101">52 U.S.C. 30101(1)</external-xref>)) for Federal office (as defined in section 301(3) of the Federal Election Campaign Act of 1971 (<external-xref legal-doc="usc" parsable-cite="usc/52/30101">52 U.S.C. 30101(3)</external-xref>)).</text></paragraph><paragraph id="H16033A7A345544ECB8ABC1B366457AD9"><enum>(4)</enum><header>Federal entity</header><text>The term <term>Federal entity</term> means any agency (as defined in section 551 of title 5, United States Code).</text></paragraph><paragraph id="H3F986DAEBD944B14B99ED667815967CE"><enum>(5)</enum><header>Local election official</header><text display-inline="yes-display-inline">The term <term>local election official</term> means the chief election official of a component of a unit of local government of a State that is responsible for administering Federal elections.</text></paragraph><paragraph id="HC575415A3C8F4AC9B55D47AB9D44C195"><enum>(6)</enum><header>Secretary</header><text>The term <term>Secretary</term> means the Secretary of Homeland Security.</text></paragraph><paragraph id="H7E5951941F6F4BCBA0CB24ED977B5CC6"><enum>(7)</enum><header>State</header><text display-inline="yes-display-inline">The term <term>State</term> means each of the several States, the District of Columbia, the Commonwealth of Puerto Rico, Guam, American Samoa, the Commonwealth of Northern Mariana Islands, and the United States Virgin Islands.</text></paragraph><paragraph id="HB34F87C6868444B39943D17DEFFE3AD6"><enum>(8)</enum><header>State election official</header><text>The term <term>State election official</term> means—</text><subparagraph id="H23172B76B9E74F8C8C21C21E0CEFC362"><enum>(A)</enum><text display-inline="yes-display-inline">the chief State election official of a State designated under section 10 of the National Voter Registration Act of 1993 (<external-xref legal-doc="usc" parsable-cite="usc/52/20509">52 U.S.C. 20509</external-xref>); or</text></subparagraph><subparagraph id="H2DD00BAC57A64E299D303E1196517376"><enum>(B)</enum><text>in the case of Puerto Rico, Guam, American Samoa, the Northern Mariana Islands, and the United States Virgin Islands, a chief State election official designated by the State for purposes of this Act.</text></subparagraph></paragraph></subsection><subsection id="H74B9D3CA04954CEA94D5E9710AE360C4"><enum>(d)</enum><header>Effective date</header><text display-inline="yes-display-inline">This section shall apply with respect to information about an election cybersecurity incident which is received on or after the date of the enactment of this Act.</text></subsection></section><section id="H68FE4772C74247BFB8D6C583E4EC0EFA"><enum>5.</enum><header>Rule of construction</header><text display-inline="no-display-inline">Nothing in this Act may be construed as authorizing the Secretary of Homeland Security to carry out the administration of an election for Federal office.</text></section></legis-body></bill> 

