<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" dms-id="H6D6A03A8D5A04EEAADBA99F1F17C073F" public-private="public" key="H" bill-type="olc"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>113 HR 5218 IH: Federal Data Center Enhancement Act of 2023</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2023-08-15</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress display="yes">118th CONGRESS</congress><session display="yes">1st Session</session><legis-num display="yes">H. R. 5218</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20230815">August 15, 2023</action-date><action-desc><sponsor name-id="N000191">Mr. Neguse</sponsor> (for himself and <cosponsor name-id="L000598">Mr. LaLota</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HGO00">Committee on Oversight and Accountability</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To amend the Carl Levin and Howard P. <quote>Buck</quote> McKeon National Defense Authorization Act for Fiscal Year 2015 to modify requirements relating to data centers of certain Federal agencies, and for other purposes.</official-title></form><legis-body id="H2207282F56074A9E92FD0B886F684E5A" style="OLC"><section section-type="section-one" id="H5C53D7FB2FC5469F80367AF0C8F2960D"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Federal Data Center Enhancement Act of 2023</short-title></quote>.</text></section><section id="H7F9B787FBFF64D8C97E58375A4083E97"><enum>2.</enum><header>Federal Data Center Consolidation Initiative Amendments</header><subsection id="H4C969288A4F644C5B9F51D83A3C1299B"><enum>(a)</enum><header>Findings</header><text>Congress finds the following:</text><paragraph id="HE4691A273F9E487A9165B471E579A512"><enum>(1)</enum><text>The statutory authorization for the Federal Data Center Optimization Initiative under section 834 of the Carl Levin and Howard P. <quote>Buck</quote> McKeon National Defense Authorization Act for Fiscal Year 2015 (<external-xref legal-doc="usc" parsable-cite="usc/44/3601">44 U.S.C. 3601</external-xref> note; <external-xref legal-doc="public-law" parsable-cite="pl/113/291">Public Law 113–291</external-xref>) expires at the end of fiscal year 2022.</text></paragraph><paragraph id="H2BF8121D80AF4225B3549740D05D32CC"><enum>(2)</enum><text>The expiration of the authorization described in paragraph (1) presents Congress with an opportunity to review the objectives of the Federal Data Center Optimization Initiative to ensure that the initiative is meeting the current needs of the Federal Government.</text></paragraph><paragraph id="HF30BF6B90F734CC898814DEB38D1FCE6"><enum>(3)</enum><text>The initial focus of the Federal Data Center Optimization Initiative, which was to consolidate data centers and create new efficiencies, has resulted in, since 2010—</text><subparagraph id="HC728AA72B4AC4903BCF850246A8812F1"><enum>(A)</enum><text>the consolidation of more than 6,000 Federal data centers; and</text></subparagraph><subparagraph id="H39655FF745CA46159E79EFB5F46597B2"><enum>(B)</enum><text>cost savings and avoidance of $5,800,000,000.</text></subparagraph></paragraph><paragraph id="H462584B6D9F74E82A43D91B028D11474"><enum>(4)</enum><text>The need of the Federal Government for access to data and data processing systems has evolved since the date of enactment in 2014 of subtitle D of title VIII of the Carl Levin and Howard P. <quote>Buck</quote> McKeon National Defense Authorization Act for Fiscal Year 2015.</text></paragraph><paragraph id="HFB91B3DC175D4ED290619325F9EA018B"><enum>(5)</enum><text>Federal agencies and employees involved in mission critical functions increasingly need reliable access to secure, reliable, sustainable, and protected facilities to house mission critical data and data operations to meet the immediate needs of the people of the United States.</text></paragraph><paragraph id="HEF6186D81AE24BB983DC8068FD18D949"><enum>(6)</enum><text>As of the date of enactment of this Act, there is a growing need for Federal agencies to use data centers and cloud applications that meet high standards for cybersecurity, resiliency, availability, and sustainability.</text></paragraph></subsection><subsection id="H13DEE41839E34C3EBF77CF4CDCC86EAE"><enum>(b)</enum><header>Minimum requirements for new data centers</header><text>Section 834 of the Carl Levin and Howard P. <quote>Buck</quote> McKeon National Defense Authorization Act for Fiscal Year 2015 (<external-xref legal-doc="usc" parsable-cite="usc/44/3601">44 U.S.C. 3601</external-xref> note; <external-xref legal-doc="public-law" parsable-cite="pl/113/291">Public Law 113–291</external-xref>) is amended—</text><paragraph id="HD761297537E54015969E7E9802E3F9C6"><enum>(1)</enum><text>in subsection (a), by striking paragraphs (3) and (4) and inserting the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="H7FC217DA382646558ADB01F8AFE1302A"><paragraph id="H618268AD05374CCDB52DF9EA49D7DBFD"><enum>(3)</enum><header>New data center</header><text>The term <term>new data center</term> means—</text><subparagraph id="HC98A7E2D888F48AF922ACE8C634485F0"><enum>(A)</enum><clause commented="no" display-inline="yes-display-inline" id="HA3CAFE40C23C4852B410650C8265FC3D"><enum>(i)</enum><text>a data center or a portion thereof that is owned, operated, or maintained by a covered agency; or </text></clause><clause id="H11994AE8B76644A8804426561CC41532" indent="up1"><enum>(ii)</enum><text>to the extent practicable, a data center or portion thereof—</text><subclause id="H986A6F67A1934431B5045A70BD4FD13B"><enum>(I)</enum><text>that is owned, operated, or maintained by a contractor on behalf of a covered agency on the date on which the contract between the covered agency and the contractor expires; and</text></subclause><subclause id="H31F1A7A0677243ADB8C2FFD7CF2343C4"><enum>(II)</enum><text>with respect to which the covered agency extends the contract, or enters into a new contract, with the contractor; and</text></subclause></clause></subparagraph><subparagraph id="H71EAF43EB8CC4880BC53CBB203A3D6FD"><enum>(B)</enum><text>on or after the date that is 180 days after the date of enactment of the <short-title>Federal Data Center Enhancement Act of 2023</short-title>, a data center or portion thereof that is—</text><clause id="HBB2C31003A6A4F4CA74FADBEA6A305CD"><enum>(i)</enum><text>established; or</text></clause><clause id="HB9FBE99EA864469885BB38A525C022B8"><enum>(ii)</enum><text>substantially upgraded or expanded.</text></clause></subparagraph></paragraph><after-quoted-block>;</after-quoted-block></quoted-block></paragraph><paragraph id="H9F10A7535A334EEF8E29970FD9A6B87B"><enum>(2)</enum><text>by striking subsection (b) and inserting the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="H6A124C1B2D7C4F73948F4587094A2929"><subsection id="H1FCAA2E4D04A475AAE837D8B0C174C36"><enum>(b)</enum><header>Minimum requirements for new data centers</header><paragraph id="H571C7BE980BF4942BD36C753B697EBF2"><enum>(1)</enum><header>In general</header><text>Not later than 180 days after the date of enactment of the <short-title>Federal Data Center Enhancement Act of 2023</short-title>, the Administrator shall establish minimum requirements for new data centers in consultation with the Administrator of General Services and the Federal Chief Information Officers Council.</text></paragraph><paragraph id="H4E72D06734AC47CCA39B348A50AE1A3A"><enum>(2)</enum><header>Contents</header><subparagraph id="HF0477B205C9F4315AF261F7F555D5DAE"><enum>(A)</enum><header>In general</header><text>The minimum requirements established under paragraph (1) shall include requirements relating to—</text><clause id="HE2AE7653EFFB4662B98AFC84BA65A868"><enum>(i)</enum><text>the availability of new data centers;</text></clause><clause id="HCB48D3FCE13F45C09388437992E3CD5F"><enum>(ii)</enum><text>the use of new data centers;</text></clause><clause id="H6E1C10AF0305490D85F9A3A7E6403A8D"><enum>(iii)</enum><text>the use of sustainable energy sources;</text></clause><clause id="H7F604D0478FF4286A0CBB761AD36A4B0"><enum>(iv)</enum><text>uptime percentage;</text></clause><clause id="H9070873600F0481D9363975BFF1CE672"><enum>(v)</enum><text>protections against power failures, including on-site energy generation and access to multiple transmission paths;</text></clause><clause id="H4FF7E8FEBDBF4304BF4FEE352D5A96E0"><enum>(vi)</enum><text>protections against physical intrusions and natural disasters;</text></clause><clause id="H56433D3CF0E94BA0A9DC97F9406DFBC5"><enum>(vii)</enum><text>information security protections required by subchapter II of <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/35">chapter 35</external-xref> of title 44, United States Code, and other applicable law and policy; and</text></clause><clause id="H0DE87DD2882B46B8B7D86E133006AC78"><enum>(viii)</enum><text>any other requirements the Administrator determines appropriate.</text></clause></subparagraph><subparagraph id="H677C5A6ECF65495CA6E8697FFB75D620"><enum>(B)</enum><header>Consultation</header><text>In establishing the requirements described in subparagraph (A)(vii), the Administrator shall consult with the Director of the Cybersecurity and Infrastructure Security Agency and the National Cyber Director.</text></subparagraph></paragraph><paragraph id="HE8B3FEC1FE1F4854A524A40DA0A660B3"><enum>(3)</enum><header>Incorporation of minimum requirements into current data centers</header><text>As soon as practicable, and in any case not later than 90 days after the Administrator establishes the minimum requirements pursuant to paragraph (1), the Administrator shall issue guidance to ensure, as appropriate, that covered agencies incorporate the minimum requirements established under that paragraph into the operations of any data center of a covered agency existing as of the date of enactment of the <short-title>Federal Data Center Enhancement Act of 2023</short-title>.</text></paragraph><paragraph id="H3B8BE2FB6CB94C38A9F8EC8A1A248F5F"><enum>(4)</enum><header>Review of requirements</header><text>The Administrator, in consultation with the Administrator of General Services and the Federal Chief Information Officers Council, shall review, update, and modify the minimum requirements established under paragraph (1), as necessary.</text></paragraph><paragraph id="HEDCDF8D303B3442AA88526BF062DC166"><enum>(5)</enum><header>Report on new data centers</header><text>During the development and planning lifecycle of a new data center, if the head of a covered agency determines that the covered agency is likely to make a management or financial decision relating to any data center, the head of the covered agency shall—</text><subparagraph id="H0C1A7AE5DB7D493686F1388B7B3BBE52"><enum>(A)</enum><text>notify—</text><clause id="HBF684A2E37A54090856DEFF360D66C2E"><enum>(i)</enum><text>the Administrator;</text></clause><clause id="H4D07891985364ADAA311218C98537423"><enum>(ii)</enum><text><committee-name committee-id="SSGA00">Committee on Homeland Security and Governmental Affairs of the Senate</committee-name>; and</text></clause><clause id="HE261CE5E72774194954D70C3CCA9143E"><enum>(iii)</enum><text><committee-name committee-id="">Committee on Oversight and Accountability of the House of Representatives</committee-name>; and</text></clause></subparagraph><subparagraph id="HE26027D8355E4E92AA58192C0074B481"><enum>(B)</enum><text>describe in the notification with sufficient detail how the covered agency intends to comply with the minimum requirements established under paragraph (1).</text></subparagraph></paragraph><paragraph id="HC0BF064021AF476AB64FFD29BB5D6754"><enum>(6)</enum><header>Use of technology</header><text>In determining whether to establish or continue to operate an existing data center, the head of a covered agency shall—</text><subparagraph id="HDF9DF2037DA342F7A80ECE9699352024"><enum>(A)</enum><text>regularly assess the application portfolio of the covered agency and ensure that each at-risk legacy application is updated, replaced, or modernized, as appropriate, to take advantage of modern technologies; and</text></subparagraph><subparagraph id="HCA7EA626AB404CFDB0155A96D5DD11B6"><enum>(B)</enum><text>prioritize and, to the greatest extent possible, leverage commercial cloud environments rather than acquiring, overseeing, or managing custom data center infrastructure.</text></subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="HCB4EBA3488F54F9CB954E2FEFD630C43"><enum>(7)</enum><header>Public website</header><subparagraph commented="no" display-inline="no-display-inline" id="H4A93138623A84FE484C23907AA8FDFEE"><enum>(A)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">The Administrator shall maintain a public-facing website that includes information, data, and explanatory statements relating to the compliance of covered agencies with the requirements of this section.</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="H8FBD01B24AF041799FA6BBCCDB1F3315"><enum>(B)</enum><header>Processes and procedures</header><text display-inline="yes-display-inline">In maintaining the website described in subparagraph (A), the Administrator shall—</text><clause commented="no" display-inline="no-display-inline" id="HBF64B27D36B542D08C6361F4BB1A89D2"><enum>(i)</enum><text display-inline="yes-display-inline">ensure covered agencies regularly, and not less frequently than biannually, update the information, data, and explanatory statements posed on the website, pursuant to guidance issued by the Administrator, relating to any new data centers and, as appropriate, each existing data center of the covered agency; and</text></clause><clause commented="no" display-inline="no-display-inline" id="HE8D7FFCF2F794C7F8C0B47E8D8A40BB9"><enum>(ii)</enum><text display-inline="yes-display-inline">ensure that all information, data, and explanatory statements on the website are maintained as open Government data assets.</text></clause></subparagraph></paragraph></subsection><after-quoted-block>; and</after-quoted-block></quoted-block></paragraph><paragraph id="H37ECFB717BAF407BBF674B84360D8314"><enum>(3)</enum><text>in subsection (c), by striking paragraph (1) and inserting the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="HDB8A43D71F6647AFA187F0367BCF1589"><paragraph id="H1A32279E3C614D16AB579E90AFF7DE2C"><enum>(1)</enum><header>In general</header><text>The head of a covered agency shall oversee and manage the data center portfolio and the information technology strategy of the covered agency in accordance with Federal cybersecurity guidelines and directives, including—</text><subparagraph id="H2BBA5AC9A535440FA2DDFB47D64BEDE7"><enum>(A)</enum><text>information security standards and guidelines promulgated by the Director of the National Institute of Standards and Technology;</text></subparagraph><subparagraph id="H71F060CEEA8F4F7483C491B6575D5A97"><enum>(B)</enum><text>applicable requirements and guidance issued by the Director of the Office of Management and Budget pursuant to section 3614 of title 44, United States Code; and</text></subparagraph><subparagraph id="HA145D8830F614FBBAE37D7416A61A251"><enum>(C)</enum><text>directives issued by the Secretary of Homeland Security under section 3553 of title 44, United States Code.</text></subparagraph></paragraph><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></subsection><subsection id="HEC73C4CEF4A34B7AA304D9938F43B8C7"><enum>(c)</enum><header>Extension of sunset</header><text display-inline="yes-display-inline">Section 834(e) of the Carl Levin and Howard P. <quote>Buck</quote> McKeon National Defense Authorization Act for Fiscal Year 2015 (<external-xref legal-doc="usc" parsable-cite="usc/44/3601">44 U.S.C. 3601</external-xref> note; <external-xref legal-doc="public-law" parsable-cite="pl/113/291">Public Law 113–291</external-xref>) is amended by striking <quote>2022</quote> and inserting <quote>2026</quote>.</text></subsection><subsection commented="no" display-inline="no-display-inline" id="HC41BCEA041D74C8F856462F3BC8E442C"><enum>(d)</enum><header>GAO review</header><text>Not later than 1 year after the date of the enactment of this Act, and annually thereafter, the Comptroller General of the United States shall review, verify, and audit the compliance of covered agencies with the minimum requirements established pursuant to section 834(b)(1) of the Carl Levin and Howard P. <quote>Buck</quote> McKeon National Defense Authorization Act for Fiscal Year 2015 (<external-xref legal-doc="usc" parsable-cite="usc/44/3601">44 U.S.C. 3601</external-xref> note; <external-xref legal-doc="public-law" parsable-cite="pl/113/291">Public Law 113–291</external-xref>) for new data centers and subsection (b)(3) of that Act for existing data centers, as appropriate.</text></subsection></section></legis-body></bill> 

