<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Reported-in-Senate" dms-id="A1" public-private="public" slc-id="S1-ELL24376-SH7-YV-H36"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>118 S4630 RS: Streamlining Federal Cybersecurity Regulations Act</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2024-12-02</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><calendar>Calendar No. 655</calendar><congress>118th CONGRESS</congress><session>2d Session</session><legis-num>S. 4630</legis-num><associated-doc role="report">[Report No. 118–254]</associated-doc><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20240708">July 8, 2024</action-date><action-desc><sponsor name-id="S380">Mr. Peters</sponsor> (for himself, <cosponsor name-id="S378">Mr. Lankford</cosponsor>, <cosponsor name-id="S402">Ms. Rosen</cosponsor>, and <cosponsor name-id="S363">Mr. King</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSGA00" added-display-style="italic" deleted-display-style="strikethrough">Committee on Homeland Security and Governmental Affairs</committee-name></action-desc></action><action stage="Reported-in-Senate"><action-date date="20241202">December 2, 2024</action-date><action-desc>Reported by <sponsor name-id="S380">Mr. Peters</sponsor>, with an amendment</action-desc><action-instruction>Strike out all after the enacting clause and insert the part printed in italic</action-instruction></action><legis-type>A BILL</legis-type><official-title>To establish an interagency committee to harmonize regulatory regimes in the United States relating to cybersecurity, and for other purposes.</official-title></form><legis-body><section id="S1" section-type="section-one" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Streamlining Federal Cybersecurity Regulations Act</short-title></quote>.</text></section><section id="idb4e60d7f35f04a6e8f0a571f8c3db2dd" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><enum>2.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act:</text><paragraph id="id50105e4ac22d4815ada8f46526822b83"><enum>(1)</enum><header>Agency</header><text>The term <term>agency</term> has the meaning given that term in section 551 of title 5, United States Code. </text></paragraph><paragraph id="idba95e4dfaed047b481f54d12c3598bb3"><enum>(2)</enum><header>Appropriate congressional committees</header><text>The term <term>appropriate congressional committees</term> means—</text><subparagraph id="id59f7b854e11f433c94122aba6207fe65"><enum>(A)</enum><text>the Committee on Homeland Security and Governmental Affairs of the Senate;</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ida349dd22e6864e04813bb12f66ecf077"><enum>(B)</enum><text display-inline="yes-display-inline">the Committee on Oversight and Accountability of the House of Representatives;</text></subparagraph><subparagraph id="id1f313ca94e754c6084a6848bdfcc28d2"><enum>(C)</enum><text>each committee of Congress with jurisdiction over the activities of a regulatory agency; and</text></subparagraph><subparagraph id="id41ae6e3549b94af7b3c2a2b577ad4f42"><enum>(D)</enum><text>each committee of Congress with jurisdiction over the activities of a Sector Risk Management Agency with respect to a sector regulated by a regulatory agency.</text></subparagraph></paragraph><paragraph id="id86dbd0ae74d94098a0b6b893de720f8a"><enum>(3)</enum><header>Committee</header><text>The term <term>Committee</term> means the Harmonization Committee established under section 3(a).</text></paragraph><paragraph id="idd124145d21df4c9bab817dad543aaa5f"><enum>(4)</enum><header>Cybersecurity requirement</header><text>The term <term>cybersecurity requirement</term> means an administrative, technical, or physical safeguard, requirement, or supervisory activity, including regulations, guidance, bulletins or examinations, relating to information security, information technology, cybersecurity, or cyber risk or resilience. </text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id73abc85e1b3c46eda3bc21d85c44548c"><enum>(5)</enum><header display-inline="yes-display-inline">Harmonization</header><subparagraph commented="no" display-inline="no-display-inline" id="idd7bb89cb590d4ce4bf08167348c91494"><enum>(A)</enum><header>Definition</header><text display-inline="yes-display-inline">The term <term>harmonization</term> means the process of aligning cybersecurity requirements issued by regulatory agencies such that the requirements consist of—</text><clause commented="no" display-inline="no-display-inline" id="id2b0bae88f6274264a797b4b8f4b69316"><enum>(i)</enum><text display-inline="yes-display-inline">a common set of minimum requirements that apply across sectors and that can be updated periodically to address new or evolving risks relating to information security or cybersecurity; and</text></clause><clause commented="no" display-inline="no-display-inline" id="id3aaac7d4bc5c4c3cb21138386aa43d3c"><enum>(ii)</enum><text display-inline="yes-display-inline">sector-specific requirements that—</text><subclause commented="no" display-inline="no-display-inline" id="id8eb2895fecd34644a99e76e60d8b71b4"><enum>(I)</enum><text>are necessary to address sector-specific risks that are not adequately addressed by the minimum requirements in clause (i); and</text></subclause><subclause commented="no" display-inline="no-display-inline" id="id39c8aff779744e23a07c991349b26e90"><enum>(II)</enum><text>are substantially similar, where appropriate, to other requirements in that sector or a similar sector.</text></subclause></clause></subparagraph><subparagraph id="idcfeb6cc7dab3438ba622c4f439471f1d"><enum>(B)</enum><header>Rule of construction</header><text>Nothing in this definition shall be construed to exempt regulatory agencies from any otherwise applicable processes or laws relating to updating regulations, including subchapter II of chapter 5, and chapter 7, of title 5, United States Code (commonly known as the <quote>Administrative Procedure Act</quote>).</text></subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id8c16cd30375847bbba688e46bb96f824"><enum>(6)</enum><header>Independent regulatory agency</header><text>The term <term>independent regulatory agency</term> has the meaning given that term in section 3502 of title 44, United States Code.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="idf747786762574cfcb45a7ef7f8ead5d3"><enum>(7)</enum><header>Reciprocity</header><text>The term <term>reciprocity</term> means the recognition or acceptance by 1 regulatory agency of an assessment, determination, examination, finding, or conclusion of another regulatory agency for determining that a regulated entity has complied with a cybersecurity requirement.</text></paragraph><paragraph id="id8adabaafcb0e4b0192821d819c9844c4" commented="no"><enum>(8)</enum><header>Regulatory agency</header><text>The term <term>regulatory agency</term> means—</text><subparagraph commented="no" display-inline="no-display-inline" id="id03e98a8284c94d46913ece50405cef0b"><enum>(A)</enum><text display-inline="yes-display-inline">any independent regulatory agency that has the statutory authority to issue or enforce any mandatory cybersecurity requirement; or</text></subparagraph><subparagraph id="id9c15abb8f50a4d91b798e2b26c452cf5" commented="no"><enum>(B)</enum><text>any other agency that has the statutory authority to issue or enforce any cybersecurity requirement.</text></subparagraph></paragraph><paragraph id="ideb0beeb784c94be987f6aeec3e6a03e9"><enum>(9)</enum><header>Regulatory Framework</header><text>The term <term>regulatory framework</term> means the framework developed under section 3(e)(1). </text></paragraph><paragraph id="ideb21bd5a12f24f7d8b520ad7535c0576"><enum>(10)</enum><header>Sector risk management agency</header><text>The term <term>Sector Risk Management Agency</term> has the meaning given that term in section 2200 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/650">6 U.S.C. 650</external-xref>).</text></paragraph></section><section id="id7c3e9d22d68748afb549ee926af430ca" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><enum>3.</enum><header>Establishment of interagency committee to harmonize regulatory regimes in the United States relating to cybersecurity</header><subsection id="ide3c7e942963c4416bf15f2196d0a357d"><enum>(a)</enum><header>Harmonization Committee</header><paragraph id="id6E622EC55DC94E2FB1ACAC6497BA58CF"><enum>(1)</enum><header>In general</header><text>The National Cyber Director shall establish an interagency committee to be known as the Harmonization Committee to enhance the harmonization of cybersecurity requirements that are applicable within the United States.</text></paragraph><paragraph id="idb74ffd97402445949ba40a52b70d98f8"><enum>(2)</enum><header>Support</header><text>The National Cyber Director shall provide the Committee with administrative and management support as appropriate.</text></paragraph></subsection><subsection id="id12932d23a26946f39413f8f16e725b18"><enum>(b)</enum><header>Members</header><paragraph id="id90EC71194AEE4C6FA8E38E0AC55A4BE7"><enum>(1)</enum><header>In general</header><text>The Committee shall be composed of—</text><subparagraph commented="no" display-inline="no-display-inline" id="id8acf540132864cd79d7d9884733d8d1d"><enum>(A)</enum><text display-inline="yes-display-inline">the National Cyber Director;</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idbf1f7f58c1db4270838cf0dd4c2f0657"><enum>(B)</enum><text display-inline="yes-display-inline">the head of each regulatory agency;</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idc2c5c0f1959e41cf99c9dbd032c000e4"><enum>(C)</enum><text display-inline="yes-display-inline">the head of the Office of Information and Regulatory Affairs of the Office of Management and Budget; and</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ide1abaced66d043448976d91c33193534"><enum>(D)</enum><text display-inline="yes-display-inline">the head of other appropriate agencies, as determined by the chair of the Committee.</text></subparagraph></paragraph><paragraph display-inline="no-display-inline" commented="no" id="idD56BBABAE30242D6BC8FA6DB27EAB087"><enum>(2)</enum><header>Publication of list of members</header><text>The Committee shall maintain a list of the agencies that are represented on the Committee on a publicly available website.</text></paragraph></subsection><subsection id="id9aece22c405245f2b90a8d3c76757af8"><enum>(c)</enum><header>Chair</header><text>The National Cyber Director shall be the chair of the Committee.</text></subsection><subsection commented="no" display-inline="no-display-inline" id="id556cfa8ba88a4355ad05dd9b6a00bf09"><enum>(d)</enum><header>Charter</header><text>The Committee shall develop, deliver to Congress, and make publicly available a charter, which shall—</text><paragraph commented="no" display-inline="no-display-inline" id="id48615AB902D64E0BB9A5F19FC042CA4B"><enum>(1)</enum><text>include the processes and rules of the Committee; and</text></paragraph><paragraph display-inline="no-display-inline" commented="no" id="idD8B04243067243419E82E5A34DE2BF26"><enum>(2)</enum><text>detail—</text><subparagraph display-inline="no-display-inline" commented="no" id="id02940E101928429D9DC1004B6CCB3D51"><enum>(A)</enum><text>the objective and scope of the Committee; and</text></subparagraph><subparagraph display-inline="no-display-inline" commented="no" id="id094128BE677041FAA0CAE0BEA474BA2B"><enum>(B)</enum><text>other items as necessary.</text></subparagraph></paragraph></subsection><subsection id="idf02338f5592344f7bca5ed3ff3a1a8ea"><enum>(e)</enum><header>Regulatory framework for harmonization</header><paragraph commented="no" display-inline="no-display-inline" id="idbd79d11c022b4969bf9299a3ceec62d5"><enum>(1)</enum><header>In general</header><subparagraph commented="no" display-inline="no-display-inline" id="id3a97678ef90b4184a3c5dbdacf788156"><enum>(A)</enum><header>Framework</header><text display-inline="yes-display-inline">Not later than 1 year after the date of enactment of this Act, the Committee shall develop a regulatory framework for achieving harmonization of the cybersecurity requirements of each regulatory agency.</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idd758674ecd5e412cb211e8731d96c147"><enum>(B)</enum><header>Factors</header><text>In developing the framework under subparagraph (A), the Committee shall account for existing sector-specific cybersecurity requirements that are identified as unique or critical to a sector.</text></subparagraph></paragraph><paragraph id="id2982b37edc784864a14e69db1891b9c4"><enum>(2)</enum><header>Minimum requirements</header><text>The framework shall contain, at a minimum, processes for—</text><subparagraph commented="no" display-inline="no-display-inline" id="id9a42fcbde0b640969307d81a60390246"><enum>(A)</enum><text display-inline="yes-display-inline">establishing a reciprocal compliance mechanism for minimum requirements relating to information security or cybersecurity for entities regulated by more than 1 regulatory agency;</text></subparagraph><subparagraph id="idb8c7d7874a1a49499d4bd1e7f46e3585"><enum>(B)</enum><text>identifying cybersecurity requirements that are overly burdensome, inconsistent, or contradictory, as determined by the Committee; and</text></subparagraph><subparagraph id="id5c580e796a994c24a5ca09b33b747958"><enum>(C)</enum><text>developing recommendations for updating regulations, guidance, and examinations to address overly burdensome, inconsistent, or contradictory cybersecurity requirements identified under subparagraph (B) to achieve harmonization.</text></subparagraph></paragraph><paragraph id="idf9f5bd94cdb54d7b98279a8e9f96aadc"><enum>(3)</enum><header>Publication</header><text>Upon completion of the regulatory framework, the Committee shall publish the regulatory framework in the Federal Register. </text></paragraph></subsection><subsection id="idbabbb4aa8d0a448888f55937eb777c67"><enum>(f)</enum><header>Pilot program on implementation of regulatory framework</header><paragraph commented="no" display-inline="no-display-inline" id="id223019f8fb484762bdb97d0af1f1c775"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">Not fewer than 3 regulatory agencies, selected by the Committee, shall carry out a pilot program to implement the regulatory framework established under subsection (e) with respect to not fewer than 3 cybersecurity requirements.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id3499bb86a7e04f13b886c3ff463938ab"><enum>(2)</enum><header>Participation by regulatory agencies and regulated entities</header><subparagraph commented="no" display-inline="no-display-inline" id="ida4672014a7dd4e1ba6b470b8e3ad0ad3"><enum>(A)</enum><header display-inline="yes-display-inline">Regulatory agencies</header><text>Participation in the pilot program by a regulatory agency shall be voluntary and subject to the consent of the regulatory agency following selection by the Committee under paragraph (1).</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idfecd9c022c194e0c8b4649b8cbd72518"><enum>(B)</enum><header>Regulated entities</header><text>Participation in the pilot program by a regulated entity shall be voluntary.</text></subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id6bdbebaea4314dc3a5a7ac72e1a99133"><enum>(3)</enum><header>Selection of cybersecurity requirements</header><text>Cybersecurity requirements selected for the pilot program under paragraph (1) shall contain substantially similar or substantially related requirements such that not fewer than 2 of the selected cybersecurity requirements govern the same regulated entity with substantially similar or substantially related requirements relating to information security or cybersecurity.</text></paragraph><paragraph id="idce239f5933ee4cdaa6faa48651072c3f"><enum>(4)</enum><header>Waivers</header><text>Notwithstanding any provision of subchapter II of chapter 5, and chapter 7, of title 5, United States Code (commonly known as the <quote>Administrative Procedure Act</quote>) and subject to the consent of any participating regulated entity, in implementing the pilot program under paragraph (1), a regulatory agency participating in the pilot program shall have the authority to issue waivers and establish alternative procedures for regulated entities participating in the pilot program with respect to the cybersecurity requirements included under the pilot program.</text></paragraph></subsection><subsection id="id0b0b258af1994b2dae6b6b0294ab3ad7" commented="no"><enum>(g)</enum><header>Consultation with the Committee</header><paragraph commented="no" id="id6C990F22C451456DB0922D20F5F6944D"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">Notwithstanding any other provision of law—</text><subparagraph id="ida03357e9ba054073932632e8f60bbce9"><enum>(A)</enum><text>before prescribing any cybersecurity requirement, the head of a regulatory agency shall consult with the Committee regarding such requirement and the regulatory framework established under subsection (e); and </text></subparagraph><subparagraph id="id35ad7db8619f459992e9f50873e08988"><enum>(B)</enum><text>independent regulatory agencies, when updating any existing cybersecurity requirement or issuing a potential new cybersecurity requirement, shall consult the Committee during the development of the updated cybersecurity requirement or the new cybersecurity requirement to ensure that the requirement is aligned to the greatest extent possible with the regulatory framework.</text></subparagraph></paragraph><paragraph id="id0CEB0C1BB9CE455EA362C2BA771D5AEC"><enum>(2)</enum><header>Determination</header><text>Following a consultation under paragraph (1), the Committee shall make a determination in writing to the agency, in coordination with the Office of Management and Budget as necessary, that shall—</text><subparagraph id="id7bf46cb200a54fa6af72b65bbf953ab7"><enum>(A)</enum><text>include to what degree the proposed cybersecurity requirement or update to the cybersecurity requirement aligns with the regulatory framework; and</text></subparagraph><subparagraph id="idabad97d72cf840cd94ad6c6cffc680f6"><enum>(B)</enum><text>provide a list of recommendations to improve the cybersecurity requirement and align it with the regulatory framework. </text></subparagraph></paragraph></subsection><subsection id="id4794bd8c32af4c13bd7a27fc867665b0"><enum>(h)</enum><header>Consultation with sector risk management agencies</header><text>The Committee shall consult with appropriate Sector Risk Management Agencies in the development of the regulatory framework under subsection (e) and the implementation of the pilot program under subsection (f). </text></subsection><subsection id="idB69076D8DAFF46A08CA4828BA12FE9D1"><enum>(i)</enum><header>Reports</header><paragraph id="id71B3D21FA36C41A3B23D07475F9C3122"><enum>(1)</enum><header>Annual report</header><text>Not later than 12 months after the date of enactment of this Act, and annually thereafter, the Committee shall submit to the appropriate congressional committees a report detailing—</text><subparagraph id="idBD8A2E0BE94A44FFAE1B85CEA4A0A076"><enum>(A)</enum><text>member participation; and</text></subparagraph><subparagraph id="idAE5856CAFB5F40CBBE3C72B081C9C4C9"><enum>(B)</enum><text>the application of the regulatory framework, once developed, on cybersecurity requirements, including consultations or discussions with regulators.</text></subparagraph></paragraph><paragraph id="idB7B3C78DF2684ECEBB06F31C6DF1BE83"><enum>(2)</enum><header>Pilot program report</header><text>Not later than 12 months after the date on which the pilot program begins, the Committee shall submit to the appropriate congressional committees a report detailing—</text><subparagraph id="id0220DB17DF2C488695BF33B8906B666E"><enum>(A)</enum><text>the cybersecurity requirements selected for the program, including the reasons that the regulatory agency and cybersecurity requirement were selected;</text></subparagraph><subparagraph id="idF11B62C95E2E46D290EA2EBDEAB29C40"><enum>(B)</enum><text>the information learned from the program;</text></subparagraph><subparagraph id="id395EE1944F574355B8780B68394159BD"><enum>(C)</enum><text>any obstacles encountered during the program; and</text></subparagraph><subparagraph id="id8E843CDEEA814F7B8BF0300A4EE4C6E5"><enum>(D)</enum><text>an assessment of the applicability of expanding the program to other agencies and cybersecurity requirements. </text></subparagraph></paragraph></subsection></section><section id="id9429c8f3690a4bf69ebda45ed26810ac" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><enum>4.</enum><header>Status updates on incident reporting</header><subsection id="idc6255288b0dd4083b313491faa8f5136"><enum>(a)</enum><header>Status update on memoranda of agreement</header><text>Not later than 180 days after the date of enactment of this Act, and not less frequently than every 180 days thereafter, the Director of the Cybersecurity and Infrastructure Security Agency shall provide to the appropriate congressional committees a status update on the development and implementation of memoranda of agreement between agencies required under section 104(a)(5) of the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (<external-xref legal-doc="usc" parsable-cite="usc/6/681g">6 U.S.C. 681g(a)(5)</external-xref>).</text></subsection><subsection commented="no" display-inline="no-display-inline" id="idb3894f1ac6884891ad8f97e45be83956"><enum>(b)</enum><header>Status update on efforts of the Cyber Incident Reporting Council</header><text>Not later than 180 days after the date of enactment of this Act, and not less frequently than every 180 days thereafter, the Secretary of Homeland Security shall provide to the appropriate congressional committees a status update on the efforts of the Cyber Incident Reporting Council established under section 2246 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/681f">6 U.S.C. 681f</external-xref>).</text></subsection></section><section id="idc2e43dc797504e47b774ba675f7a2cdd" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><enum>5.</enum><header>Rule of construction</header><text display-inline="no-display-inline">Nothing in this Act shall be construed—</text><paragraph commented="no" display-inline="no-display-inline" id="id14e484933077429a91128f6a22bdc2ca"><enum>(1)</enum><text display-inline="yes-display-inline">to expand or alter the existing regulatory authorities of any agency, including any independent regulatory agency, except for exemptions under section 3(f) to implement the pilot program established under that section;</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="idc6e96cb4f4e74886bae7aec3deae11f8"><enum>(2)</enum><text display-inline="yes-display-inline">to provide any such agency any new or additional regulatory authorities; or</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id828522c665cc4802ae17929a85a62e4c"><enum>(3)</enum><text>to address security incident reporting requirements subject to coordination by the Cyber Incident Reporting Council established under section 2246 of the Homeland Security Act of 2022 (<external-xref legal-doc="usc" parsable-cite="usc/6/681f">6 U.S.C. 681f</external-xref>), except for the required status updates under section 4.</text></paragraph></section></legis-body><legis-body display-enacting-clause="no-display-enacting-clause"><section id="id182349b7-b46b-44eb-aae3-b983b84281e8" section-type="section-one" changed="added" reported-display-style="italic" committee-id="SSGA00"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Streamlining Federal Cybersecurity Regulations Act</short-title></quote>.</text></section><section id="idc276cfa1-3338-401e-8af8-e737c55759ea" changed="added" reported-display-style="italic" committee-id="SSGA00"><enum>2.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act:</text><paragraph id="id573290d6-07a9-4e76-859d-a0be5a7c34bf"><enum>(1)</enum><header>Agency</header><text>The term <term>agency</term> has the meaning given that term in section 551 of title 5, United States Code. </text></paragraph><paragraph id="idc1faf2ab-02f3-495e-a55a-7a187abf9896"><enum>(2)</enum><header>Appropriate congressional committees</header><text>The term <term>appropriate congressional committees</term> means—</text><subparagraph id="id6b6e2999-cc7a-4cda-9c9d-f24c01ca9266"><enum>(A)</enum><text>the Committee on Homeland Security and Governmental Affairs of the Senate;</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id1512568b-c48f-4d00-8f24-0408f7c01bde"><enum>(B)</enum><text display-inline="yes-display-inline">the Committee on Oversight and Accountability of the House of Representatives;</text></subparagraph><subparagraph id="id2d18403f-4167-4d29-96c9-63b594646dd7"><enum>(C)</enum><text>each committee of Congress with jurisdiction over the activities of a regulatory agency; and</text></subparagraph><subparagraph id="id8a573767-149b-4454-8c56-a97679941167"><enum>(D)</enum><text>each committee of Congress with jurisdiction over the activities of a Sector Risk Management Agency with respect to a sector regulated by a regulatory agency.</text></subparagraph></paragraph><paragraph id="id2a193851-4473-4d86-8edb-4eff69cb492f"><enum>(3)</enum><header>Committee</header><text>The term <term>Committee</term> means the Harmonization Committee established under section 3(a).</text></paragraph><paragraph id="ide8ad57e3-4d89-4cb3-81a5-83157dd6215f"><enum>(4)</enum><header>Cybersecurity requirement</header><text>The term <term>cybersecurity requirement</term> means an administrative, technical, or physical safeguard, requirement, or supervisory activity, including regulations, guidance, bulletins, or examinations, relating to information security, information technology, cybersecurity, or cyber risk or resilience. </text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id48ed24ba-3c5b-43ff-ba41-c5cb35a7edf6"><enum>(5)</enum><header display-inline="yes-display-inline">Harmonization</header><subparagraph commented="no" display-inline="no-display-inline" id="idef873e49-de9b-40f9-9bb1-b035a8250f3b"><enum>(A)</enum><header>Definition</header><text display-inline="yes-display-inline">The term <term>harmonization</term> means the process of aligning cybersecurity requirements issued by regulatory agencies such that the requirements consist of—</text><clause commented="no" display-inline="no-display-inline" id="id01a99d5f-dae0-4f21-a3bf-df6681705bc8"><enum>(i)</enum><text display-inline="yes-display-inline">a common set of minimum requirements that apply across sectors and that can be updated periodically to address new or evolving risks relating to information security or cybersecurity; and</text></clause><clause commented="no" display-inline="no-display-inline" id="idb159a0dc-8370-4cae-a1c6-57a5d46ceb4e"><enum>(ii)</enum><text display-inline="yes-display-inline">sector-specific requirements, which may include performance-based requirements, that—</text><subclause commented="no" display-inline="no-display-inline" id="idf40423ef-3045-4112-af20-54623dbc304f"><enum>(I)</enum><text>are necessary to address sector-specific risks that are not adequately addressed by the minimum requirements described in clause (i); and</text></subclause><subclause commented="no" display-inline="no-display-inline" id="id28c73501-3395-40f1-8b0f-08ed1ffd8777"><enum>(II)</enum><text>are substantially similar, where appropriate, to other requirements in that sector or a similar sector.</text></subclause></clause></subparagraph><subparagraph id="id7738b318-47b0-4169-982e-9a9ffe8f2207"><enum>(B)</enum><header>Rule of construction</header><text>Nothing in this definition shall be construed to exempt regulatory agencies from any otherwise applicable processes or laws relating to updating regulations, including subchapter II of chapter 5, and chapter 7, of title 5, United States Code (commonly known as the <quote>Administrative Procedure Act</quote>).</text></subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id254429e2-394d-4a58-9ca8-0b57136127e8"><enum>(6)</enum><header>Independent regulatory agency</header><text>The term <term>independent regulatory agency</term> has the meaning given that term in section 3502 of title 44, United States Code.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id1a9e743b-a42a-4e73-811b-38b9bd105f65"><enum>(7)</enum><header>Reciprocity</header><text>The term <term>reciprocity</term> means the recognition or acceptance by 1 regulatory agency of an assessment, determination, examination, finding, or conclusion of another regulatory agency for determining that a regulated entity has complied with a cybersecurity requirement.</text></paragraph><paragraph id="id1f1e19ca-b88b-42eb-8150-7f7820f29b2b" commented="no"><enum>(8)</enum><header>Regulatory agency</header><text>The term <term>regulatory agency</term> means—</text><subparagraph commented="no" display-inline="no-display-inline" id="ide00ac881-3de5-49ad-bd16-44c3e502a495"><enum>(A)</enum><text display-inline="yes-display-inline">any independent regulatory agency that has the statutory authority to issue or enforce any mandatory cybersecurity requirement; or</text></subparagraph><subparagraph id="id510c21c4-77a0-4ecb-b290-2bcf80efeef5" commented="no"><enum>(B)</enum><text>any other agency that has the statutory authority to issue or enforce any cybersecurity requirement.</text></subparagraph></paragraph><paragraph id="idb91a4248-d7f9-41a8-9bd8-4afdbbf9efdd"><enum>(9)</enum><header>Regulatory framework</header><text>The term <term>regulatory framework</term> means the framework developed under section 3(e)(1). </text></paragraph><paragraph id="id0581585b-fb5d-432e-acfb-98b8e27519d5"><enum>(10)</enum><header>Sector risk management agency</header><text>The term <term>Sector Risk Management Agency</term> has the meaning given that term in section 2200 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/650">6 U.S.C. 650</external-xref>).</text></paragraph></section><section id="idb1dc3fe9-a87e-480f-9a9e-d97ca4bde22d" changed="added" reported-display-style="italic" committee-id="SSGA00"><enum>3.</enum><header>Establishment of interagency committee to harmonize regulatory regimes in the United States relating to cybersecurity</header><subsection id="id33309aaf-7267-4bab-8d0e-935f91d490b9"><enum>(a)</enum><header>Harmonization Committee</header><paragraph id="id3c923fde-69c4-4396-83ac-86680d5f7e89"><enum>(1)</enum><header>In general</header><text>The National Cyber Director shall establish an interagency committee to be known as the Harmonization Committee to enhance the harmonization of cybersecurity requirements that are applicable within the United States.</text></paragraph><paragraph id="idd0cab5fb-484d-41bc-b881-f47f17280856"><enum>(2)</enum><header>Support</header><text>The National Cyber Director shall provide the Committee with administrative and management support as appropriate.</text></paragraph></subsection><subsection id="id88f94e5b-90f6-4366-8feb-95c27577c700"><enum>(b)</enum><header>Members</header><paragraph id="ida56da63c-6471-46f3-87fc-5516982a1472"><enum>(1)</enum><header>In general</header><text>The Committee shall be composed of—</text><subparagraph commented="no" display-inline="no-display-inline" id="ida15a4823-587d-40aa-b1a2-e76f2ce10a75"><enum>(A)</enum><text display-inline="yes-display-inline">the National Cyber Director;</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idc2c34972-3895-4eff-b9d1-6225a808c7fc"><enum>(B)</enum><text display-inline="yes-display-inline">the head of each regulatory agency;</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id5268d8cd-f935-4018-89e9-677258de40e5"><enum>(C)</enum><text display-inline="yes-display-inline">the head of the Office of Information and Regulatory Affairs of the Office of Management and Budget; and</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id840ef930-9b4f-43dd-8835-5840e87dd3c2"><enum>(D)</enum><text display-inline="yes-display-inline">the head of other appropriate agencies, as determined by the chair of the Committee.</text></subparagraph></paragraph><paragraph display-inline="no-display-inline" commented="no" id="id82a4d249-655e-4e32-aef0-a32a872e3583"><enum>(2)</enum><header>Publication of list of members</header><text>The Committee shall maintain, on a publicly available website, a list of the agencies that are represented on the Committee, and shall update the list as members are added or removed.</text></paragraph></subsection><subsection id="idca60c886-7e7d-4b60-b1fa-eec0127fe6e9"><enum>(c)</enum><header>Chair</header><text>The National Cyber Director shall be the chair of the Committee.</text></subsection><subsection commented="no" display-inline="no-display-inline" id="id5a925330-fc2f-4217-ad9c-a87fcac0fab7"><enum>(d)</enum><header>Charter</header><text>The Committee shall develop, deliver to Congress, and make publicly available a charter, which shall—</text><paragraph commented="no" display-inline="no-display-inline" id="id997d337a-a73d-4a1d-9cc4-3af28303232d"><enum>(1)</enum><text>include the processes and rules of the Committee; and</text></paragraph><paragraph display-inline="no-display-inline" commented="no" id="id11fa50ab-0561-4553-93de-c60d276c31e1"><enum>(2)</enum><text>detail—</text><subparagraph display-inline="no-display-inline" commented="no" id="idd7bf1cf4-bcab-4247-a168-cee773c11fc7"><enum>(A)</enum><text>the objective and scope of the Committee; and</text></subparagraph><subparagraph display-inline="no-display-inline" commented="no" id="id3e988135-9ddc-477e-9235-9f60460194cd"><enum>(B)</enum><text>other items as necessary.</text></subparagraph></paragraph></subsection><subsection id="id31f56a41-3c38-4428-a9d5-d0efa4206383"><enum>(e)</enum><header>Regulatory framework for harmonization</header><paragraph commented="no" display-inline="no-display-inline" id="id272ebdfe-8e51-4d3f-90d7-69f08418aee2"><enum>(1)</enum><header>In general</header><subparagraph commented="no" display-inline="no-display-inline" id="id880f1c3a-9130-4193-ba55-248b118c92d8"><enum>(A)</enum><header>Framework</header><text display-inline="yes-display-inline">Not later than 1 year after the date of enactment of this Act, the Committee shall develop a regulatory framework for achieving harmonization of the cybersecurity requirements of each regulatory agency.</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ida0abadac-8fa5-4a68-8824-d7ba0d79484c"><enum>(B)</enum><header>Factors</header><text>In developing the framework under subparagraph (A), the Committee shall account for existing sector-specific cybersecurity requirements that are identified as unique or critical to a sector.</text></subparagraph></paragraph><paragraph id="id83517f63-fdb9-4a0a-80db-111acc3f5082"><enum>(2)</enum><header>Minimum requirements</header><text>The framework shall contain, at a minimum, processes for—</text><subparagraph commented="no" display-inline="no-display-inline" id="ide0db22ea-7b43-4bda-8bea-da4ce8978694"><enum>(A)</enum><text display-inline="yes-display-inline">establishing a reciprocal compliance mechanism for minimum requirements relating to information security or cybersecurity for entities regulated by more than 1 regulatory agency;</text></subparagraph><subparagraph id="id0a6c423f-cf01-49a8-bf7f-5e52ee357ec1"><enum>(B)</enum><text>identifying cybersecurity requirements that are overly burdensome, inconsistent, or contradictory, as determined by the Committee; and</text></subparagraph><subparagraph id="idaacf3b85-5c9c-4584-a5ce-5527b8741b9a"><enum>(C)</enum><text>developing recommendations for updating regulations, guidance, and examinations to address overly burdensome, inconsistent, or contradictory cybersecurity requirements identified under subparagraph (B) to achieve harmonization.</text></subparagraph></paragraph><paragraph id="iddeb85c9c-8923-4744-aa9d-56dc5b850f78"><enum>(3)</enum><header>Publication</header><text>Upon completion of the regulatory framework, the Committee shall publish the regulatory framework in the Federal Register for public comment. </text></paragraph></subsection><subsection id="id576346c2-51ad-480b-aea5-69cce72e9d65"><enum>(f)</enum><header>Pilot program on implementation of regulatory framework</header><paragraph commented="no" display-inline="no-display-inline" id="idae7bf57e-088e-41bf-a6da-877bbbe3bd67"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">Not fewer than 3 regulatory agencies, selected by the Committee, shall carry out a pilot program to implement the regulatory framework with respect to not fewer than 3 cybersecurity requirements.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id76007ebb-6541-4c7d-99cb-27e9d321d329"><enum>(2)</enum><header>Participation by regulatory agencies and regulated entities</header><subparagraph commented="no" display-inline="no-display-inline" id="ide43cbe2e-c09f-47dc-85ae-737718dcf263"><enum>(A)</enum><header display-inline="yes-display-inline">Regulatory agencies</header><text>Participation in the pilot program by a regulatory agency shall be voluntary and subject to the consent of the regulatory agency following selection by the Committee under paragraph (1).</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id83ddba03-ff96-4f27-981d-52092b7c4646"><enum>(B)</enum><header>Regulated entities</header><text>Participation in the pilot program by a regulated entity shall be voluntary.</text></subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id0ce230da-5f69-4af2-95c5-669b11d95bf2"><enum>(3)</enum><header>Selection of cybersecurity requirements</header><text>Cybersecurity requirements selected for the pilot program under paragraph (1) shall contain substantially similar or substantially related requirements such that not fewer than 2 of the selected cybersecurity requirements govern the same regulated entity with substantially similar or substantially related requirements relating to information security or cybersecurity.</text></paragraph><paragraph id="idfcb147e1-cda9-41ed-a300-892c0b23abe8"><enum>(4)</enum><header>Waivers</header><text>Notwithstanding any provision of subchapter II of chapter 5, and chapter 7, of title 5, United States Code (commonly known as the <quote>Administrative Procedure Act</quote>) and subject to the consent of any participating regulated entity, in implementing the pilot program under paragraph (1), a regulatory agency participating in the pilot program shall have the authority to issue waivers and establish alternative procedures for regulated entities participating in the pilot program with respect to the cybersecurity requirements included under the pilot program.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ideae5992508fa4b7eb10d6c19ab9ed8f7"><enum>(5)</enum><header>Subsequent pilot program</header><text>The Committee may only authorize an additional pilot program after the later of—</text><subparagraph commented="no" display-inline="no-display-inline" id="id99a276dd6ca04377ad958325d92475b9"><enum>(A)</enum><text display-inline="yes-display-inline">the date of the conclusion of all 3 initial pilot programs under paragraph (1); and</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id4ea1cbd7cfa3465194cf11fa6480d452"><enum>(B)</enum><text display-inline="yes-display-inline">the date of submission of all reports required under subsection (i) for each initial pilot program.</text></subparagraph></paragraph></subsection><subsection id="id79f8aa61-cbaf-46c8-825b-50b8fbf23de0" commented="no"><enum>(g)</enum><header>Consultation with the Committee</header><paragraph commented="no" id="id73b74b7a-46b5-46be-8293-963fa1005d2a"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">Notwithstanding any other provision of law—</text><subparagraph id="idef188846-9bb3-41fa-a96c-fabfc3e2b590"><enum>(A)</enum><text>except when an exigent circumstance described in paragraph (3) exists, before prescribing any cybersecurity requirement, the head of a regulatory agency shall consult with the Committee regarding such requirement and the regulatory framework; and </text></subparagraph><subparagraph id="idca381a83-8d3e-4f41-b07e-da3b49a2c870"><enum>(B)</enum><text>independent regulatory agencies, when updating any existing cybersecurity requirement or issuing a potential new cybersecurity requirement, shall consult the Committee during the development of the updated cybersecurity requirement or the new cybersecurity requirement to ensure that the requirement is aligned to the greatest extent possible with the regulatory framework.</text></subparagraph></paragraph><paragraph id="id7d607a20-70b5-46eb-a041-931d33c346f0"><enum>(2)</enum><header>Determination</header><text>Following a consultation under paragraph (1), the Committee shall make a determination in writing to the agency, in coordination with the Office of Management and Budget as necessary, that shall—</text><subparagraph id="id32e14bce-6ba9-454a-9ce5-5396098f668e"><enum>(A)</enum><text>include to what degree the proposed cybersecurity requirement or update to the cybersecurity requirement aligns with the regulatory framework; and</text></subparagraph><subparagraph id="id88285e52-2aac-4d82-9ca8-c3bd33c9cb03"><enum>(B)</enum><text>provide a list of recommendations to improve the cybersecurity requirement and align it with the regulatory framework. </text></subparagraph></paragraph><paragraph id="id2E529E0DB2CF4223A966591D22583307"><enum>(3)</enum><header>Exigent circumstances</header><text>In the case of an exigent circumstance where an agency is authorized by law to act expeditiously, the agency shall notify the Committee as soon as possible. </text></paragraph></subsection><subsection id="idca70a70c-87cb-4dc9-88f5-bc44832001da"><enum>(h)</enum><header>Consultation with sector risk management agencies</header><text>The Committee shall consult with appropriate Sector Risk Management Agencies in the development of the regulatory framework and the implementation of the pilot program under subsection (f) and shall consult with members of industry and critical infrastructure, as appropriate, for the development of the regulatory framework and pilot program.</text></subsection><subsection id="idcd3d68a8-6eb5-4238-9747-48f8841a02d0"><enum>(i)</enum><header>Reports</header><paragraph id="id276f16ad-1d0f-4bcc-8249-dfd599c96782"><enum>(1)</enum><header>Annual report</header><text>Not later than 1 year after the date of enactment of this Act, and annually thereafter, the Committee shall submit to the appropriate congressional committees a report detailing—</text><subparagraph id="idc6edc43c-4d66-42d6-b961-b1e4e43bf525"><enum>(A)</enum><text>member participation, including the rationale for any nonparticipation by Committee members;</text></subparagraph><subparagraph id="id042270eb-8ae0-449b-aec2-7f8f818157df"><enum>(B)</enum><text>the application of the regulatory framework, once developed, on cybersecurity requirements, including consultations or discussions with regulators; and</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id4dba940aaa7b479186bcc5886154a19d"><enum>(C)</enum><text>any determination made under subsection (g)(2).</text></subparagraph></paragraph><paragraph id="ide33f32a1-654a-4df8-8156-675ce0097b7c"><enum>(2)</enum><header>Pilot program report</header><text>Not later than 1 year after the date on which a pilot program under subsection (f) begins, the Committee shall submit to the appropriate congressional committees a report detailing—</text><subparagraph id="idec7833f0-b36e-4450-a5d4-f6d0aa24605b"><enum>(A)</enum><text>the cybersecurity requirements selected for the program, including—</text><clause commented="no" display-inline="no-display-inline" id="idce515678e68043ccbe2954fb711ce76c"><enum>(i)</enum><text display-inline="yes-display-inline">the reasons that the regulatory agency and cybersecurity requirement were selected;</text></clause><clause commented="no" display-inline="no-display-inline" id="ida987b460fb3a42ae8464a5c10a062edd"><enum>(ii)</enum><text>a list of the pilot programs considered by the Committee; and</text></clause><clause commented="no" display-inline="no-display-inline" id="id0a2daabea55e476eb281186c50543cf9"><enum>(iii)</enum><text display-inline="yes-display-inline">the rationale for selecting the pilot program;</text></clause></subparagraph><subparagraph id="idbe3ef349-81b0-4b2a-a593-12f63df256a5"><enum>(B)</enum><text>the information learned from the program;</text></subparagraph><subparagraph id="id61e61247-1274-4710-98c1-650ae276c68a"><enum>(C)</enum><text>any obstacles encountered during the program; and</text></subparagraph><subparagraph id="id448b7e1a-91a7-40bd-b81d-4852536bb1e3"><enum>(D)</enum><text>an assessment of the applicability of expanding the program to other agencies and cybersecurity requirements.</text></subparagraph></paragraph></subsection></section><section id="idc9be21f8-736a-479a-81a8-d05fe09bd01f" changed="added" reported-display-style="italic" committee-id="SSGA00"><enum>4.</enum><header>Status updates on incident reporting</header><subsection id="idf4419149-201d-4960-81cf-61fad4918b41"><enum>(a)</enum><header>Status update on memoranda of agreement</header><text>Not later than 180 days after the date of enactment of this Act, and not less frequently than every 180 days thereafter, the Director of the Cybersecurity and Infrastructure Security Agency shall provide to the appropriate congressional committees a status update on the development and implementation of documented agreements between agencies required under section 104(a)(5) of the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (<external-xref legal-doc="usc" parsable-cite="usc/6/681g">6 U.S.C. 681g(a)(5)</external-xref>).</text></subsection><subsection id="id35f9ad196da146c6aa296eb935261dfa"><enum>(b)</enum><header>Yearly briefing on activities of the Cyber Incident Reporting Council</header><text>Section 2246 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/681f">6 U.S.C. 681f</external-xref>) is amended—</text><paragraph commented="no" display-inline="no-display-inline" id="id6ae216efe8434c0c81987443c61e3132"><enum>(1)</enum><text>by redesignating subsection (b) as subsection (c); and</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="idf62830f9c0a94f8fb70149b5118bb7c5"><enum>(2)</enum><text>by inserting after subsection (a) the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="idF6B5233D055C411A95F2EEDACEE7CDCB" changed="added" reported-display-style="italic" committee-id="SSGA00"><subsection commented="no" display-inline="no-display-inline" id="id01b2d35ca2ad40a48d430b514b149ed9"><enum>(b)</enum><text>Not later than 1 year after the date of enactment of the <short-title>Streamlining Federal Cybersecurity Regulations Act</short-title>, and not less frequently than every 1 year thereafter, the Secretary shall brief the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives on the activities of the Cyber Incident Reporting Council.</text></subsection><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></subsection></section><section id="id40b4ede8-64ec-4697-bae2-25c5f11e98ed" changed="added" reported-display-style="italic" committee-id="SSGA00"><enum>5.</enum><header>Rule of construction</header><text display-inline="no-display-inline">Nothing in this Act shall be construed—</text><paragraph commented="no" display-inline="no-display-inline" id="ida8981368-e7fb-4440-81c4-46d3e0f7ed55"><enum>(1)</enum><text display-inline="yes-display-inline">to expand or alter the existing regulatory authorities of any agency, including any independent regulatory agency, except for exemptions under section 3(f) to implement the pilot program established under that section; or</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id7d9d57af-39ec-4614-8cb9-373b35b75cec"><enum>(2)</enum><text display-inline="yes-display-inline">to provide any such agency any new or additional regulatory authorities.</text></paragraph></section></legis-body><endorsement><action-date date="20241202">December 2, 2024</action-date><action-desc>Reported with an amendment</action-desc></endorsement></bill> 

