[Congressional Record Volume 165, Number 20 (Thursday, January 31, 2019)]
[Senate]
[Pages S814-S815]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]

  SA 100. Mr. GARDNER (for himself and Mr. Coons) submitted an 
amendment intended to be proposed by him to the bill S. 1, to make 
improvements to certain defense and security assistance provisions and 
to authorize the appropriation of funds to Israel, to reauthorize the 
United States-Jordan Defense Cooperation Act of 2015, and to halt the 
wholesale slaughter of the Syrian people, and for other purposes; which 
was ordered to lie on the table; as follows:

       At the end, add the following:

         TITLE V--CYBERSECURITY SANCTIONS WITH RESPECT TO IRAN

     SEC. 501. MANDATORY SANCTIONS WITH RESPECT TO IRAN RELATING 
                   TO SIGNIFICANT ACTIVITIES UNDERMINING 
                   CYBERSECURITY.

       (a) Investigation.--The President shall initiate an 
     investigation into the possible designation of an Iranian 
     person under subsection (b) upon receipt by the President of 
     credible information indicating that the person has engaged 
     in conduct described in that subsection.
       (b) Designation.--The President shall designate under this 
     subsection any Iranian person that the President determines 
     has directly or indirectly--
       (1) engaged in significant activities undermining 
     cybersecurity conducted by the Government of Iran; or
       (2) acted for or on behalf of the Government of Iran in 
     connection with such activities.
       (c) Sanctions.--The President shall block and prohibit all 
     transactions in all property and interests in property of any 
     Iranian person designated under subsection (b) if such 
     property and interests in property are in the United States, 
     come within the United States, or are or come within the 
     possession or control of a United States person.
       (d) Suspension of Sanctions.--
       (1) In general.--The President may suspend the application 
     of sanctions under subsection (c) with respect to an Iranian 
     person only if the President submits to the appropriate 
     congressional committees in writing a certification described 
     in paragraph (2) and a detailed justification for the 
     certification.
       (2) Certification described.--

[[Page S815]]

       (A) In general.--A certification described in this 
     paragraph with respect to an Iranian person is a 
     certification by the President that--
       (i) the person has not, during the 12-month period 
     immediately preceding the date of the certification, directly 
     or indirectly engaged in activities that would qualify the 
     person for designation under subsection (b); and
       (ii) the person is not expected to resume any such 
     activities.
       (B) Form of certification.--The certification described in 
     subparagraph (A) shall be submitted in unclassified form but 
     may include a classified annex.
       (e) Reimposition of Sanctions.--If sanctions are suspended 
     with respect to an Iranian person under subsection (d), such 
     sanctions shall be reinstated if the President determines 
     that the person has resumed the activity that resulted in the 
     initial imposition of sanctions or has engaged in any other 
     activity subject to sanctions relating to the involvement of 
     the person in significant activities undermining 
     cybersecurity on behalf of the Government of Iran.
       (f) Rule of Construction.--Nothing in this section shall be 
     construed to limit the authority of the President pursuant to 
     the International Emergency Economic Powers Act (50 U.S.C. 
     1701 et seq.), the Comprehensive Iran Sanctions, 
     Accountability, and Divestment Act of 2010 (22 U.S.C. 8501 et 
     seq.), or any other provision of law.
       (g) Report.--
       (1) In general.--Not later than 90 days after the date of 
     the enactment of this Act, and annually thereafter, the 
     President shall submit to the appropriate congressional 
     committees a report that describes significant activities 
     undermining cybersecurity conducted by the Government of 
     Iran, a person owned or controlled, directly or indirectly, 
     by that Government, or any person acting for or on behalf of 
     that Government.
       (2) Elements.--Each report required by paragraph (1) shall 
     include the following:
       (A) An assessment of the extent to which a foreign 
     government has provided material support to the Government of 
     Iran, to any person owned or controlled, directly or 
     indirectly, by that Government, or to any person acting for 
     or on behalf of that Government, in connection with the 
     conduct of significant activities undermining cybersecurity.
       (B) A strategy to counter efforts by Iran to conduct 
     significant activities undermining cybersecurity directed 
     against the United States that includes a description of 
     efforts to engage foreign governments in preventing the 
     Government of Iran, persons owned or controlled, directly or 
     indirectly, by that Government, and persons acting for or on 
     behalf of that Government from conducting significant 
     activities undermining cybersecurity.
       (3) Form of report.--Each report required by paragraph (1) 
     shall be submitted in an unclassified form but may include a 
     classified annex.

                          ____________________