[Congressional Record Volume 166, Number 119 (Monday, June 29, 2020)]
[Senate]
[Pages S3658-S3659]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]

  SA 2214. Mr. KING submitted an amendment intended to be proposed by 
him to the bill S. 4049, to authorize appropriations for fiscal year 
2021 for military activities of the Department of Defense, for military 
construction, and for defense activities of the Department of Energy, 
to prescribe military personnel strengths for such fiscal year, and for 
other purposes; which was ordered to lie on the table; as follows:

       At the title X, add the following:

     Subtitle _--National Cybersecurity Certification and Labeling

     SEC. _01. DEFINITIONS.

       In this subtitle:
       (1) Accredited certifying agent.--The term ``accredited 
     certifying agent'' means any person who is accredited by the 
     National Cybersecurity Certification and Labeling Authority 
     as a certifying agent for the purposes of certifying a 
     specific class of critical information and communications 
     technology.
       (2) Certification.--The term ``certification'' means a seal 
     or symbol provided by the National Cybersecurity 
     Certification and Labeling Authority or an accredited 
     certifying agent, that results from passage of a 
     comprehensive evaluation of an information and communications 
     technology that establishes the extent to which a particular 
     design and implementation meets a set of specified security 
     standards.
       (3) Critical information and communications technology.--
     The term ``critical information and communications 
     technology'' means information and communications

[[Page S3659]]

     technology that is in use in critical infrastructure sectors 
     and that underpins national critical functions as determined 
     by the Secretary of Homeland Security.
       (4) Label.--The term ``label'' means a clear, visual, and 
     easy to understand symbol or list that conveys specific 
     information about a product's security attributes, 
     characteristics, functionality, components, or other features

     SEC. _02. NATIONAL CYBERSECURITY CERTIFICATION AND LABELING 
                   AUTHORITY AND PROGRAM.

       (a) Establishment.--There is established a National 
     Cybersecurity Certification and Labeling Authority 
     (hereinafter referred to as the ``Authority'') for the 
     purpose of administering a voluntary program, which the 
     Authority shall establish, for the certification and labeling 
     of critical information and communications technologies.
       (b) Accreditation of Certifying Agents.--As part of the 
     program established and administered under subsection (a), 
     the Authority shall define and publish a process whereby 
     nongovernmental entities may apply to become accredited 
     agents for the certification of specific critical information 
     and communications technologies.
       (c) Identification of Standards, Frameworks, and 
     Benchmarks.--As part of the program established and 
     administered under subsection (a), the Authority shall work 
     in close coordination with the Secretary of Commerce, the 
     Secretary of Homeland Security, and subject matter experts 
     from the Federal Government, academia, nongovernmental 
     organizations, and the private sector to identify and 
     harmonize common security standards, frameworks, and 
     benchmarks against which the security of critical information 
     and communications technologies may be measured.
       (d) Product Certification.--As part of the program 
     established and administered under subsection (a), the 
     Authority, in consultation with the Secretary of Commerce, 
     the Secretary of Homeland Security, and other experts from 
     the Federal Government, academia, nongovernmental 
     organizations, and the private sector, shall--
       (1) develop, and disseminate to accredited certifying 
     agents, guidelines to standardize the presentation of 
     certifications to communicate the level of security for 
     critical information and communications technologies;
       (2) develop, or permit agents accredited under subsection 
     (b) to develop, certification criteria for critical 
     information and communications technologies based on 
     identified security standards, frameworks, and benchmarks, 
     through the work conducted pursuant to subsection (c);
       (3) issue, or permit agents accredited under subsection (b) 
     to issue, certifications for products and services that meet 
     and comply with security standards, frameworks, and 
     benchmarks the standards, frameworks, and benchmarks 
     identified under subsection (c);
       (4) permit a manufacturer or distributor of a critical 
     information and communication technology to display a 
     certificate reflecting the extent to which the covered 
     product meets the standards, frameworks, and benchmarks 
     identified under subsection (c);
       (5) remove the certification of a critical information and 
     communication technology as a critical information and 
     communication technology certified under the program if the 
     manufacturer of the certified critical information and 
     communication technology falls out of conformity with the 
     standards, frameworks, and benchmarks identified under 
     subsection (c);
       (6) work to enhance public awareness of the Authority's 
     certificates and labeling, including through public outreach, 
     education, research and development, and other means; and
       (7) publicly display a list of certified critical 
     information and communication technology, along with their 
     respective certification information.
       (e) Certifications.--
       (1) In general.--Certifications issued under the program 
     established and administered under subsection (a) shall 
     remain valid for one year from the date of issuance.
       (2) Classes of certification.--In identifying and 
     harmonizing the standards, frameworks, and benchmarks under 
     subsection (c), the Authority shall designate at least three 
     classes of certifications, including--
       (A) for products and services that product manufacturers 
     and service providers of critical information and 
     communications attest meet the criteria for certification 
     under the program established and administered under 
     subsection (a), attestation-based certification;
       (B) for products that have undergone a security evaluation 
     and testing process by a qualifying third party, 
     accreditation-based certification; and
       (C) for products that have undergone a security evaluation 
     and testing process by a qualifying third party, test-based 
     certification.
       (f) Product Labeling.--The Authority, in consultation with 
     the Secretary of Commerce, the Secretary of Homeland 
     Security, and other experts from the Federal Government, 
     academia, nongovernmental organizations, and the private 
     sector, shall--
       (1) collaborate with the private sector to standardize 
     language and define a labeling schema to provide transparent 
     information on the security characteristics and constituent 
     components of a software or hardware product that includes 
     critical information and communication technology; and
       (2) establish a mechanism by which product developers can 
     provide this information for both product labeling and public 
     posting.
       (g) Enforcement.--
       (1) Prohibition.--It shall be unlawful for a person--
       (A) to falsely attested to, or falsify an audit or test 
     for, a security standard, framework, or benchmark for 
     certification;
       (B) to intentionally mislabel a product; or
       (C) to failed to maintain a security standard, framework, 
     or benchmark to which the person has attested for a security 
     standard, framework, or benchmark for certification.
       (2) Enforcement by federal trade commission.--
       (A) Unfair or deceptive acts or practices.--A violation of 
     paragraph (1) shall be treated as an unfair and deceptive act 
     or practice in violation of a regulation under section 
     18(a)(1)(B) of the Federal Trade Commission Act (15 U.S.C. 
     57a(a)(1)(B)) regarding unfair or deceptive acts or 
     practices.
       (B) Powers of commission.--
       (i) In general.--The Federal Trade Commission shall enforce 
     this subsection in the same manner, by the same means, and 
     with the same jurisdiction, powers, and duties as though all 
     applicable terms and provisions of the Federal Trade 
     Commission Act (15 U.S.C. 41 et seq.) were incorporated into 
     and made a part of this subsection.
       (ii) Privileges and immunities.--Any person who violates 
     this subsection shall be subject to the penalties and 
     entitled to the privileges and immunities provided in the 
     Federal Trade Commission Act (15 U.S.C. 41 et seq.).

     SEC. _03. SELECTION OF THE AUTHORITY.

       (a) Selection.--The Secretary of Commerce, in coordination 
     with the Secretary of Homeland Security, shall issue a notice 
     of funding opportunity and select, on a competitive basis, a 
     nonprofit, nongovernmental organization to serve as the 
     National Cybersecurity Certification and Labeling Authority 
     (in this section referred to as the ``Authority'') for period 
     of five years.
       (b) Eligibility for Selection.--The Secretary of Commerce 
     may only select an organization to serve as the Authority if 
     such organization--
       (1) is a nongovernmental, not-for-profit that is--
       (A) exempt from taxation under section 501(a) of the 
     Internal Revenue Code of 1986; and
       (B) described in sections 501(c)(3) and 170(b)(1)(A)(vi) of 
     that Code;
       (2) has a demonstrable track record of work on 
     cybersecurity and information security standards, frameworks, 
     and benchmarks; and
       (3) possesses requisite staffing and expertise, with 
     demonstrable prior experience in technology security or 
     safety standards, frameworks, and benchmarks, as well as 
     certification.
       (c) Application.--The Secretary shall establish a process 
     by which a nonprofit, nongovernmental organization that seeks 
     to be selected as the Authority may apply for consideration.
       (d) Program Evaluation.--Not later than the date that is 
     four years after the initial selection pursuant subsection 
     (a), and every four years thereafter, the Secretary of 
     Commerce, in consultation with the Secretary of Homeland 
     Security, shall--
       (1) assess the effectiveness of the labels and certificates 
     produced by the Authority, including--
       (A) assessing the costs to businesses that manufacture 
     critical information and communication technologies 
     participating in the Authority's program;
       (B) evaluating the level of participation in the 
     Authority's program by businesses that manufacture critical 
     information and communication technologies; and
       (C) assessing the level of public awareness and consumer 
     awareness of the labels under the Authority's program;
       (2) audit the impartiality and fairness of the activities 
     of the Authority;
       (3) issue a public report on the assessment most recently 
     carried out under paragraph (1) and the audit most recently 
     carried out under paragraph (2); and
       (4) brief Congress on the findings of the Secretary of 
     Commerce with respect to the most recent assessment under 
     paragraph (1) and the most recent audit under paragraph (2).
       (e) Renewal.--After the initial selection pursuant to 
     subsection (a), the Secretary of Commerce, in consultation 
     with the Secretary of Homeland Security, shall, every five 
     years--
       (1) accept applications from nonprofit, nongovernmental 
     organizations seeking selection as the Authority; and
       (2) following competitive consideration of all 
     applications--
       (A) renew the selection of the existing Authority; or
       (B) select another applicant organization to serve as the 
     Authority.

     SEC. _04. AUTHORIZATION OF APPROPRIATIONS.

       There is authorized to be appropriated such sums as may be 
     necessary to carry out this subtitle. Such funds shall remain 
     available until expended.
                                 ______