[Congressional Record Volume 171, Number 143 (Tuesday, September 2, 2025)]
[Senate]
[Pages S5646-S5647]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]

  SA 3715. Mr. COTTON submitted an amendment intended to be proposed by 
him to the bill S. 2296, to authorize appropriations for fiscal year 
2026 for military activities of the Department of Defense, for military 
construction, and for defense activities of the Department of Energy, 
to prescribe military personnel strengths for such fiscal year, and for 
other purposes; which was ordered to lie on the table; as follows:

       At the appropriate place in title XVI, insert the 
     following:

     SEC. 16__. PROHIBITION ON ACCESS TO DEPARTMENT OF DEFENSE 
                   CLOUD-BASED RESOURCES BY INDIVIDUALS WHO ARE 
                   NOT CITIZENS OF THE UNITED STATES OR ALLIED 
                   COUNTRIES.

       (a) Maintenance, Administration, Operation, and Access.--
       (1) In general.--An individual not described in paragraph 
     (2) may not maintain, administer, operate, use, receive 
     information about, or directly access or indirectly access, 
     irrespective of whether the individual is supervised by a 
     citizen of the United States, any Department of Defense cloud 
     computing system or cloud-based software, Department data, or 
     Department-related data.
       (2) Individual described.--An individual is described in 
     this paragraph if the individual--
       (A) has the requisite security clearance or authorization 
     required to access the applicable system, software, or data; 
     and
       (B)(i) is person described in paragraph (1) or (2) of 
     section 504(b) of title 10, United States Code; or
       (ii) is a citizen of a member country of the Five Eyes 
     intelligence-sharing alliance or of a country that is an ally 
     or partner of the United States that has a similar agreement 
     in effect.
       (3) Safeguards.--The Secretary of Defense shall establish 
     regulations to carry out this subsection, including 
     safeguards to ensure that only individuals described in 
     paragraph (2) maintain, administer, operate, access, and use 
     the systems, software, and data described in paragraph (1).
       (b) Department of Defense Guidance, Directives, Procedures, 
     Requirements, and Regulations.--The Secretary shall--
       (1) review all relevant guidance, directives, procedures, 
     requirements, and regulations of the Department of Defense, 
     including the Cloud Computing Security Requirements Guide, 
     the Security Technical Implementation Guides, and related 
     Department instructions; and
       (2) make such revisions as may be necessary to ensure 
     conformity and compliance with subsection (a).
       (c) Review and Report.--The Secretary shall--
       (1) conduct a review of all cloud computing contracts in 
     effect for the Department--
       (A) for any violations of section 252.225-7058 of the 
     Defense Federal Acquisition Regulation Supplement and 
     recommended penalties; and
       (B) to determine--
       (i) which contracts have allowed individuals not described 
     in paragraph (2) to maintain, administer, operate, or 
     directly access or indirectly access, whether supervised or 
     unsupervised by a United States citizen, any Government cloud 
     computing system or cloud-based software, Government data, or 
     Government-related data; and

[[Page S5647]]

       (ii) how many of the individuals described in clause (i) 
     are citizens of foreign countries of concern; and
       (2) submit to the Committee on Armed Services of the Senate 
     and the Committee on Armed Services of the House of 
     Representatives a report on the findings of the Secretary 
     with respect to the review conducted pursuant to paragraph 
     (1).
       (d) Definitions.--ln this section:
       (1) The term ``cloud computing'' has the meaning given such 
     term in section 239.7601 of the Defense Federal Acquisition 
     Regulation Supplement, or successor regulation.
       (2) The term ``cloud-based software'' means a software 
     application, platform, or computational service that is--
       (A) delivered to end users via internet-based cloud 
     computing infrastructure;
       (B) hosted, operated, maintained, and controlled by a 
     third-party service provider; and
       (C) accessed remotely by users without requiring local 
     installation or deployment of the software on user devices or 
     Department-controlled systems.
       (3) The terms ``Department data'' and ``Department-related 
     data'' have the meanings given the terms ``Government data'' 
     and ``Government-related data'', respectively, in section 
     239.7601 of the Defense Federal Acquisition Regulation 
     Supplement, or successor regulation, except in this section, 
     such terms apply only to the Department of Defense.
       (4) The term ``directly access'', with respect to a system, 
     software, or data, means--
       (A) to physically access the system, software, or data; or
       (B) to logically access the system, software, or data, 
     through proxy, virtual, administrative, or programmatic means 
     such that an individual can modify, alter, control, 
     administer, configure, or deploy the system, software, or 
     data.
       (5) The term ``Five Eyes intelligence-sharing alliance'' 
     includes the following:
       (A) The Commonwealth of Australia.
       (B) Canada.
       (C) New Zealand.
       (D) The United Kingdom of Great Britain and Northern 
     Ireland.
       (E) The United States of America.
       (6) The term ``foreign country of concern'' has the meaning 
     given that term in section 9901 of the William M. (Mac) 
     Thornberry National Defense Authorization Act for Fiscal Year 
     2021 (15 U.S.C. 4651).
       (7) The term ``indirectly access'', with respect to a 
     system, software, or data, means to obtain, receive, collect, 
     or derive information from the system, software, or data 
     regarding technical details, operational characteristics, or 
     security-related attributes, including--
       (A) system configurations;
       (B) network architecture;
       (C) security controls;
       (D) data schemas;
       (E) performance metrics; and
       (F) access logs or other information that could compromise 
     the confidentiality, integrity, or availability of the 
     system, software, or data.
                                 ______