<?xml version="1.0" encoding="UTF-8" standalone="no"?><?xml-stylesheet type="text/css" href="uslm.css"?><pLaw xmlns="http://schemas.gpo.gov/xml/uslm" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xml:lang="en" xsi:schemaLocation="http://schemas.gpo.gov/xml/uslm https://www.govinfo.gov/schemas/xml/uslm/uslm-2.0.17.xsd">

<?I97 132 STAT. ?>
<?I98 132 STAT. ?>
<?I99 132 STAT. ?>
<?I50 PUBLIC LAW 115–390—DEC. 21, 2018?>
<?I51 PUBLIC LAW 115–390—DEC. 21, 2018?>
<?I52 PUBLIC LAW 115–390—DEC. 21, 2018?>


<!--Disclaimer: Legislative measures that include compacts or other non-standard data structures will require additional modeling and may contain inconsistencies in the converted USLM XML.-->
<meta><dc:title>Public Law 115–390: To require the Secretary of Homeland Security to establish a security vulnerability disclosure policy, to establish a bug bounty program for the Department of Homeland Security, to amend title 41, United States Code, to provide for Federal acquisition supply chain security, and for other purposes.</dc:title>
<dc:type>Public Law</dc:type><docNumber>390</docNumber>
<citableAs>Public Law 115–390</citableAs><citableAs>132 Stat. 5173</citableAs>
<approvedDate>2018-12-21</approvedDate>
<dc:date>2018-12-21</dc:date>
<dc:publisher>United States Government Publishing Office</dc:publisher><dc:creator>National Archives and Records Administration</dc:creator><dc:creator>Office of the Federal Register</dc:creator><dc:format>text/xml</dc:format><dc:language>EN</dc:language><dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
<processedBy>GPO Locator to USLM Converter 4.15.31;Stage2.20250702</processedBy><processedDate>2026-01-02</processedDate>
<congress>115</congress><publicPrivate>public</publicPrivate>
</meta>
<preface><centerRunningHead>PUBLIC LAW 115–390—DEC. 21, 2018</centerRunningHead>
<page identifier="/us/stat/132/5173">132 STAT. 5173</page>
<dc:type>Public Law</dc:type><docNumber>115–390</docNumber>
<congress value="115">115th Congress</congress>
</preface>
<main>
<longTitle>
<docTitle class="centered fontsize12" style="-uslm-lc:I658005">An Act</docTitle>
<officialTitle class="indentUp0 firstIndent1 fontsize8" style="-uslm-lc:I658011">To require the Secretary of Homeland Security to establish a security vulnerability disclosure policy, to establish a bug bounty program for the Department of Homeland Security, to amend title 41, United States Code, to provide for Federal acquisition supply chain security, and for other purposes.<sidenote><p class="centered fontsize8" id="x39a739dd-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658076"><approvedDate date="2018-12-21">Dec. 21, 2018</approvedDate></p><p class="centered fontsize8" id="x39a739de-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658076">[<ref href="/us/bill/115/hr/7327">H.R. 7327</ref>]<?GPOvSpace 08?></p></sidenote></officialTitle>
</longTitle>
<enactingFormula style="-uslm-lc:I658120"><i>  Be it enacted by the Senate and House of Representa­tives of the United States of America in Congress assembled,</i></enactingFormula><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39a739df-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Strengthening and Enhancing Cyber-capabilities by Utilizing Risk Exposure Technology Act.</p></sidenote>
<section id="d140329e88" identifier="/us/pl/115/390/s1" style="-uslm-lc:I658146"><num class="bold" value="1">SECTION 1. </num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39a739e0-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180"><ref href="/us/usc/t41/s101">41 USC 101 note</ref>.</p></sidenote><heading>SHORT TITLE; TABLE OF CONTENTS.</heading><subsection class="firstIndent0 fontsize10" id="y39a78701-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/s1/a" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="a">(a) </num><heading class="fontsize10"><inline class="smallCaps">Short Title</inline>.—</heading><content>This Act may be cited as the “<shortTitle role="act">Strengthening and Enhancing Cyber-capabilities by Utilizing Risk Exposure Technology Act</shortTitle>” or the “<shortTitle role="act">SECURE Technology Act</shortTitle>”.</content></subsection>
<subsection class="firstIndent0 fontsize10" id="y39a78702-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/s1/b" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="b">(b) </num><heading class="fontsize10"><inline class="smallCaps">Table of Contents</inline>.—</heading><content>The table of contents for this Act is as follows:<?GPOvSpace 04?>
<toc>
<referenceItem role="section" style="-uslm-lc:I658242">
<designator>Sec. 1. </designator>
<label>Short title; table of contents.</label>
</referenceItem><referenceItem role="title" style="-uslm-lc:I658274">
<designator>TITLE I—</designator>
<label>DEPARTMENT OF HOMELAND SECURITY INFORMATION SECURITY AND OTHER MATTERS</label>
</referenceItem><referenceItem role="section" style="-uslm-lc:I658242">
<designator>Sec. 101. </designator>
<label>Department of Homeland Security disclosure of security vulnerabilities.</label>
</referenceItem><referenceItem role="section" style="-uslm-lc:I658242">
<designator>Sec. 102. </designator>
<label>Department of Homeland Security bug bounty pilot program.</label>
</referenceItem><referenceItem role="section" style="-uslm-lc:I658242">
<designator>Sec. 103. </designator>
<label>Congressional submittal of reports relating to certain special access programs and similar programs.</label>
</referenceItem><referenceItem role="title" style="-uslm-lc:I658274">
<designator>TITLE II—</designator>
<label>FEDERAL ACQUISITION SUPPLY CHAIN SECURITY</label>
</referenceItem><referenceItem role="section" style="-uslm-lc:I658242">
<designator>Sec. 201. </designator>
<label>Short title.</label>
</referenceItem><referenceItem role="section" style="-uslm-lc:I658242">
<designator>Sec. 202. </designator>
<label>Federal acquisition supply chain security.</label>
</referenceItem><referenceItem role="section" style="-uslm-lc:I658242">
<designator>Sec. 203. </designator>
<label>Authorities of executive agencies relating to mitigating supply chain risks in the procurement of covered articles.</label>
</referenceItem><referenceItem role="section" style="-uslm-lc:I658242">
<designator>Sec. 204. </designator>
<label>Federal Information Security Modernization Act.</label>
</referenceItem><referenceItem role="section" style="-uslm-lc:I658242">
<designator>Sec. 205. </designator>
<label>Effective date.</label>
</referenceItem></toc>
</content></subsection>
</section>
<title id="d140329e183" identifier="/us/pl/115/390/tI" style="-uslm-lc:I658178"><num value="I">TITLE I—</num><heading>DEPARTMENT OF HOMELAND SECURITY INFORMATION SECURITY AND OTHER MATTERS</heading>
<section id="d140329e188" identifier="/us/pl/115/390/tI/s101" style="-uslm-lc:I658143"><num class="fontsize12" value="101">SEC. 101. </num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39a7ae13-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180"><ref href="/us/usc/t6/s663">6 USC 663 note</ref>.</p></sidenote><heading>DEPARTMENT OF HOMELAND SECURITY DISCLOSURE OF SECURITY VULNERABILITIES.</heading><subsection class="firstIndent0 fontsize10" id="y39a9a9e4-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s101/a" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="a">(a) </num><heading class="fontsize10"><inline class="smallCaps">Vulnerability Disclosure Policy</inline>.—</heading><chapeau>The Secretary of Homeland Security shall establish a policy applicable to individuals, organizations, and companies that report security vulnerabilities on appropriate information systems of Department of Homeland Security. Such policy shall include each of the following:<page identifier="/us/stat/132/5174">132 STAT. 5174</page></chapeau><paragraph class="fontsize10" id="y39a9a9e5-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s101/a/1" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="1">(1) </num><content>The appropriate information systems of the Department that individuals, organizations, and companies may use to discover and report security vulnerabilities on appropriate information systems.</content></paragraph>
<paragraph class="fontsize10" id="y39a9a9e6-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s101/a/2" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="2">(2) </num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39a9a9e7-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Criteria.</p></sidenote><content>The conditions and criteria under which individuals, organizations, and companies may operate to discover and report security vulnerabilities.</content></paragraph>
<paragraph class="fontsize10" id="y39a9a9e8-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s101/a/3" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="3">(3) </num><content>How individuals, organizations, and companies may disclose to the Department security vulnerabilities discovered on appropriate information systems of the Department.</content></paragraph>
<paragraph class="fontsize10" id="y39a9a9e9-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s101/a/4" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="4">(4) </num><content>The ways in which the Department may communicate with individuals, organizations, and companies that report security vulnerabilities.</content></paragraph>
<paragraph class="fontsize10" id="y39a9a9ea-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s101/a/5" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="5">(5) </num><content>The process the Department shall use for public disclosure of reported security vulnerabilities.</content></paragraph>
</subsection>
<subsection class="firstIndent0 fontsize10" id="y39a9a9eb-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s101/b" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="b">(b) </num><heading class="fontsize10"><inline class="smallCaps">Remediation Process</inline>.—</heading><content>The Secretary of Homeland Security shall develop a process for the Department of Homeland Security to address the mitigation or remediation of the security vulnerabilities reported through the policy developed in subsection (a).</content></subsection>
<subsection class="firstIndent0 fontsize10" id="y39a9a9ec-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s101/c" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="c">(c) </num><heading class="fontsize10"><inline class="smallCaps">Consultation</inline>.—</heading><paragraph class="fontsize10" id="y39a9a9ed-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s101/c/1" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="1">(1) </num><heading class="fontsize10"><inline class="smallCaps">In general</inline>.—</heading><chapeau>In developing the security vulnerability disclosure policy under subsection (a), the Secretary of Homeland Security shall consult with each of the following:</chapeau><subparagraph class="fontsize10" id="y39a9a9ee-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s101/c/1/A" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">(A) </num><content>The Attorney General regarding how to ensure that individuals, organizations, and companies that comply with the requirements of the policy developed under subsection (a) are protected from prosecution under <ref href="/us/usc/t18/s1030">section 1030 of title 18, United States Code</ref>, civil lawsuits, and similar provisions of law with respect to specific activities authorized under the policy.</content></subparagraph>
<subparagraph class="fontsize10" id="y39a9a9ef-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s101/c/1/B" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">(B) </num><content>The Secretary of Defense and the Administrator of General Services regarding lessons that may be applied from existing vulnerability disclosure policies.</content></subparagraph>
<subparagraph class="fontsize10" id="y39a9a9f0-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s101/c/1/C" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="C">(C) </num><content>Non-governmental security researchers.</content></subparagraph>
</paragraph>
<paragraph class="fontsize10" id="y39a9a9f1-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s101/c/2" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="2">(2) </num><heading class="fontsize10"><inline class="smallCaps">Nonapplicability of faca</inline>.—</heading><content>The Federal Advisory Committee Act (<ref href="/us/usc/t5/app">5 U.S.C. App.</ref>) shall not apply to any consultation under this section.</content></paragraph>
</subsection>
<subsection class="firstIndent0 fontsize10" id="y39a9a9f2-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s101/d" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="d">(d) </num><heading class="fontsize10"><inline class="smallCaps">Public Availability</inline>.—</heading><content>The Secretary of Homeland Security shall make the policy developed under subsection (a) publicly available.</content></subsection>
<subsection class="firstIndent0 fontsize10" id="y39a9a9f3-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s101/e" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="e">(e) </num><heading class="fontsize10"><inline class="smallCaps">Submission to Congress</inline>.—</heading><paragraph class="fontsize10" id="y39a9a9f4-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s101/e/1" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="1">(1) </num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39a9a9f5-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Deadline.</p><p class="leftAlign firstIndent0 fontsize8" id="x39a9a9f6-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Records.</p></sidenote><heading class="fontsize10"><inline class="smallCaps">Disclosure policy and remediation process</inline>.—</heading><content>Not later than 90 days after the date of the enactment of this Act, the Secretary of Homeland Security shall submit to the appropriate congressional committees a copy of the policy required under subsection (a) and the remediation process required under subsection (b).</content></paragraph>
<paragraph class="fontsize10" id="y39a9a9f7-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s101/e/2" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="2">(2) </num><heading class="fontsize10"><inline class="smallCaps">Report and briefing</inline>.—</heading><subparagraph class="fontsize10" id="y39a9a9f8-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s101/e/2/A" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">(A) </num><heading class="fontsize10"><inline class="smallCaps">Report</inline>.—</heading><content>Not later than one year after establishing the policy required under subsection (a), the Secretary of Homeland Security shall submit to the appropriate congressional committees a report on such policy and the remediation process required under subsection (b).</content></subparagraph>
<subparagraph class="fontsize10" id="y39a9a9f9-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s101/e/2/B" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">(B) </num><heading class="fontsize10"><inline class="smallCaps">Annual briefings</inline>.—</heading><content>One year after the date of the submission of the report under subparagraph (A), and annually thereafter for each of the next three years, the <page identifier="/us/stat/132/5175">132 STAT. 5175</page>
Secretary of Homeland Security shall provide to the appropriate congressional committees a briefing on the policy required under subsection (a) and the process required under subsection (b).</content></subparagraph>
<subparagraph class="fontsize10" id="y39a9a9fa-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s101/e/2/C" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="C">(C) </num><heading class="fontsize10"><inline class="smallCaps">Matters for inclusion</inline>.—</heading><chapeau>The report required under subparagraph (A) and the briefings required under subparagraph (B) shall include each of the following with respect to the policy required under subsection (a) and the process required under subsection (b) for the period covered by the report or briefing, as the case may be:</chapeau><clause class="fontsize10" id="y39a9a9fb-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s101/e/2/C/i" style="-uslm-lc:I658126"><num class="fontsize10" style="-uslm-lc:emspace2" value="i">(i) </num><content>The number of unique security vulnerabilities reported.</content></clause>
<clause class="fontsize10" id="y39a9a9fc-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s101/e/2/C/ii" style="-uslm-lc:I658126"><num class="fontsize10" style="-uslm-lc:emspace2" value="ii">(ii) </num><content>The number of previously unknown security vulnerabilities mitigated or remediated.</content></clause>
<clause class="fontsize10" id="y39a9a9fd-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s101/e/2/C/iii" style="-uslm-lc:I658126"><num class="fontsize10" style="-uslm-lc:emspace2" value="iii">(iii) </num><content>The number of unique individuals, organizations, and companies that reported security vulnerabilities.</content></clause>
<clause class="fontsize10" id="y39a9a9fe-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s101/e/2/C/iv" style="-uslm-lc:I658126"><num class="fontsize10" style="-uslm-lc:emspace2" value="iv">(iv) </num><content>The average length of time between the reporting of security vulnerabilities and mitigation or remediation of such vulnerabilities.</content></clause>
</subparagraph>
</paragraph>
</subsection>
<subsection class="firstIndent0 fontsize10" id="y39a9a9ff-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s101/f" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="f">(f) </num><heading class="fontsize10"><inline class="smallCaps">Definitions</inline>.—</heading><chapeau>In this section:</chapeau><paragraph class="fontsize10" id="y39a9aa00-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s101/f/1" role="definitions" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="1">(1) </num><content>The term “<term>security vulnerability</term>” has the meaning given that term in section 102(17) of the Cybersecurity Information Sharing Act of 2015 (<ref href="/us/usc/t6/s1501/17">6 U.S.C. 1501(17)</ref>), in information technology.</content></paragraph>
<paragraph class="fontsize10" id="y39a9aa01-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s101/f/2" role="definitions" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="2">(2) </num><content>The term “<term>information system</term>” has the meaning given that term by <ref href="/us/usc/t44/s3502">section 3502 of title 44, United States Code</ref>.</content></paragraph>
<paragraph class="fontsize10" id="y39a9aa02-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s101/f/3" role="definitions" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="3">(3) </num><content>The term “<term>appropriate information system</term>” means an information system that the Secretary of Homeland Security selects for inclusion under the vulnerability disclosure policy required by subsection (a).</content></paragraph>
<paragraph class="fontsize10" id="y39a9aa03-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s101/f/4" role="definitions" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="4">(4) </num><chapeau>The term “<term>appropriate congressional committees</term>” means—</chapeau><subparagraph class="fontsize10" id="y39a9aa04-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s101/f/4/A" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">(A) </num><content>the Committee on Homeland Security, the Committee on Armed Services, the Committee on Energy and Commerce, and the Permanent Select Committee on Intelligence of the House of Representatives; and</content></subparagraph>
<subparagraph class="fontsize10" id="y39a9aa05-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s101/f/4/B" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">(B) </num><content>the Committee on Homeland Security and Governmental Affairs, the Committee on Armed Services, the Committee on Commerce, Science, and Transportation, and the Select Committee on Intelligence of the Senate.</content></subparagraph>
</paragraph>
</subsection>
</section>
<section id="d140329e435" identifier="/us/pl/115/390/tI/s102" style="-uslm-lc:I658143"><num class="fontsize12" value="102">SEC. 102. </num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39a9d116-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180"><ref href="/us/usc/t6/s663">6 USC 663 note</ref>.</p></sidenote><heading>DEPARTMENT OF HOMELAND SECURITY BUG BOUNTY PILOT PROGRAM.</heading><subsection class="firstIndent0 fontsize10" id="y39ac1b07-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s102/a" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="a">(a) </num><heading class="fontsize10"><inline class="smallCaps">Definitions</inline>.—</heading><chapeau>In this section:</chapeau><paragraph class="fontsize10" id="y39ac1b08-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s102/a/1" role="definitions" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="1">(1) </num><chapeau>The term “<term>appropriate congressional committees</term>” means—</chapeau><subparagraph class="fontsize10" id="y39ac1b09-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s102/a/1/A" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">(A) </num><content>the Committee on Homeland Security and Governmental Affairs of the Senate;</content></subparagraph>
<subparagraph class="fontsize10" id="y39ac1b0a-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s102/a/1/B" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">(B) </num><content>the Select Committee on Intelligence of the Senate;</content></subparagraph>
<subparagraph class="fontsize10" id="y39ac1b0b-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s102/a/1/C" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="C">(C) </num><content>the Committee on Homeland Security of the House of Representatives; and</content></subparagraph>
<subparagraph class="fontsize10" id="y39ac1b0c-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s102/a/1/D" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="D">(D) </num><content>Permanent Select Committee on Intelligence of the House of Representatives.</content></subparagraph>
</paragraph>
<paragraph class="fontsize10" id="y39ac1b0d-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s102/a/2" role="definitions" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="2">(2) </num><chapeau>The term “<term>bug bounty program</term>” means a program under which—<page identifier="/us/stat/132/5176">132 STAT. 5176</page></chapeau><subparagraph class="fontsize10" id="y39ac1b0e-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s102/a/2/A" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">(A) </num><content>individuals, organizations, and companies are temporarily authorized to identify and report vulnerabilities of appropriate information systems of the Department; and</content></subparagraph>
<subparagraph class="fontsize10" id="y39ac1b0f-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s102/a/2/B" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">(B) </num><content>eligible individuals, organizations, and companies receive compensation in exchange for such reports.</content></subparagraph>
</paragraph>
<paragraph class="fontsize10" id="y39ac1b10-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s102/a/3" role="definitions" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="3">(3) </num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39ac1b11-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180"><ref href="/us/usc/t6/s651">6 USC 651 note</ref>.</p></sidenote><content>The term “<term>Department</term>” means the Department of Homeland Security.</content></paragraph>
<paragraph class="fontsize10" id="y39ac1b12-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s102/a/4" role="definitions" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="4">(4) </num><content>The term “<term>eligible individual, organization, or company</term>” means an individual, organization, or company that meets such criteria as the Secretary determines in order to receive compensation in compliance with Federal laws.</content></paragraph>
<paragraph class="fontsize10" id="y39ac1b13-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s102/a/5" role="definitions" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="5">(5) </num><content>The term “<term>information system</term>” has the meaning given the term in <ref href="/us/usc/t44/s3502">section 3502 of title 44, United States Code</ref>.</content></paragraph>
<paragraph class="fontsize10" id="y39ac1b14-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s102/a/6" role="definitions" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="6">(6) </num><content>The term “<term>pilot program</term>” means the bug bounty pilot program required to be established under subsection (b)(1).</content></paragraph>
<paragraph class="fontsize10" id="y39ac1b15-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s102/a/7" role="definitions" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="7">(7) </num><content>The term “<term>Secretary</term>” means the Secretary of Homeland Security.</content></paragraph>
</subsection>
<subsection class="firstIndent0 fontsize10" id="y39ac1b16-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s102/b" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="b">(b) </num><heading class="fontsize10"><inline class="smallCaps">Bug Bounty Pilot Program</inline>.—</heading><paragraph class="fontsize10" id="y39ac1b17-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s102/b/1" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="1">(1) </num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39ac1b18-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Deadline.</p></sidenote><heading class="fontsize10"><inline class="smallCaps">Establishment</inline>.—</heading><content>Not later than 180 days after the date of enactment of this Act, the Secretary shall establish, within the Office of the Chief Information Officer, a bug bounty pilot program to minimize vulnerabilities of appropriate information systems of the Department.</content></paragraph>
<paragraph class="fontsize10" id="y39ac1b19-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s102/b/2" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="2">(2) </num><heading class="fontsize10"><inline class="smallCaps">Responsibilities of secretary</inline>.—</heading><chapeau>In establishing and conducting the pilot program, the Secretary shall—</chapeau><subparagraph class="fontsize10" id="y39ac1b1a-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s102/b/2/A" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">(A) </num><content>designate appropriate information systems to be included in the pilot program;</content></subparagraph>
<subparagraph class="fontsize10" id="y39ac1b1b-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s102/b/2/B" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">(B) </num><content>provide compensation to eligible individuals, organizations, and companies for reports of previously unidentified security vulnerabilities within the information systems designated under subparagraph (A);</content></subparagraph>
<subparagraph class="fontsize10" id="y39ac1b1c-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s102/b/2/C" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="C">(C) </num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39ac1b1d-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Criteria.</p></sidenote><content>establish criteria for individuals, organizations, and companies to be considered eligible for compensation under the pilot program in compliance with Federal laws;</content></subparagraph>
<subparagraph class="fontsize10" id="y39ac1b1e-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s102/b/2/D" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="D">(D) </num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39ac1b1f-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Consultation.</p></sidenote><content>consult with the Attorney General on how to ensure that approved individuals, organizations, or companies that comply with the requirements of the pilot program are protected from prosecution under <ref href="/us/usc/t18/s1030">section 1030 of title 18, United States Code</ref>, and similar provisions of law, and civil lawsuits for specific activities authorized under the pilot program;</content></subparagraph>
<subparagraph class="fontsize10" id="y39ac1b20-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s102/b/2/E" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="E">(E) </num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39ac1b21-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Consultation.</p></sidenote><content>consult with the Secretary of Defense and the heads of other departments and agencies that have implemented programs to provide compensation for reports of previously undisclosed vulnerabilities in information systems, regarding lessons that may be applied from such programs; and</content></subparagraph>
<subparagraph class="fontsize10" id="y39ac1b22-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s102/b/2/F" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="F">(F) </num><content>develop an expeditious process by which an individual, organization, or company can register with the Department, submit to a background check as determined by the Department, and receive a determination as to eligibility; and</content></subparagraph>
<subparagraph class="fontsize10" id="y39ac1b23-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s102/b/2/G" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="G">(G) </num><content>engage qualified interested persons, including non-government sector representatives, about the structure of the pilot program as constructive and to the extent practicable.<page identifier="/us/stat/132/5177">132 STAT. 5177</page></content></subparagraph>
</paragraph>
<paragraph class="fontsize10" id="y39ac1b24-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s102/b/3" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="3">(3) </num><heading class="fontsize10"><inline class="smallCaps">Contract authority</inline>.—</heading><content>In establishing the pilot program, the Secretary, subject to the availability of appropriations, may award 1 or more competitive contracts to an entity, as necessary, to manage the pilot program.</content></paragraph>
</subsection>
<subsection class="firstIndent0 fontsize10" id="y39ac1b25-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s102/c" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="c">(c) </num><heading class="fontsize10"><inline class="smallCaps">Report to Congress</inline>.—</heading><chapeau>Not later than 180 days after the date on which the pilot program is completed, the Secretary shall submit to the appropriate congressional committees a report on the pilot program, which shall include—</chapeau><paragraph class="fontsize10" id="y39ac1b26-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s102/c/1" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="1">(1) </num><chapeau>the number of individuals, organizations, or companies that participated in the pilot program, broken down by the number of individuals, organizations, or companies that—</chapeau><subparagraph class="fontsize10" id="y39ac1b27-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s102/c/1/A" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">(A) </num><content>registered;</content></subparagraph>
<subparagraph class="fontsize10" id="y39ac1b28-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s102/c/1/B" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">(B) </num><content>were determined eligible;</content></subparagraph>
<subparagraph class="fontsize10" id="y39ac1b29-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s102/c/1/C" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="C">(C) </num><content>submitted security vulnerabilities; and</content></subparagraph>
<subparagraph class="fontsize10" id="y39ac1b2a-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s102/c/1/D" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="D">(D) </num><content>received compensation;</content></subparagraph>
</paragraph>
<paragraph class="fontsize10" id="y39ac1b2b-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s102/c/2" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="2">(2) </num><content>the number and severity of vulnerabilities reported as part of the pilot program;</content></paragraph>
<paragraph class="fontsize10" id="y39ac1b2c-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s102/c/3" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="3">(3) </num><content>the number of previously unidentified security vulnerabilities remediated as a result of the pilot program;</content></paragraph>
<paragraph class="fontsize10" id="y39ac1b2d-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s102/c/4" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="4">(4) </num><content>the current number of outstanding previously unidentified security vulnerabilities and Department remediation plans;</content></paragraph>
<paragraph class="fontsize10" id="y39ac1b2e-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s102/c/5" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="5">(5) </num><content>the average length of time between the reporting of security vulnerabilities and remediation of the vulnerabilities;</content></paragraph>
<paragraph class="fontsize10" id="y39ac1b2f-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s102/c/6" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="6">(6) </num><content>the types of compensation provided under the pilot program; and</content></paragraph>
<paragraph class="fontsize10" id="y39ac4240-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s102/c/7" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="7">(7) </num><content>the lessons learned from the pilot program.</content></paragraph>
</subsection>
<subsection class="firstIndent0 fontsize10" id="y39ac4241-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s102/d" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="d">(d) </num><heading class="fontsize10"><inline class="smallCaps">Authorization of Appropriations</inline>.—</heading><content>There is authorized to be appropriated to the Department $250,000 for fiscal year 2019 to carry out this section.</content></subsection>
</section>
<section id="d140329e696" identifier="/us/pl/115/390/tI/s103" role="instruction" style="-uslm-lc:I658143"><num class="fontsize12" value="103">SEC. 103. </num><heading>CONGRESSIONAL SUBMITTAL OF REPORTS RELATING TO CERTAIN SPECIAL ACCESS PROGRAMS AND SIMILAR PROGRAMS.</heading><chapeau class="indentUp0 firstIndent0 fontsize10" id="x39ac9062-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658120">  The National Defense Authorization Act for Fiscal Year 1994 (<ref href="/us/usc/t50/s3348">50 U.S.C. 3348</ref>) <amendingAction type="amend">is amended</amendingAction>—</chapeau><paragraph class="fontsize10" id="y39ac9063-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s103/1" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="1">(1) </num><content>by <amendingAction type="delete">striking</amendingAction> “<quotedText>Congress</quotedText>” each place it appears and <amendingAction type="insert">inserting</amendingAction> “<quotedText>the congressional oversight committees</quotedText>”;</content></paragraph>
<paragraph class="fontsize10" id="y39ac9064-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s103/2" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="2">(2) </num><content>in subsection (f)(1), by <amendingAction type="delete">striking</amendingAction> “<quotedText>appropriate oversight committees</quotedText>” and <amendingAction type="insert">inserting</amendingAction> “<quotedText>congressional oversight committees</quotedText>”; and</content></paragraph>
<paragraph class="fontsize10" id="y39ac9065-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s103/3" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="3">(3) </num><chapeau>in subsection (g)—</chapeau><subparagraph class="fontsize10" id="y39ac9066-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s103/3/A" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">(A) </num><content>by <amendingAction type="redesignate">redesignating</amendingAction> paragraphs (1) and (2) as paragraphs (2) and (3), respectively; and</content></subparagraph>
<subparagraph class="fontsize10" id="y39ac9067-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tI/s103/3/B" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">(B) </num><content>by <amendingAction type="insert">inserting</amendingAction> before paragraph (2), as so redesignated, the following:<quotedContent><paragraph class="indentDown1 fontsize10" id="y39acb778-e830-11f0-a1e4-69761a48a15a" role="definitions" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="1">“(1) </num><heading class="fontsize10"><inline class="smallCaps">Congressional oversight committees</inline><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39acb779-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Definition.</p></sidenote>.—</heading><chapeau>The term ‘<term>congressional oversight committees</term>’ means—</chapeau><subparagraph class="fontsize10" id="y39acb77a-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">“(A) </num><content>congressional leadership and authorizing and appropriations congressional committees with jurisdiction or shared jurisdiction over a department or agency;</content></subparagraph>
<subparagraph class="fontsize10" id="y39acb77b-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">“(B) </num><content>the Committee on Homeland Security and Governmental Affairs of the Senate; and</content></subparagraph>
<subparagraph class="fontsize10" id="y39acb77c-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="C">“(C) </num><content>the Committee on Oversight and Government Reform of the House of Representatives.”</content></subparagraph>
</paragraph>
</quotedContent>.<page identifier="/us/stat/132/5178">132 STAT. 5178</page></content></subparagraph>
</paragraph>
</section>
</title>
<title id="d140329e788" identifier="/us/pl/115/390/tII" style="-uslm-lc:I658178"><num value="II">TITLE II—</num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39acde8d-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Federal Acquisition Supply Chain Security Act</p><p class="leftAlign firstIndent0 fontsize8" id="x39acde8e-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">of 2018.</p></sidenote><heading>FEDERAL ACQUISITION SUPPLY CHAIN SECURITY</heading>
<section id="d140329e798" identifier="/us/pl/115/390/tII/s201" style="-uslm-lc:I658143"><num class="fontsize12" value="201">SEC. 201. </num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39acde8f-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180"><ref href="/us/usc/t41/s101">41 USC 101 note</ref>.</p></sidenote><heading>SHORT TITLE.</heading><content style="-uslm-lc:I658120">  This title may be cited as the “<shortTitle role="title">Federal Acquisition Supply Chain Security Act of 2018</shortTitle>”.</content></section>
<section id="d140329e813" identifier="/us/pl/115/390/tII/s202" style="-uslm-lc:I658143"><num class="fontsize12" value="202">SEC. 202. </num><heading>FEDERAL ACQUISITION SUPPLY CHAIN SECURITY.</heading><subsection class="firstIndent0 fontsize10" id="y39b06100-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tII/s202/a" role="instruction" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="a">(a) </num><heading class="fontsize10"><inline class="smallCaps">In General</inline>.—</heading><content><ref href="/us/usc/t41/ch13">Chapter 13 of title 41, United States Code</ref>, <amendingAction type="amend">is amended</amendingAction> by <amendingAction type="add">adding</amendingAction><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b06101-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180"><ref href="/us/usc/t41/s1321">41 USC 1321</ref> prec.</p></sidenote> at the end the following new subchapter:<quotedContent><subchapter id="y39b56a12-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658174"><num class="fontsize10 smallCaps" value="III">“SUBCHAPTER III—</num><heading class="fontsize10 smallCaps">FEDERAL ACQUISITION SUPPLY CHAIN SECURITY</heading><section class="centered fontsize12" id="y39b56a13-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658164"><num class="fontsize12" value="1321">“§ 1321.</num><heading class="fontsize12"><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b56a14-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180"><ref href="/us/usc/t41/s1321">41 USC 1321</ref>.</p></sidenote> Definitions</heading><chapeau class="indentUp0 firstIndent0 fontsize10" id="x39b56a15-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658120">  “In this subchapter:</chapeau><paragraph class="fontsize10" id="y39b56a16-e830-11f0-a1e4-69761a48a15a" role="definitions" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="1">“(1) </num><heading class="fontsize10"><inline class="smallCaps">Appropriate congressional committees and leadership</inline>.—</heading><chapeau>The term ‘<term>appropriate congressional committees and leadership</term>’ means—</chapeau><subparagraph class="fontsize10" id="y39b56a17-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">“(A) </num><content>the Committee on Homeland Security and Governmental Affairs, the Committee on the Judiciary, the Committee on Appropriations, the Committee on Armed Services, the Committee on Commerce, Science, and Transportation, the Select Committee on Intelligence, and the majority and minority leader of the Senate; and</content></subparagraph>
<subparagraph class="fontsize10" id="y39b56a18-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">“(B) </num><content>the Committee on Oversight and Government Reform, the Committee on the Judiciary, the Committee on Appropriations, the Committee on Homeland Security, the Committee on Armed Services, the Committee on Energy and Commerce, the Permanent Select Committee on Intelligence, and the Speaker and minority leader of the House of Representatives.</content></subparagraph>
</paragraph>
<paragraph class="fontsize10" id="y39b56a19-e830-11f0-a1e4-69761a48a15a" role="definitions" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="2">“(2) </num><heading class="fontsize10"><inline class="smallCaps">Council</inline>.—</heading><content>The term ‘<term>Council</term>’ means the Federal Acquisition Security Council established under section 1322(a) of this title.</content></paragraph>
<paragraph class="fontsize10" id="y39b56a1a-e830-11f0-a1e4-69761a48a15a" role="definitions" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="3">“(3) </num><heading class="fontsize10"><inline class="smallCaps">Covered article</inline>.—</heading><content>The term ‘<term>covered article</term>’ has the meaning given that term in section 4713 of this title.</content></paragraph>
<paragraph class="fontsize10" id="y39b56a1b-e830-11f0-a1e4-69761a48a15a" role="definitions" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="4">“(4) </num><heading class="fontsize10"><inline class="smallCaps">Covered procurement action</inline>.—</heading><content>The term ‘<term>covered procurement action</term>’ has the meaning given that term in section 4713 of this title.</content></paragraph>
<paragraph class="fontsize10" id="y39b56a1c-e830-11f0-a1e4-69761a48a15a" role="definitions" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="5">“(5) </num><heading class="fontsize10"><inline class="smallCaps">Information and communications technology</inline>.—</heading><content>The term ‘<term>information and communications technology</term>’ has the meaning given that term in section 4713 of this title.</content></paragraph>
<paragraph class="fontsize10" id="y39b56a1d-e830-11f0-a1e4-69761a48a15a" role="definitions" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="6">“(6) </num><heading class="fontsize10"><inline class="smallCaps">Intelligence community</inline>.—</heading><content>The term ‘<term>intelligence community</term>’ has the meaning given that term in section 3(4) of the National Security Act of 1947 (<ref href="/us/usc/t50/s3003/4">50 U.S.C. 3003(4)</ref>).</content></paragraph>
<paragraph class="fontsize10" id="y39b56a1e-e830-11f0-a1e4-69761a48a15a" role="definitions" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="7">“(7) </num><heading class="fontsize10"><inline class="smallCaps">National security system</inline>.—</heading><content>The term ‘<term>national security system</term>’ has the meaning given that term in section 3552 of title 44.</content></paragraph>
<paragraph class="fontsize10" id="y39b56a1f-e830-11f0-a1e4-69761a48a15a" role="definitions" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="8">“(8) </num><heading class="fontsize10"><inline class="smallCaps">Supply chain risk</inline>.—</heading><content>The term ‘<term>supply chain risk</term>’ has the meaning given that term in section 4713 of this title.</content></paragraph>
</section>
<section class="centered fontsize12" id="y39b56a20-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658164"><num class="fontsize12" value="1322">“§ 1322.</num><heading class="fontsize12"><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b56a21-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180"><ref href="/us/usc/t41/s1322">41 USC 1322</ref>.</p></sidenote> Federal Acquisition Security Council establishment and membership</heading><subsection class="firstIndent0 fontsize10" id="y39b56a22-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="a">“(a) </num><heading class="fontsize10"><inline class="smallCaps">Establishment</inline>.—</heading><content>There is established in the executive branch a Federal Acquisition Security Council.<page identifier="/us/stat/132/5179">132 STAT. 5179</page></content></subsection>
<subsection class="firstIndent0 fontsize10" id="y39b56a23-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="b">“(b) </num><heading class="fontsize10"><inline class="smallCaps">Membership</inline>.—</heading><paragraph class="fontsize10" id="y39b56a24-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="1">“(1) </num><heading class="fontsize10"><inline class="smallCaps">In general</inline>.—</heading><chapeau>The following agencies shall be represented on the Council:</chapeau><subparagraph class="fontsize10" id="y39b56a25-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">“(A) </num><content>The Office of Management and Budget.</content></subparagraph>
<subparagraph class="fontsize10" id="y39b56a26-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">“(B) </num><content>The General Services Administration.</content></subparagraph>
<subparagraph class="fontsize10" id="y39b56a27-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="C">“(C) </num><content>The Department of Homeland Security, including the Cybersecurity and Infrastructure Security Agency.</content></subparagraph>
<subparagraph class="fontsize10" id="y39b56a28-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="D">“(D) </num><content>The Office of the Director of National Intelligence, including the National Counterintelligence and Security Center.</content></subparagraph>
<subparagraph class="fontsize10" id="y39b56a29-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="E">“(E) </num><content>The Department of Justice, including the Federal Bureau of Investigation.</content></subparagraph>
<subparagraph class="fontsize10" id="y39b56a2a-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="F">“(F) </num><content>The Department of Defense, including the National Security Agency.</content></subparagraph>
<subparagraph class="fontsize10" id="y39b56a2b-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="G">“(G) </num><content>The Department of Commerce, including the National Institute of Standards and Technology.</content></subparagraph>
<subparagraph class="fontsize10" id="y39b56a2c-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="H">“(H) </num><content>Such other executive agencies as determined by the Chairperson of the Council.</content></subparagraph>
</paragraph>
<paragraph class="fontsize10" id="y39b56a2d-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="2">“(2) </num><heading class="fontsize10"><inline class="smallCaps">Lead representatives</inline>.—</heading><subparagraph class="fontsize10" id="y39b56a2e-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">“(A) </num><heading class="fontsize10"><inline class="smallCaps">Designation</inline>.—</heading><clause class="fontsize10" id="y39b56a2f-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658126"><num class="fontsize10" style="-uslm-lc:emspace2" value="i">“(i) </num><heading class="fontsize10"><inline class="smallCaps">In general</inline><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b56a30-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Deadline.</p></sidenote>.—</heading><content>Not later than 45 days after the date of the enactment of the Federal Acquisition Supply Chain Security Act of 2018, the head of each agency represented on the Council shall designate a representative of that agency as the lead representative of the agency on the Council.</content></clause>
<clause class="fontsize10" id="y39b56a31-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658126"><num class="fontsize10" style="-uslm-lc:emspace2" value="ii">“(ii) </num><heading class="fontsize10"><inline class="smallCaps">Requirements</inline>.—</heading><content>The representative of an agency designated under clause (i) shall have expertise in supply chain risk management, acquisitions, or information and communications technology.</content></clause>
</subparagraph>
<subparagraph class="fontsize10" id="y39b56a32-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">“(B) </num><heading class="fontsize10"><inline class="smallCaps">Functions</inline>.—</heading><content>The lead representative of an agency designated under subparagraph (A) shall ensure that appropriate personnel, including leadership and subject matter experts of the agency, are aware of the business of the Council.</content></subparagraph>
</paragraph>
</subsection>
<subsection class="firstIndent0 fontsize10" id="y39b56a33-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="c">“(c) </num><heading class="fontsize10"><inline class="smallCaps">Chairperson</inline>.—</heading><paragraph class="fontsize10" id="y39b56a34-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="1">“(1) </num><heading class="fontsize10"><inline class="smallCaps">Designation</inline><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b56a35-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Deadline.</p></sidenote>.—</heading><content>Not later than 45 days after the date of the enactment of the Federal Acquisition Supply Chain Security Act of 2018, the Director of the Office of Management and Budget shall designate a senior-level official from the Office of Management and Budget to serve as the Chairperson of the Council.</content></paragraph>
<paragraph class="fontsize10" id="y39b56a36-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="2">“(2) </num><heading class="fontsize10"><inline class="smallCaps">Functions</inline>.—</heading><chapeau>The Chairperson shall perform functions that include—</chapeau><subparagraph class="fontsize10" id="y39b56a37-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">“(A) </num><content>subject to subsection (d), developing a schedule for meetings of the Council;</content></subparagraph>
<subparagraph class="fontsize10" id="y39b56a38-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">“(B) </num><content>designating executive agencies to be represented on the Council under subsection (b)(1)(H);</content></subparagraph>
<subparagraph class="fontsize10" id="y39b56a39-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="C">“(C) </num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b56a3a-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Consultation.</p></sidenote><content>in consultation with the lead representative of each agency represented on the Council, developing a charter for the Council; and</content></subparagraph>
<subparagraph class="fontsize10" id="y39b56a3b-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="D">“(D) </num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b56a3c-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Deadline.</p></sidenote><content>not later than 7 days after completion of the charter, submitting the charter to the appropriate congressional committees and leadership.</content></subparagraph>
</paragraph>
</subsection>
<subsection class="firstIndent0 fontsize10" id="y39b56a3d-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="d">“(d) </num><heading class="fontsize10"><inline class="smallCaps">Meetings</inline><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b56a3e-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Deadline.</p></sidenote>.—</heading><content>The Council shall meet not later than 60 days after the date of the enactment of the Federal Acquisition Supply <page identifier="/us/stat/132/5180">132 STAT. 5180</page>
Chain Security Act of 2018 and not less frequently than quarterly thereafter.</content></subsection>
</section>
<section class="centered fontsize12" id="y39b56a3f-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658164"><num class="fontsize12" value="1323">“§ 1323.</num><heading class="fontsize12"><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b56a40-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180"><ref href="/us/usc/t41/s1323">41 USC 1323</ref>.</p></sidenote> Functions and authorities</heading><subsection class="firstIndent0 fontsize10" id="y39b56a41-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="a">“(a) </num><heading class="fontsize10"><inline class="smallCaps">In General</inline>.—</heading><chapeau>The Council shall perform functions that include the following:</chapeau><paragraph class="fontsize10" id="y39b56a42-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="1">“(1) </num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b56a43-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Recommenda-</p><p class="leftAlign firstIndent0 fontsize8" id="x39b56a44-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">tions.</p></sidenote><content>Identifying and recommending development by the National Institute of Standards and Technology of supply chain risk management standards, guidelines, and practices for executive agencies to use when assessing and developing mitigation strategies to address supply chain risks, particularly in the acquisition and use of covered articles under section 1326(a) of this title.</content></paragraph>
<paragraph class="fontsize10" id="y39b56a45-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="2">“(2) </num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b56a46-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Criteria.</p></sidenote><chapeau>Identifying or developing criteria for sharing information with executive agencies, other Federal entities, and non-Federal entities with respect to supply chain risk, including information related to the exercise of authorities provided under this section and sections 1326 and 4713 of this title. At a minimum, such criteria shall address—</chapeau><subparagraph class="fontsize10" id="y39b59157-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">“(A) </num><content>the content to be shared;</content></subparagraph>
<subparagraph class="fontsize10" id="y39b59158-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">“(B) </num><content>the circumstances under which sharing is mandated or voluntary; and</content></subparagraph>
<subparagraph class="fontsize10" id="y39b59159-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="C">“(C) </num><content>the circumstances under which it is appropriate for an executive agency to rely on information made available through such sharing in exercising the responsibilities and authorities provided under this section and section 4713 of this title.</content></subparagraph>
</paragraph>
<paragraph class="fontsize10" id="y39b5915a-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="3">“(3) </num><chapeau>Identifying an appropriate executive agency to—</chapeau><subparagraph class="fontsize10" id="y39b5915b-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">“(A) </num><content>accept information submitted by executive agencies based on the criteria established under paragraph (2);</content></subparagraph>
<subparagraph class="fontsize10" id="y39b5915c-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">“(B) </num><content>facilitate the sharing of information received under subparagraph (A) to support supply chain risk analyses under section 1326 of this title, recommendations under this section, and covered procurement actions under section 4713 of this title;</content></subparagraph>
<subparagraph class="fontsize10" id="y39b5915d-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="C">“(C) </num><content>share with the Council information regarding covered procurement actions by executive agencies taken under section 4713 of this title; and</content></subparagraph>
<subparagraph class="fontsize10" id="y39b5915e-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="D">“(D) </num><content>inform the Council of orders issued under this section.</content></subparagraph>
</paragraph>
<paragraph class="fontsize10" id="y39b5915f-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="4">“(4) </num><chapeau>Identifying, as appropriate, executive agencies to provide—</chapeau><subparagraph class="fontsize10" id="y39b59160-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">“(A) </num><content>shared services, such as support for making risk assessments, validation of products that may be suitable for acquisition, and mitigation activities; and</content></subparagraph>
<subparagraph class="fontsize10" id="y39b59161-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">“(B) </num><content>common contract solutions to support supply chain risk management activities, such as subscription services or machine-learning-enhanced analysis applications to support informed decision making.</content></subparagraph>
</paragraph>
<paragraph class="fontsize10" id="y39b59162-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="5">“(5) </num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b59163-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Guidance.</p></sidenote><content>Identifying and issuing guidance on additional steps that may be necessary to address supply chain risks arising in the course of executive agencies providing shared services, common contract solutions, acquisitions vehicles, or assisted acquisitions.</content></paragraph>
<paragraph class="fontsize10" id="y39b59164-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="6">“(6) </num><content>Engaging with the private sector and other nongovernmental stakeholders in performing the functions described in <page identifier="/us/stat/132/5181">132 STAT. 5181</page>
paragraphs (1) and (2) and on issues relating to the management of supply chain risks posed by the acquisition of covered articles.</content></paragraph>
<paragraph class="fontsize10" id="y39b59165-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="7">“(7) </num><content>Carrying out such other actions, as determined by the Council, that are necessary to reduce the supply chain risks posed by acquisitions and use of covered articles.</content></paragraph>
</subsection>
<subsection class="firstIndent0 fontsize10" id="y39b59166-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="b">“(b) </num><heading class="fontsize10"><inline class="smallCaps">Program Office and Committees</inline>.—</heading><content>The Council may establish a program office and any committees, working groups, or other constituent bodies the Council deems appropriate, in its sole and unreviewable discretion, to carry out its functions.</content></subsection>
<subsection class="firstIndent0 fontsize10" id="y39b59167-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="c">“(c) </num><heading class="fontsize10"><inline class="smallCaps">Authority for Exclusion or Removal Orders</inline>.—</heading><paragraph class="fontsize10" id="y39b59168-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="1">“(1) </num><heading class="fontsize10"><inline class="smallCaps">Criteria</inline><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b59169-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Procedures.</p></sidenote>.—</heading><chapeau>To reduce supply chain risk, the Council shall establish criteria and procedures for—</chapeau><subparagraph class="fontsize10" id="y39b5916a-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">“(A) </num><content>recommending orders applicable to executive agencies requiring the exclusion of sources or covered articles from executive agency procurement actions (in this section referred to as ‘exclusion orders’);</content></subparagraph>
<subparagraph class="fontsize10" id="y39b5916b-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">“(B) </num><content>recommending orders applicable to executive agencies requiring the removal of covered articles from executive agency information systems (in this section referred to as ‘removal orders’);</content></subparagraph>
<subparagraph class="fontsize10" id="y39b5916c-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="C">“(C) </num><content>requesting and approving exceptions to an issued exclusion or removal order when warranted by circumstances, including alternative mitigation actions or other findings relating to the national interest, including national security reviews, national security investigations, or national security agreements; and</content></subparagraph>
<subparagraph class="fontsize10" id="y39b5916d-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="D">“(D) </num><content>ensuring that recommended orders do not conflict with standards and guidelines issued under section 11331 of title 40 and that the Council consults with the Director of the National Institute of Standards and Technology regarding any recommended orders that would implement standards and guidelines developed by the National Institute of Standards and Technology.</content></subparagraph>
</paragraph>
<paragraph class="fontsize10" id="y39b5916e-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="2">“(2) </num><heading class="fontsize10"><inline class="smallCaps">Recommendations</inline>.—</heading><chapeau>The Council shall use the criteria established under paragraph (1), information made available under subsection (a)(3), and any other information the Council determines appropriate to issue recommendations, for application to executive agencies or any subset thereof, regarding the exclusion of sources or covered articles from any executive agency procurement action, including source selection and consent for a contractor to subcontract, or the removal of covered articles from executive agency information systems. Such recommendations shall include—</chapeau><subparagraph class="fontsize10" id="y39b5916f-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">“(A) </num><content>information necessary to positively identify the sources or covered articles recommended for exclusion or removal;</content></subparagraph>
<subparagraph class="fontsize10" id="y39b59170-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">“(B) </num><content>information regarding the scope and applicability of the recommended exclusion or removal order;</content></subparagraph>
<subparagraph class="fontsize10" id="y39b59171-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="C">“(C) </num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b59172-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Summary.</p></sidenote><content>a summary of any risk assessment reviewed or conducted in support of the recommended exclusion or removal order;</content></subparagraph>
<subparagraph class="fontsize10" id="y39b59173-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="D">“(D) </num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b59174-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Summary.</p></sidenote><content>a summary of the basis for the recommendation, including a discussion of less intrusive measures that were considered and why such measures were not reasonably available to reduce supply chain risk;<page identifier="/us/stat/132/5182">132 STAT. 5182</page></content></subparagraph>
<subparagraph class="fontsize10" id="y39b59175-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="E">“(E) </num><content>a description of the actions necessary to implement the recommended exclusion or removal order; and</content></subparagraph>
<subparagraph class="fontsize10" id="y39b59176-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="F">“(F) </num><content>where practicable, in the Council’s sole and unreviewable discretion, a description of mitigation steps that could be taken by the source that may result in the Council rescinding a recommendation.</content></subparagraph>
</paragraph>
<paragraph class="fontsize10" id="y39b59177-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="3">“(3) </num><heading class="fontsize10"><inline class="smallCaps">Notice of recommendation and review</inline>.—</heading><chapeau>A notice of the Council’s recommendation under paragraph (2) shall be issued to any source named in the recommendation advising—</chapeau><subparagraph class="fontsize10" id="y39b59178-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">“(A) </num><content>that a recommendation has been made;</content></subparagraph>
<subparagraph class="fontsize10" id="y39b59179-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">“(B) </num><content>of the criteria the Council relied upon under paragraph (1) and, to the extent consistent with national security and law enforcement interests, of information that forms the basis for the recommendation;</content></subparagraph>
<subparagraph class="fontsize10" id="y39b5917a-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="C">“(C) </num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b5917b-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Deadline.</p></sidenote><content>that, within 30 days after receipt of notice, the source may submit information and argument in opposition to the recommendation;</content></subparagraph>
<subparagraph class="fontsize10" id="y39b5917c-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="D">“(D) </num><content>of the procedures governing the review and possible issuance of an exclusion or removal order pursuant to paragraph (5); and</content></subparagraph>
<subparagraph class="fontsize10" id="y39b5917d-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="E">“(E) </num><content>where practicable, in the Council’s sole and unreviewable discretion, a description of mitigation steps that could be taken by the source that may result in the Council rescinding the recommendation.</content></subparagraph>
</paragraph>
<paragraph class="fontsize10" id="y39b5917e-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="4">“(4) </num><heading class="fontsize10"><inline class="smallCaps">Confidentiality</inline>.—</heading><chapeau>Any notice issued to a source under paragraph (3) shall be kept confidential until—</chapeau><subparagraph class="fontsize10" id="y39b5917f-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">“(A) </num><content>an exclusion or removal order is issued pursuant to paragraph (5); and</content></subparagraph>
<subparagraph class="fontsize10" id="y39b59180-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">“(B) </num><content>the source has been notified pursuant to paragraph (6).</content></subparagraph>
</paragraph>
<paragraph class="fontsize10" id="y39b59181-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="5">“(5) </num><heading class="fontsize10"><inline class="smallCaps">Exclusion and removal orders</inline>.—</heading><subparagraph class="fontsize10" id="y39b59182-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">“(A) </num><heading class="fontsize10"><inline class="smallCaps">Order issuance</inline>.—</heading><chapeau>Recommendations of the Council under paragraph (2), together with any information submitted by a source under paragraph (3) related to such a recommendation, shall be reviewed by the following officials, who may issue exclusion and removal orders based upon such recommendations:</chapeau><clause class="fontsize10" id="y39b59183-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658126"><num class="fontsize10" style="-uslm-lc:emspace2" value="i">“(i) </num><content>The Secretary of Homeland Security, for exclusion and removal orders applicable to civilian agencies, to the extent not covered by clause (ii) or (iii).</content></clause>
<clause class="fontsize10" id="y39b59184-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658126"><num class="fontsize10" style="-uslm-lc:emspace2" value="ii">“(ii) </num><content>The Secretary of Defense, for exclusion and removal orders applicable to the Department of Defense and national security systems other than sensitive compartmented information systems.</content></clause>
<clause class="fontsize10" id="y39b59185-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658126"><num class="fontsize10" style="-uslm-lc:emspace2" value="iii">“(iii) </num><content>The Director of National Intelligence, for exclusion and removal orders applicable to the intelligence community and sensitive compartmented information systems, to the extent not covered by clause (ii).</content></clause>
</subparagraph>
<subparagraph class="fontsize10" id="y39b59186-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">“(B) </num><heading class="fontsize10"><inline class="smallCaps">Delegation</inline>.—</heading><content>The officials identified in subparagraph (A) may not delegate any authority under this subparagraph to an official below the level one level below the Deputy Secretary or Principal Deputy Director, except that the Secretary of Defense may delegate authority for removal orders to the Commander of the United States Cyber Command, who may not redelegate such authority <page identifier="/us/stat/132/5183">132 STAT. 5183</page>
to an official below the level one level below the Deputy Commander.</content></subparagraph>
<subparagraph class="fontsize10" id="y39b59187-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="C">“(C) </num><heading class="fontsize10"><inline class="smallCaps">Facilitation of exclusion orders</inline>.—</heading><content>If officials identified under this paragraph from the Department of Homeland Security, the Department of Defense, and the Office of the Director of National Intelligence issue orders collectively resulting in a governmentwide exclusion, the Administrator for General Services and officials at other executive agencies responsible for management of the Federal Supply Schedules, governmentwide acquisition contracts and multi-agency contracts shall help facilitate implementation of such orders by removing the covered articles or sources identified in the orders from such contracts.</content></subparagraph>
<subparagraph class="fontsize10" id="y39b59188-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="D">“(D) </num><heading class="fontsize10"><inline class="smallCaps">Review of exclusion and removal orders</inline>.—</heading><content>The officials identified under this paragraph shall review all exclusion and removal orders issued under subparagraph (A) not less frequently than annually pursuant to procedures established by the Council.</content></subparagraph>
<subparagraph class="fontsize10" id="y39b59189-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="E">“(E) </num><heading class="fontsize10"><inline class="smallCaps">Rescission</inline>.—</heading><content>Orders issued pursuant to subparagraph (A) may be rescinded by an authorized official from the relevant issuing agency.</content></subparagraph>
</paragraph>
<paragraph class="fontsize10" id="y39b5918a-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="6">“(6) </num><heading class="fontsize10"><inline class="smallCaps">Notifications</inline>.—</heading><chapeau>Upon issuance of an exclusion or removal order pursuant to paragraph (5)(A), the official identified under that paragraph who issued the order shall—</chapeau><subparagraph class="fontsize10" id="y39b5918b-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">“(A) </num><chapeau>notify any source named in the order of—</chapeau><clause class="fontsize10" id="y39b5918c-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658126"><num class="fontsize10" style="-uslm-lc:emspace2" value="i">“(i) </num><content>the exclusion or removal order; and</content></clause>
<clause class="fontsize10" id="y39b5918d-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658126"><num class="fontsize10" style="-uslm-lc:emspace2" value="ii">“(ii) </num><content>to the extent consistent with national security and law enforcement interests, information that forms the basis for the order;</content></clause>
</subparagraph>
<subparagraph class="fontsize10" id="y39b5918e-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">“(B) </num><content>provide classified or unclassified notice of the exclusion or removal order to the appropriate congressional committees and leadership; and</content></subparagraph>
<subparagraph class="fontsize10" id="y39b5918f-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="C">“(C) </num><content>provide the exclusion or removal order to the agency identified in subsection (a)(3).</content></subparagraph>
</paragraph>
<paragraph class="fontsize10" id="y39b59190-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="7">“(7) </num><heading class="fontsize10"><inline class="smallCaps">Compliance</inline>.—</heading><content>Executive agencies shall comply with exclusion and removal orders issued pursuant to paragraph (5).</content></paragraph>
</subsection>
<subsection class="firstIndent0 fontsize10" id="y39b59191-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="d">“(d) </num><heading class="fontsize10"><inline class="smallCaps">Authority To Request Information</inline>.—</heading><content>The Council may request such information from executive agencies as is necessary for the Council to carry out its functions.</content></subsection>
<subsection class="firstIndent0 fontsize10" id="y39b59192-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="e">“(e) </num><heading class="fontsize10"><inline class="smallCaps">Relationship to Other Councils</inline><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b59193-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Consultation.</p><p class="leftAlign firstIndent0 fontsize8" id="x39b59194-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Coordination.</p></sidenote>.—</heading><content>The Council shall consult and coordinate, as appropriate, with other relevant councils and interagency committees, including the Chief Information Officers Council, the Chief Acquisition Officers Council, the Federal Acquisition Regulatory Council, and the Committee on Foreign Investment in the United States, with respect to supply chain risks posed by the acquisition and use of covered articles.</content></subsection>
<subsection class="firstIndent0 fontsize10" id="y39b59195-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="f">“(f) </num><heading class="fontsize10"><inline class="smallCaps">Rules of Construction</inline>.—</heading><chapeau>Nothing in this section shall be construed—</chapeau><paragraph class="fontsize10" id="y39b59196-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="1">“(1) </num><content>to limit the authority of the Office of Federal Procurement Policy to carry out the responsibilities of that Office under any other provision of law; or</content></paragraph>
<paragraph class="fontsize10" id="y39b59197-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="2">“(2) </num><content>to authorize the issuance of an exclusion or removal order based solely on the fact of foreign ownership of a potential procurement source that is otherwise qualified to enter into procurement contracts with the Federal Government.<page identifier="/us/stat/132/5184">132 STAT. 5184</page></content></paragraph>
</subsection>
</section>
<section class="centered fontsize12" id="y39b59198-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658164"><num class="fontsize12" value="1324">“§ 1324.</num><heading class="fontsize12"><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b59199-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180"><ref href="/us/usc/t41/s1324">41 USC 1324</ref>.</p></sidenote> Strategic plan</heading><subsection class="firstIndent0 fontsize10" id="y39b5919a-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="a">“(a) </num><heading class="fontsize10"><inline class="smallCaps">In General</inline>.—</heading><chapeau><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b5919b-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Deadline.</p></sidenote>Not later than 180 days after the date of the enactment of the Federal Acquisition Supply Chain Security Act of 2018, the Council shall develop a strategic plan for addressing supply chain risks posed by the acquisition of covered articles and for managing such risks that includes—</chapeau><paragraph class="fontsize10" id="y39b5919c-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="1">“(1) </num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b5919d-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Criteria.</p></sidenote><content>the criteria and processes required under section 1323(a) of this title, including a threshold and requirements for sharing relevant information about such risks with all executive agencies and, as appropriate, with other Federal entities and non-Federal entities;</content></paragraph>
<paragraph class="fontsize10" id="y39b5919e-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="2">“(2) </num><content>an identification of existing authorities for addressing such risks;</content></paragraph>
<paragraph class="fontsize10" id="y39b5919f-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="3">“(3) </num><content>an identification and promulgation of best practices and procedures and available resources for executive agencies to assess and mitigate such risks;</content></paragraph>
<paragraph class="fontsize10" id="y39b591a0-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="4">“(4) </num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b591a1-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Recommenda-</p><p class="leftAlign firstIndent0 fontsize8" id="x39b591a2-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">tions.</p></sidenote><content>recommendations for any legislative, regulatory, or other policy changes to improve efforts to address such risks;</content></paragraph>
<paragraph class="fontsize10" id="y39b591a3-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="5">“(5) </num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b591a4-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Recommenda-</p><p class="leftAlign firstIndent0 fontsize8" id="x39b591a5-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">tions.</p></sidenote><content>recommendations for any legislative, regulatory, or other policy changes to incentivize the adoption of best practices for supply chain risk management by the private sector;</content></paragraph>
<paragraph class="fontsize10" id="y39b5b8b6-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="6">“(6) </num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b5b8b7-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Evaluation.</p></sidenote><content>an evaluation of the effect of implementing new policies or procedures on existing contracts and the procurement process;</content></paragraph>
<paragraph class="fontsize10" id="y39b5b8b8-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="7">“(7) </num><content>a plan for engaging with executive agencies, the private sector, and other nongovernmental stakeholders to address such risks;</content></paragraph>
<paragraph class="fontsize10" id="y39b5b8b9-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="8">“(8) </num><content>a plan for identification, assessment, mitigation, and vetting of supply chain risks from existing and prospective information and communications technology made available by executive agencies to other executive agencies through common contract solutions, shared services, acquisition vehicles, or other assisted acquisition services; and</content></paragraph>
<paragraph class="fontsize10" id="y39b5b8ba-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="9">“(9) </num><chapeau>plans to strengthen the capacity of all executive agencies to conduct assessments of—</chapeau><subparagraph class="fontsize10" id="y39b5b8bb-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">“(A) </num><content>the supply chain risk posed by the acquisition of covered articles; and</content></subparagraph>
<subparagraph class="fontsize10" id="y39b5b8bc-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">“(B) </num><content>compliance with the requirements of this subchapter.</content></subparagraph>
</paragraph>
</subsection>
<subsection class="firstIndent0 fontsize10" id="y39b5b8bd-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="b">“(b) </num><heading class="fontsize10"><inline class="smallCaps">Submission to Congress</inline><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b5b8be-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Deadline.</p></sidenote>.—</heading><content>Not later than 7 calendar days after completion of the strategic plan required by subsection (a), the Chairperson of the Council shall submit the plan to the appropriate congressional committees and leadership.</content></subsection>
</section>
<section class="centered fontsize12" id="y39b5b8bf-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658164"><num class="fontsize12" value="1325">“§ 1325.</num><heading class="fontsize12"><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b5b8c0-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180"><ref href="/us/usc/t41/s1325">41 USC 1325</ref>.</p></sidenote> Annual report</heading><content class="indentUp0 firstIndent0 fontsize10" style="-uslm-lc:I658120">  “Not later than December 31 of each year, the Chairperson of the Council shall submit to the appropriate congressional committees and leadership a report on the activities of the Council during the preceding 12-month period.</content></section>
<section class="centered fontsize12" id="y39b5b8c1-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658164"><num class="fontsize12" value="1326">“§ 1326.</num><heading class="fontsize12"><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b5b8c2-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180"><ref href="/us/usc/t41/s1326">41 USC 1326</ref>.</p></sidenote> Requirements for executive agencies</heading><subsection class="firstIndent0 fontsize10" id="y39b5b8c3-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="a">“(a) </num><heading class="fontsize10"><inline class="smallCaps">In General</inline>.—</heading><chapeau>The head of each executive agency shall be responsible for—</chapeau><paragraph class="fontsize10" id="y39b5b8c4-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="1">“(1) </num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b5b8c5-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Assessment.</p></sidenote><content>assessing the supply chain risk posed by the acquisition and use of covered articles and avoiding, mitigating, accepting, or transferring that risk, as appropriate and consistent with <page identifier="/us/stat/132/5185">132 STAT. 5185</page>
the standards, guidelines, and practices identified by the Council under section 1323(a)(1); and</content></paragraph>
<paragraph class="fontsize10" id="y39b5b8c6-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="2">“(2) </num><content>prioritizing supply chain risk assessments conducted under paragraph (1) based on the criticality of the mission, system, component, service, or asset.</content></paragraph>
</subsection>
<subsection class="firstIndent0 fontsize10" id="y39b5b8c7-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="b">“(b) </num><heading class="fontsize10"><inline class="smallCaps">Inclusions</inline>.—</heading><chapeau>The responsibility for assessing supply chain risk described in subsection (a) includes—</chapeau><paragraph class="fontsize10" id="y39b5b8c8-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="1">“(1) </num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b5b8c9-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Strategy.</p><p class="leftAlign firstIndent0 fontsize8" id="x39b5b8ca-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Plan.</p><p class="leftAlign firstIndent0 fontsize8" id="x39b5b8cb-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Policy.</p><p class="leftAlign firstIndent0 fontsize8" id="x39b5b8cc-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Processes.</p></sidenote><content>developing an overall supply chain risk management strategy and implementation plan and policies and processes to guide and govern supply chain risk management activities;</content></paragraph>
<paragraph class="fontsize10" id="y39b5b8cd-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="2">“(2) </num><content>integrating supply chain risk management practices throughout the life cycle of the system, component, service, or asset;</content></paragraph>
<paragraph class="fontsize10" id="y39b5b8ce-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="3">“(3) </num><content>limiting, avoiding, mitigating, accepting, or transferring any identified risk;</content></paragraph>
<paragraph class="fontsize10" id="y39b5b8cf-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="4">“(4) </num><content>sharing relevant information with other executive agencies as determined appropriate by the Council in a manner consistent with section 1323(a) of this title;</content></paragraph>
<paragraph class="fontsize10" id="y39b5b8d0-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="5">“(5) </num><content>reporting on progress and effectiveness of the agency’s supply chain risk management consistent with guidance issued by the Office of Management and Budget and the Council; and</content></paragraph>
<paragraph class="fontsize10" id="y39b5b8d1-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="6">“(6) </num><content>ensuring that all relevant information, including classified information, with respect to acquisitions of covered articles that may pose a supply chain risk, consistent with section 1323(a) of this title, is incorporated into existing processes of the agency for conducting assessments described in subsection (a) and ongoing management of acquisition programs, including any identification, investigation, mitigation, or remediation needs.</content></paragraph>
</subsection>
<subsection class="firstIndent0 fontsize10" id="y39b5b8d2-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="c">“(c) </num><heading class="fontsize10"><inline class="smallCaps">Interagency Acquisitions</inline>.—</heading><paragraph class="fontsize10" id="y39b5b8d3-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="1">“(1) </num><heading class="fontsize10"><inline class="smallCaps">In general</inline>.—</heading><content>Except as provided in paragraph (2), in the case of an interagency acquisition, subsection (a) shall be carried out by the head of the executive agency whose funds are being used to procure the covered article.</content></paragraph>
<paragraph class="fontsize10" id="y39b5b8d4-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="2">“(2) </num><heading class="fontsize10"><inline class="smallCaps">Assisted acquisitions</inline><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b5b8d5-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Determination.</p></sidenote>.—</heading><content>In an assisted acquisition, the parties to the acquisition shall determine, as part of the interagency agreement governing the acquisition, which agency is responsible for carrying out subsection (a).</content></paragraph>
<paragraph class="fontsize10" id="y39b5b8d6-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="3">“(3) </num><heading class="fontsize10"><inline class="smallCaps">Definitions</inline>.—</heading><content>In this subsection, the terms ‘assisted acquisition’ and ‘interagency acquisition’ have the meanings given those terms in <ref href="/us/cfr/t48/s2.101">section 2.101 of title 48, Code of Federal Regulations</ref> (or any corresponding similar regulation or ruling).</content></paragraph>
</subsection>
<subsection class="firstIndent0 fontsize10" id="y39b5b8d7-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="d">“(d) </num><heading class="fontsize10"><inline class="smallCaps">Assistance</inline>.—</heading><chapeau>The Secretary of Homeland Security may—</chapeau><paragraph class="fontsize10" id="y39b5b8d8-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="1">“(1) </num><content>assist executive agencies in conducting risk assessments described in subsection (a) and implementing mitigation requirements for information and communications technology; and</content></paragraph>
<paragraph class="fontsize10" id="y39b5b8d9-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="2">“(2) </num><content>provide such additional guidance or tools as are necessary to support actions taken by executive agencies.</content></paragraph>
</subsection>
</section>
<section class="centered fontsize12" id="y39b5b8da-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658164"><num class="fontsize12" value="1327">“§ 1327.</num><heading class="fontsize12"><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b5b8db-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180"><ref href="/us/usc/t41/s1327">41 USC 1327</ref>.</p></sidenote> Judicial review procedures</heading><subsection class="firstIndent0 fontsize10" id="y39b5b8dc-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="a">“(a) </num><heading class="fontsize10"><inline class="smallCaps">In General</inline>.—</heading><content>Except as provided in subsection (b) and chapter 71 of this title, and notwithstanding any other provision of law, an action taken under section 1323 or 4713 of this title, or any action taken by an executive agency to implement such an action, shall not be subject to administrative review or judicial <page identifier="/us/stat/132/5186">132 STAT. 5186</page>
review, including bid protests before the Government Accountability Office or in any Federal court.</content></subsection>
<subsection class="firstIndent0 fontsize10" id="y39b5b8dd-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="b">“(b) </num><heading class="fontsize10"><inline class="smallCaps">Petitions</inline>.—</heading><paragraph class="fontsize10" id="y39b5b8de-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="1">“(1) </num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b5b8df-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Deadline.</p></sidenote><heading class="fontsize10"><inline class="smallCaps">In general</inline>.—</heading><content>Not later than 60 days after a party is notified of an exclusion or removal order under section 1323(c)(6) of this title or a covered procurement action under section 4713 of this title, the party may file a petition for judicial review in the United States Court of Appeals for the District of Columbia Circuit claiming that the issuance of the exclusion or removal order or covered procurement action is unlawful.</content></paragraph>
<paragraph class="fontsize10" id="y39b5b8e0-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="2">“(2) </num><heading class="fontsize10"><inline class="smallCaps">Standard of review</inline>.—</heading><chapeau>The Court shall hold unlawful a covered action taken under sections 1323 or 4713 of this title, in response to a petition that the court finds to be—</chapeau><subparagraph class="fontsize10" id="y39b5b8e1-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">“(A) </num><content>arbitrary, capricious, an abuse of discretion, or otherwise not in accordance with law;</content></subparagraph>
<subparagraph class="fontsize10" id="y39b5b8e2-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">“(B) </num><content>contrary to constitutional right, power, privilege, or immunity;</content></subparagraph>
<subparagraph class="fontsize10" id="y39b5b8e3-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="C">“(C) </num><content>in excess of statutory jurisdiction, authority, or limitation, or short of statutory right;</content></subparagraph>
<subparagraph class="fontsize10" id="y39b5b8e4-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="D">“(D) </num><content>lacking substantial support in the administrative record taken as a whole or in classified information submitted to the court under paragraph (3); or</content></subparagraph>
<subparagraph class="fontsize10" id="y39b5b8e5-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="E">“(E) </num><content>not in accord with procedures required by law.</content></subparagraph>
</paragraph>
<paragraph class="fontsize10" id="y39b5b8e6-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="3">“(3) </num><heading class="fontsize10"><inline class="smallCaps">Exclusive jurisdiction</inline>.—</heading><content>The United States Court of Appeals for the District of Columbia Circuit shall have exclusive jurisdiction over claims arising under sections 1323(c)(5) or 4713 of this title against the United States, any United States department or agency, or any component or official of any such department or agency, subject to review by the Supreme Court of the United States under section 1254 of title 28.</content></paragraph>
<paragraph class="fontsize10" id="y39b5b8e7-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="4">“(4) </num><heading class="fontsize10"><inline class="smallCaps">Administrative record and procedures</inline>.—</heading><subparagraph class="fontsize10" id="y39b5b8e8-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">“(A) </num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b5b8e9-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Applicability.</p></sidenote><heading class="fontsize10"><inline class="smallCaps">In general</inline>.—</heading><content>The procedures described in this paragraph shall apply to the review of a petition under this section.</content></subparagraph>
<subparagraph class="fontsize10" id="y39b5b8ea-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">“(B) </num><heading class="fontsize10"><inline class="smallCaps">Administrative record</inline>.—</heading><clause class="fontsize10" id="y39b5b8eb-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658126"><num class="fontsize10" style="-uslm-lc:emspace2" value="i">“(i) </num><heading class="fontsize10"><inline class="smallCaps">Filing of record</inline>.—</heading><content>The United States shall file with the court an administrative record, which shall consist of the information that the appropriate official relied upon in issuing an exclusion or removal order under section 1323(c)(5) or a covered procurement action under section 4713 of this title.</content></clause>
<clause class="fontsize10" id="y39b5b8ec-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658126"><num class="fontsize10" style="-uslm-lc:emspace2" value="ii">“(ii) </num><heading class="fontsize10"><inline class="smallCaps">Unclassified, nonprivileged information</inline>.—</heading><content>All unclassified information contained in the administrative record that is not otherwise privileged or subject to statutory protections shall be provided to the petitioner with appropriate protections for any privileged or confidential trade secrets and commercial or financial information.</content></clause>
<clause class="fontsize10" id="y39b5b8ed-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658126"><num class="fontsize10" style="-uslm-lc:emspace2" value="iii">“(iii) </num><heading class="fontsize10"><inline class="smallCaps">In camera and ex parte</inline>.—</heading><chapeau>The following information may be included in the administrative record and shall be submitted only to the court ex parte and in camera:</chapeau><subclause class="fontsize10" id="y39b5b8ee-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658128"><num class="fontsize10" style="-uslm-lc:emspace2" value="I">“(I) </num><content>Classified information.<page identifier="/us/stat/132/5187">132 STAT. 5187</page></content></subclause>
<subclause class="fontsize10" id="y39b5b8ef-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658128"><num class="fontsize10" style="-uslm-lc:emspace2" value="II">“(II) </num><content>Sensitive security information, as defined by <ref href="/us/cfr/t49/s1520.5">section 1520.5 of title 49, Code of Federal Regulations</ref>.</content></subclause>
<subclause class="fontsize10" id="y39b5b8f0-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658128"><num class="fontsize10" style="-uslm-lc:emspace2" value="III">“(III) </num><content>Privileged law enforcement information.</content></subclause>
<subclause class="fontsize10" id="y39b5b8f1-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658128"><num class="fontsize10" style="-uslm-lc:emspace2" value="IV">“(IV) </num><content>Information obtained or derived from any activity authorized under the Foreign Intelligence Surveillance Act of 1978 (<ref href="/us/usc/t50/s1801/etseq">50 U.S.C. 1801 et seq.</ref>), except that, with respect to such information, subsections (c), (e), (f), (g), and (h) of section 106 (<ref href="/us/usc/t50/s1806">50 U.S.C. 1806</ref>), subsections (d), (f), (g), (h), and (i) of section 305 (<ref href="/us/usc/t50/s1825">50 U.S.C. 1825</ref>), subsections (c), (e), (f), (g), and (h) of section 405 (<ref href="/us/usc/t50/s1845">50 U.S.C. 1845</ref>), and section 706 (<ref href="/us/usc/t50/s1881e">50 U.S.C. 1881e</ref>) of that Act shall not apply.</content></subclause>
<subclause class="fontsize10" id="y39b5b8f2-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658128"><num class="fontsize10" style="-uslm-lc:emspace2" value="V">“(V) </num><content>Information subject to privilege or protections under any other provision of law.</content></subclause>
</clause>
<clause class="fontsize10" id="y39b5b8f3-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658126"><num class="fontsize10" style="-uslm-lc:emspace2" value="iv">“(iv) </num><heading class="fontsize10"><inline class="smallCaps">Under seal</inline>.—</heading><content>Any information that is part of the administrative record filed ex parte and in camera under clause (iii), or cited by the court in any decision, shall be treated by the court consistent with the provisions of this subparagraph and shall remain under seal and preserved in the records of the court to be made available consistent with the above provisions in the event of further proceedings. In no event shall such information be released to the petitioner or as part of the public record.</content></clause>
<clause class="fontsize10" id="y39b5b8f4-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658126"><num class="fontsize10" style="-uslm-lc:emspace2" value="v">“(v) </num><heading class="fontsize10"><inline class="smallCaps">Return</inline>.—</heading><content>After the expiration of the time to seek further review, or the conclusion of further proceedings, the court shall return the administrative record, including any and all copies, to the United States.</content></clause>
</subparagraph>
<subparagraph class="fontsize10" id="y39b5b8f5-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="C">“(C) </num><heading class="fontsize10"><inline class="smallCaps">Exclusive remedy</inline><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b5b8f6-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Determination.</p></sidenote>.—</heading><content>A determination by the court under this subsection shall be the exclusive judicial remedy for any claim described in this section against the United States, any United States department or agency, or any component or official of any such department or agency.</content></subparagraph>
<subparagraph class="fontsize10" id="y39b5b8f7-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="D">“(D) </num><heading class="fontsize10"><inline class="smallCaps">Rule of construction</inline>.—</heading><content>Nothing in this section shall be construed as limiting, superseding, or preventing the invocation of, any privileges or defenses that are otherwise available at law or in equity to protect against the disclosure of information.</content></subparagraph>
</paragraph>
</subsection>
<subsection class="firstIndent0 fontsize10" id="y39b5b8f8-e830-11f0-a1e4-69761a48a15a" role="definitions" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="c">“(c) </num><heading class="fontsize10"><inline class="smallCaps">Definition</inline>.—</heading><chapeau>In this section, the term ‘<term>classified information</term>’—</chapeau><paragraph class="fontsize10" id="y39b5b8f9-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="1">“(1) </num><content>has the meaning given that term in section 1(a) of the Classified Information Procedures Act (<ref href="/us/usc/t18/app">18 U.S.C. App.</ref>); and</content></paragraph>
<paragraph class="fontsize10" id="y39b5b8fa-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="2">“(2) </num><chapeau>includes—</chapeau><subparagraph class="fontsize10" id="y39b5b8fb-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">“(A) </num><content>any information or material that has been determined by the United States Government pursuant to an Executive order, statute, or regulation to require protection against unauthorized disclosure for reasons of national security; and</content></subparagraph>
<subparagraph class="fontsize10" id="y39b5b8fc-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">“(B) </num><content>any restricted data, as defined in section 11 of the Atomic Energy Act of 1954 (<ref href="/us/usc/t42/s2014">42 U.S.C. 2014</ref>).<page identifier="/us/stat/132/5188">132 STAT. 5188</page></content></subparagraph>
</paragraph>
</subsection>
</section>
<section class="centered fontsize12" id="y39b5b8fd-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658164"><num class="fontsize12" value="1328">“§ 1328.</num><heading class="fontsize12"><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b5b8fe-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180"><ref href="/us/usc/t41/s1328">41 USC 1328</ref>.</p></sidenote> Termination</heading><content class="indentUp0 firstIndent0 fontsize10" style="-uslm-lc:I658120">  “This subchapter shall terminate on the date that is 5 years after the date of the enactment of the Federal Acquisition Supply Chain Security Act of 2018.”</content></section>
</subchapter>
</quotedContent>.</content></subsection>
<subsection class="firstIndent0 fontsize10" id="y39b5b8ff-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tII/s202/b" role="instruction" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="b">(b) </num><heading class="fontsize10"><inline class="smallCaps">Clerical Amendment</inline>.—</heading><content>The table of sections at the beginning of chapter 13 of such title<sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b5b900-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180"><ref href="/us/usc/t41/s1301">41 USC 1301</ref> prec.</p></sidenote> <amendingAction type="amend">is amended</amendingAction> by <amendingAction type="add">adding</amendingAction> at the end the following new items:<quotedContent><toc>
<referenceItem role="subchapter" style="-uslm-lc:I658274">
<designator><inline class="smallCaps"> “subchapter iii—</inline></designator>
<label><inline class="smallCaps">federal acquisition supply chain security</inline></label>
</referenceItem><headingItem role="section" style="-uslm-lc:I658242">
<designator>“Sec.</designator>
<label/>
</headingItem><referenceItem role="section" style="-uslm-lc:I658242">
<designator>“1321. </designator>
<label>Definitions.</label>
</referenceItem><referenceItem role="section" style="-uslm-lc:I658242">
<designator>“1322. </designator>
<label>Federal Acquisition Security Council establishment and membership.</label>
</referenceItem><referenceItem role="section" style="-uslm-lc:I658242">
<designator>“1323. </designator>
<label>Functions and authorities.</label>
</referenceItem><referenceItem role="section" style="-uslm-lc:I658242">
<designator>“1324. </designator>
<label>Strategic plan.</label>
</referenceItem><referenceItem role="section" style="-uslm-lc:I658242">
<designator>“1325. </designator>
<label>Annual report.</label>
</referenceItem><referenceItem role="section" style="-uslm-lc:I658242">
<designator>“1326. </designator>
<label>Requirements for executive agencies.</label>
</referenceItem><referenceItem role="section" style="-uslm-lc:I658242">
<designator>“1327. </designator>
<label>Judicial review procedures.</label>
</referenceItem><referenceItem role="section" style="-uslm-lc:I658242">
<designator>“1328. </designator>
<label>Termination.”.<?GPOvSpace 04?></label>
</referenceItem></toc>
</quotedContent></content></subsection>
<subsection class="firstIndent0 fontsize10" id="y39b5df11-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tII/s202/c" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="c">(c) </num><heading class="fontsize10"><inline class="smallCaps">Effective Date</inline><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b5df12-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Applicability.</p><p class="leftAlign firstIndent0 fontsize8" id="x39b5df13-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180"><ref href="/us/usc/t41/s1321">41 USC 1321 note</ref>.</p></sidenote>.—</heading><content>The amendments made by this section shall take effect on the date that is 90 days after the date of the enactment of this Act and shall apply to contracts that are awarded before, on, or after that date.</content></subsection>
<subsection class="firstIndent0 fontsize10" id="y39b5df14-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tII/s202/d" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="d">(d) </num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b5df15-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Deadlines.</p><p class="leftAlign firstIndent0 fontsize8" id="x39b5df16-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180"><ref href="/us/usc/t41/s1321">41 USC 1321 note</ref>.</p></sidenote><heading class="fontsize10"><inline class="smallCaps">Implementation</inline>.—</heading><paragraph class="fontsize10" id="y39b5df17-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tII/s202/d/1" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="1">(1) </num><heading class="fontsize10"><inline class="smallCaps">Interim final rule</inline>.—</heading><content>Not later than one year after the date of the enactment of this Act, the Federal Acquisition Security Council shall prescribe an interim final rule to implement <ref href="/us/usc/t41/ch13/schIII">subchapter III of chapter 13 of title 41, United States Code</ref>, as added by subsection (a).</content></paragraph>
<paragraph class="fontsize10" id="y39b5df18-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tII/s202/d/2" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="2">(2) </num><heading class="fontsize10"><inline class="smallCaps">Final rule</inline><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b5df19-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Public comments.</p></sidenote>.—</heading><content>Not later than one year after prescribing the interim final rule under paragraph (1) and considering public comments with respect to such interim final rule, the Council shall prescribe a final rule to implement <ref href="/us/usc/t41/ch13/schIII">subchapter III of chapter 13 of title 41, United States Code</ref>, as added by subsection (a).</content></paragraph>
<paragraph class="fontsize10" id="y39b5df1a-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tII/s202/d/3" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="3">(3) </num><heading class="fontsize10"><inline class="smallCaps">Failure to act</inline>.—</heading><subparagraph class="fontsize10" id="y39b5df1b-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tII/s202/d/3/A" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">(A) </num><heading class="fontsize10"><inline class="smallCaps">In general</inline><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b5df1c-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Reports.</p><p class="leftAlign firstIndent0 fontsize8" id="x39b5df1d-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Estimate.</p></sidenote>.—</heading><content>If the Council does not issue a final rule in accordance with paragraph (2) on or before the last day of the one-year period referred to in that paragraph, the Council shall submit to the appropriate congressional committees and leadership, not later than 10 days after such last day and every 90 days thereafter until the final rule is issued, a report explaining why the final rule was not timely issued and providing an estimate of the earliest date on which the final rule will be issued.</content></subparagraph>
<subparagraph class="fontsize10" id="y39b5df1e-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tII/s202/d/3/B" role="definitions" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">(B) </num><heading class="fontsize10"><inline class="smallCaps">Appropriate congressional committees and leadership defined</inline>.—</heading><content>In this paragraph, the term “<term>appropriate congressional committees and leadership</term>” has the meaning given that term in <ref href="/us/usc/t41/s1321">section 1321 of title 41, United States Code</ref>, as added by subsection (a).</content></subparagraph>
</paragraph>
</subsection>
</section>
<section id="d140329e2308" identifier="/us/pl/115/390/tII/s203" style="-uslm-lc:I658143"><num class="fontsize12" value="203">SEC. 203. </num><heading>AUTHORITIES OF EXECUTIVE AGENCIES RELATING TO MITIGATING SUPPLY CHAIN RISKS IN THE PROCUREMENT OF COVERED ARTICLES.</heading><subsection class="firstIndent0 fontsize10" id="y39b6a26f-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tII/s203/a" role="instruction" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="a">(a) </num><heading class="fontsize10"><inline class="smallCaps">In General</inline>.—</heading><content><ref href="/us/usc/t41/ch47">Chapter 47 of title 41, United States Code</ref>, <amendingAction type="amend">is amended</amendingAction> by <amendingAction type="add">adding</amendingAction> at the end the following new section:<page identifier="/us/stat/132/5189">132 STAT. 5189</page>
<quotedContent><section class="centered fontsize12" id="y39b7daf0-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658164"><num class="fontsize12" value="4713">“§ 4713.</num><heading class="fontsize12"><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b7daf1-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180"><ref href="/us/usc/t41/s4713">41 USC 4713</ref>.</p></sidenote> Authorities relating to mitigating supply chain risks in the procurement of covered articles</heading><subsection class="firstIndent0 fontsize10" id="y39b7daf2-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="a">“(a) </num><heading class="fontsize10"><inline class="smallCaps">Authority</inline>.—</heading><content>Subject to subsection (b), the head of an executive agency may carry out a covered procurement action.</content></subsection>
<subsection class="firstIndent0 fontsize10" id="y39b7daf3-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="b">“(b) </num><heading class="fontsize10"><inline class="smallCaps">Determination and Notification</inline>.—</heading><chapeau>Except as authorized by subsection (c) to address an urgent national security interest, the head of an executive agency may exercise the authority provided in subsection (a) only after—</chapeau><paragraph class="fontsize10" id="y39b7daf4-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="1">“(1) </num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b7daf5-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Recommenda-</p><p class="leftAlign firstIndent0 fontsize8" id="x39b7daf6-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">tions.</p><p class="leftAlign firstIndent0 fontsize8" id="x39b7daf7-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Review.</p></sidenote><content>obtaining a joint recommendation, in unclassified or classified form, from the chief acquisition officer and the chief information officer of the agency, or officials performing similar functions in the case of executive agencies that do not have such officials, which includes a review of any risk assessment made available by the executive agency identified under section 1323(a)(3) of this title, that there is a significant supply chain risk in a covered procurement;</content></paragraph>
<paragraph class="fontsize10" id="y39b7daf8-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="2">“(2) </num><chapeau>providing notice of the joint recommendation described in paragraph (1) to any source named in the joint recommendation advising—</chapeau><subparagraph class="fontsize10" id="y39b7daf9-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">“(A) </num><content>that a recommendation is being considered or has been obtained;</content></subparagraph>
<subparagraph class="fontsize10" id="y39b7dafa-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">“(B) </num><content>to the extent consistent with the national security and law enforcement interests, of information that forms the basis for the recommendation;</content></subparagraph>
<subparagraph class="fontsize10" id="y39b7dafb-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="C">“(C) </num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b7dafc-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Deadline.</p></sidenote><content>that, within 30 days after receipt of the notice, the source may submit information and argument in opposition to the recommendation; and</content></subparagraph>
<subparagraph class="fontsize10" id="y39b7dafd-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="D">“(D) </num><content>of the procedures governing the consideration of the submission and the possible exercise of the authority provided in subsection (a);</content></subparagraph>
</paragraph>
<paragraph class="fontsize10" id="y39b7dafe-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="3">“(3) </num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b7daff-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Consultation.</p></sidenote><chapeau>making a determination in writing, in unclassified or classified form, after considering any information submitted by a source under paragraph (2) and in consultation with the chief information security officer of the agency, that—</chapeau><subparagraph class="fontsize10" id="y39b7db00-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">“(A) </num><content>use of the authority under subsection (a) is necessary to protect national security by reducing supply chain risk;</content></subparagraph>
<subparagraph class="fontsize10" id="y39b7db01-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">“(B) </num><content>less intrusive measures are not reasonably available to reduce such supply chain risk; and</content></subparagraph>
<subparagraph class="fontsize10" id="y39b7db02-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="C">“(C) </num><content>the use of such authorities will apply to a single covered procurement or a class of covered procurements, and otherwise specifies the scope of the determination; and</content></subparagraph>
</paragraph>
<paragraph class="fontsize10" id="y39b7db03-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="4">“(4) </num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b7db04-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Summaries.</p></sidenote><chapeau>providing a classified or unclassified notice of the determination made under paragraph (3) to the appropriate congressional committees and leadership that includes—</chapeau><subparagraph class="fontsize10" id="y39b7db05-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">“(A) </num><content>the joint recommendation described in paragraph (1);</content></subparagraph>
<subparagraph class="fontsize10" id="y39b7db06-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">“(B) </num><content>a summary of any risk assessment reviewed in support of the joint recommendation required by paragraph (1); and</content></subparagraph>
<subparagraph class="fontsize10" id="y39b7db07-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="C">“(C) </num><content>a summary of the basis for the determination, including a discussion of less intrusive measures that were considered and why such measures were not reasonably available to reduce supply chain risk.</content></subparagraph>
</paragraph>
</subsection>
<subsection class="firstIndent0 fontsize10" id="y39b7db08-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="c">“(c) </num><heading class="fontsize10"><inline class="smallCaps">Procedures To Address Urgent National Security Interests</inline>.—</heading><chapeau>In any case in which the head of an executive agency <page identifier="/us/stat/132/5190">132 STAT. 5190</page>
determines that an urgent national security interest requires the immediate exercise of the authority provided in subsection (a), the head of the agency—</chapeau><paragraph class="fontsize10" id="y39b7db09-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="1">“(1) </num><chapeau>may, to the extent necessary to address such national security interest, and subject to the conditions in paragraph (2)—</chapeau><subparagraph class="fontsize10" id="y39b7db0a-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">“(A) </num><content>temporarily delay the notice required by subsection (b)(2);</content></subparagraph>
<subparagraph class="fontsize10" id="y39b7db0b-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">“(B) </num><content>make the determination required by subsection (b)(3), regardless of whether the notice required by subsection (b)(2) has been provided or whether the notified source has submitted any information in response to such notice;</content></subparagraph>
<subparagraph class="fontsize10" id="y39b7db0c-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="C">“(C) </num><content>temporarily delay the notice required by subsection (b)(4); and</content></subparagraph>
<subparagraph class="fontsize10" id="y39b7db0d-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="D">“(D) </num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b7db0e-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Deadline.</p></sidenote><content>exercise the authority provided in subsection (a) in accordance with such determination within 60 calendar days after the day the determination is made; and</content></subparagraph>
</paragraph>
<paragraph class="fontsize10" id="y39b7db0f-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="2">“(2) </num><chapeau>shall take actions necessary to comply with all requirements of subsection (b) as soon as practicable after addressing the urgent national security interest, including—</chapeau><subparagraph class="fontsize10" id="y39b7db10-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">“(A) </num><content>providing the notice required by subsection (b)(2);</content></subparagraph>
<subparagraph class="fontsize10" id="y39b7db11-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">“(B) </num><content>promptly considering any information submitted by the source in response to such notice, and making any appropriate modifications to the determination based on such information;</content></subparagraph>
<subparagraph class="fontsize10" id="y39b7db12-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="C">“(C) </num><content>providing the notice required by subsection (b)(4), including a description of the urgent national security interest, and any modifications to the determination made in accordance with subparagraph (B); and</content></subparagraph>
<subparagraph class="fontsize10" id="y39b7db13-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="D">“(D) </num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b7db14-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Notice.</p><p class="leftAlign firstIndent0 fontsize8" id="x39b7db15-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Deadline.</p></sidenote><content>providing notice to the appropriate congressional committees and leadership within 7 calendar days of the covered procurement actions taken under this section.</content></subparagraph>
</paragraph>
</subsection>
<subsection class="firstIndent0 fontsize10" id="y39b7db16-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="d">“(d) </num><heading class="fontsize10"><inline class="smallCaps">Confidentiality</inline>.—</heading><content>The notice required by subsection (b)(2) shall be kept confidential until a determination with respect to a covered procurement action has been made pursuant to subsection (b)(3).</content></subsection>
<subsection class="firstIndent0 fontsize10" id="y39b7db17-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="e">“(e) </num><heading class="fontsize10"><inline class="smallCaps">Delegation</inline>.—</heading><content>The head of an executive agency may not delegate the authority provided in subsection (a) or the responsibility identified in subsection (f) to an official below the level one level below the Deputy Secretary or Principal Deputy Director.</content></subsection>
<subsection class="firstIndent0 fontsize10" id="y39b7db18-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="f">“(f) </num><heading class="fontsize10"><inline class="smallCaps">Annual Review of Determinations</inline>.—</heading><content>The head of an executive agency shall conduct an annual review of all determinations made by such head under subsection (b) and promptly amend any covered procurement action as appropriate.</content></subsection>
<subsection class="firstIndent0 fontsize10" id="y39b7db19-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="g">“(g) </num><heading class="fontsize10"><inline class="smallCaps">Regulations</inline>.—</heading><content>The Federal Acquisition Regulatory Council shall prescribe such regulations as may be necessary to carry out this section.</content></subsection>
<subsection class="firstIndent0 fontsize10" id="y39b7db1a-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="h">“(h) </num><heading class="fontsize10"><inline class="smallCaps">Reports Required</inline>.—</heading><content>Not less frequently than annually, the head of each executive agency that exercised the authority provided in subsection (a) or (c) during the preceding 12-month period shall submit to the appropriate congressional committees and leadership a report summarizing the actions taken by the agency under this section during that 12-month period.</content></subsection>
<subsection class="firstIndent0 fontsize10" id="y39b7db1b-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="i">“(i) </num><heading class="fontsize10"><inline class="smallCaps">Rule of Construction</inline>.—</heading><content>Nothing in this section shall be construed to authorize the head of an executive agency to carry out a covered procurement action based solely on the fact of foreign <page identifier="/us/stat/132/5191">132 STAT. 5191</page>
ownership of a potential procurement source that is otherwise qualified to enter into procurement contracts with the Federal Government.</content></subsection>
<subsection class="firstIndent0 fontsize10" id="y39b7db1c-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="j">“(j) </num><heading class="fontsize10"><inline class="smallCaps">Termination</inline>.—</heading><content>The authority provided under subsection (a) shall terminate on the date that is 5 years after the date of the enactment of the Federal Acquisition Supply Chain Security Act of 2018.</content></subsection>
<subsection class="firstIndent0 fontsize10" id="y39b7db1d-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="k">“(k) </num><heading class="fontsize10"><inline class="smallCaps">Definitions</inline>.—</heading><chapeau>In this section:</chapeau><paragraph class="fontsize10" id="y39b7db1e-e830-11f0-a1e4-69761a48a15a" role="definitions" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="1">“(1) </num><heading class="fontsize10"><inline class="smallCaps">Appropriate congressional committees and leadership</inline>.—</heading><chapeau>The term ‘<term>appropriate congressional committees and leadership</term>’ means—</chapeau><subparagraph class="fontsize10" id="y39b7db1f-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">“(A) </num><content>the Committee on Homeland Security and Governmental Affairs, the Committee on the Judiciary, the Committee on Appropriations, the Committee on Armed Services, the Committee on Commerce, Science, and Transportation, the Select Committee on Intelligence, and the majority and minority leader of the Senate; and</content></subparagraph>
<subparagraph class="fontsize10" id="y39b7db20-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">“(B) </num><content>the Committee on Oversight and Government Reform, the Committee on the Judiciary, the Committee on Appropriations, the Committee on Homeland Security, the Committee on Armed Services, the Committee on Energy and Commerce, the Permanent Select Committee on Intelligence, and the Speaker and minority leader of the House of Representatives.</content></subparagraph>
</paragraph>
<paragraph class="fontsize10" id="y39b80231-e830-11f0-a1e4-69761a48a15a" role="definitions" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="2">“(2) </num><heading class="fontsize10"><inline class="smallCaps">Covered article</inline>.—</heading><chapeau>The term ‘<term>covered article</term>’ means—</chapeau><subparagraph class="fontsize10" id="y39b80232-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">“(A) </num><content>information technology, as defined in section 11101 of title 40, including cloud computing services of all types;</content></subparagraph>
<subparagraph class="fontsize10" id="y39b80233-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">“(B) </num><content>telecommunications equipment or telecommunications service, as those terms are defined in section 3 of the Communications Act of 1934 (<ref href="/us/usc/t47/s153">47 U.S.C. 153</ref>);</content></subparagraph>
<subparagraph class="fontsize10" id="y39b80234-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="C">“(C) </num><content>the processing of information on a Federal or non-Federal information system, subject to the requirements of the Controlled Unclassified Information program; or</content></subparagraph>
<subparagraph class="fontsize10" id="y39b80235-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="D">“(D) </num><content>hardware, systems, devices, software, or services that include embedded or incidental information technology.</content></subparagraph>
</paragraph>
<paragraph class="fontsize10" id="y39b80236-e830-11f0-a1e4-69761a48a15a" role="definitions" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="3">“(3) </num><heading class="fontsize10"><inline class="smallCaps">Covered procurement</inline>.—</heading><chapeau>The term ‘<term>covered procurement</term>’ means—</chapeau><subparagraph class="fontsize10" id="y39b80237-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">“(A) </num><content>a source selection for a covered article involving either a performance specification, as provided in subsection (a)(3)(B) of section 3306 of this title, or an evaluation factor, as provided in subsection (b)(1)(A) of such section, relating to a supply chain risk, or where supply chain risk considerations are included in the agency’s determination of whether a source is a responsible source as defined in section 113 of this title;</content></subparagraph>
<subparagraph class="fontsize10" id="y39b80238-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">“(B) </num><content>the consideration of proposals for and issuance of a task or delivery order for a covered article, as provided in section 4106(d)(3) of this title, where the task or delivery order contract includes a contract clause establishing a requirement relating to a supply chain risk;</content></subparagraph>
<subparagraph class="fontsize10" id="y39b80239-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="C">“(C) </num><content>any contract action involving a contract for a covered article where the contract includes a clause establishing requirements relating to a supply chain risk; or</content></subparagraph>
<subparagraph class="fontsize10" id="y39b8023a-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="D">“(D) </num><content>any other procurement in a category of procurements determined appropriate by the Federal Acquisition <page identifier="/us/stat/132/5192">132 STAT. 5192</page>
Regulatory Council, with the advice of the Federal Acquisition Security Council.</content></subparagraph>
</paragraph>
<paragraph class="fontsize10" id="y39b8023b-e830-11f0-a1e4-69761a48a15a" role="definitions" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="4">“(4) </num><heading class="fontsize10"><inline class="smallCaps">Covered procurement action</inline>.—</heading><chapeau>The term ‘<term>covered procurement action</term>’ means any of the following actions, if the action takes place in the course of conducting a covered procurement:</chapeau><subparagraph class="fontsize10" id="y39b8023c-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">“(A) </num><content>The exclusion of a source that fails to meet qualification requirements established under section 3311 of this title for the purpose of reducing supply chain risk in the acquisition or use of covered articles.</content></subparagraph>
<subparagraph class="fontsize10" id="y39b8023d-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">“(B) </num><content>The exclusion of a source that fails to achieve an acceptable rating with regard to an evaluation factor providing for the consideration of supply chain risk in the evaluation of proposals for the award of a contract or the issuance of a task or delivery order.</content></subparagraph>
<subparagraph class="fontsize10" id="y39b8023e-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="C">“(C) </num><content>The determination that a source is not a responsible source as defined in section 113 of this title based on considerations of supply chain risk.</content></subparagraph>
<subparagraph class="fontsize10" id="y39b8023f-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="D">“(D) </num><content>The decision to withhold consent for a contractor to subcontract with a particular source or to direct a contractor to exclude a particular source from consideration for a subcontract under the contract.</content></subparagraph>
</paragraph>
<paragraph class="fontsize10" id="y39b80240-e830-11f0-a1e4-69761a48a15a" role="definitions" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="5">“(5) </num><heading class="fontsize10"><inline class="smallCaps">Information and communications technology</inline>.—</heading><chapeau>The term ‘<term>information and communications technology</term>’ means—</chapeau><subparagraph class="fontsize10" id="y39b80241-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">“(A) </num><content>information technology, as defined in section 11101 of title 40;</content></subparagraph>
<subparagraph class="fontsize10" id="y39b80242-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">“(B) </num><content>information systems, as defined in section 3502 of title 44; and</content></subparagraph>
<subparagraph class="fontsize10" id="y39b80243-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="C">“(C) </num><content>telecommunications equipment and telecommunications services, as those terms are defined in section 3 of the Communications Act of 1934 (<ref href="/us/usc/t47/s153">47 U.S.C. 153</ref>).</content></subparagraph>
</paragraph>
<paragraph class="fontsize10" id="y39b80244-e830-11f0-a1e4-69761a48a15a" role="definitions" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="6">“(6) </num><heading class="fontsize10"><inline class="smallCaps">Supply chain risk</inline>.—</heading><content>The term ‘<term>supply chain risk</term>’ means the risk that any person may sabotage, maliciously introduce unwanted function, extract data, or otherwise manipulate the design, integrity, manufacturing, production, distribution, installation, operation, maintenance, disposition, or retirement of covered articles so as to surveil, deny, disrupt, or otherwise manipulate the function, use, or operation of the covered articles or information stored or transmitted on the covered articles.</content></paragraph>
<paragraph class="fontsize10" id="y39b80245-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="7">“(7) </num><heading class="fontsize10"><inline class="smallCaps">Executive agency</inline>.—</heading><content>Notwithstanding section 3101(c)(1), this section applies to the Department of Defense, the Coast Guard, and the National Aeronautics and Space Administration.”</content></paragraph>
</subsection>
</section>
</quotedContent>.</content></subsection>
<subsection class="firstIndent0 fontsize10" id="y39b80246-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tII/s203/b" role="instruction" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="b">(b) </num><heading class="fontsize10"><inline class="smallCaps">Clerical Amendment</inline>.—</heading><content>The table of sections at the beginning of chapter 47 of such title<sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b80247-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180"><ref href="/us/usc/t41/s4701">41 USC 4701</ref> prec.<?GPOvSpace 04?></p></sidenote> <amendingAction type="amend">is amended</amendingAction> by <amendingAction type="add">adding</amendingAction> at the end the following new item:<quotedContent><toc>
<referenceItem role="section" style="-uslm-lc:I658242">
<designator>“4713. </designator>
<label>Authorities relating to mitigating supply chain risks in the procurement of covered articles.”.<?GPOvSpace 04?></label>
</referenceItem></toc>
</quotedContent></content></subsection>
<subsection class="firstIndent0 fontsize10" id="y39b80248-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tII/s203/c" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="c">(c) </num><heading class="fontsize10"><inline class="smallCaps">Effective Date</inline><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b80249-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180"><ref href="/us/usc/t41/s4713">41 USC 4713 note</ref>.</p></sidenote>.—</heading><content>The amendments made by this section shall take effect on the date that is 90 days after the date of the enactment of this Act and shall apply to contracts that are awarded before, on, or after that date.</content></subsection>
</section>
<section id="d140329e2808" identifier="/us/pl/115/390/tII/s204" style="-uslm-lc:I658143"><num class="fontsize12" value="204">SEC. 204. </num><heading>FEDERAL INFORMATION SECURITY MODERNIZATION ACT.</heading><subsection class="firstIndent0 fontsize10" id="y39b8506a-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tII/s204/a" role="instruction" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="a">(a) </num><heading class="fontsize10"><inline class="smallCaps">In General</inline>.—</heading><chapeau><ref href="/us/usc/t44">Title 44, United States Code</ref>, <amendingAction type="amend">is amended</amendingAction>—<page identifier="/us/stat/132/5193">132 STAT. 5193</page></chapeau><paragraph class="fontsize10" id="y39b8506b-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tII/s204/a/1" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="1">(1) </num><content>in section 3553(a)(5), by <amendingAction type="insert">inserting</amendingAction> “<quotedText>and section 1326 of title 41</quotedText>” after “<quotedText>compliance with the requirements of this subchapter</quotedText>”; and</content></paragraph>
<paragraph class="fontsize10" id="y39b8506c-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tII/s204/a/2" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="2">(2) </num><chapeau>in section 3554(a)(1)(B)—</chapeau><subparagraph class="fontsize10" id="y39b8506d-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tII/s204/a/2/A" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">(A) </num><content>by <amendingAction type="insert">inserting</amendingAction> “<quotedText>, subchapter III of chapter 13 of title 41,</quotedText>” after “<quotedText>complying with the requirements of this subchapter</quotedText>”;</content></subparagraph>
<subparagraph class="fontsize10" id="y39b8506e-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tII/s204/a/2/B" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">(B) </num><content>in clause (iv), by <amendingAction type="delete">striking</amendingAction> “<quotedText>; and</quotedText>” and <amendingAction type="insert">inserting</amendingAction> a semicolon; and</content></subparagraph>
<subparagraph class="fontsize10" id="y39b8506f-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tII/s204/a/2/C" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="C">(C) </num><content>by <amendingAction type="add">adding</amendingAction> at the end the following new clause:<quotedContent><clause class="fontsize10" id="y39b85070-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658126"><num class="fontsize10" style="-uslm-lc:emspace2" value="vi">“(vi) </num><content>responsibilities relating to assessing and avoiding, mitigating, transferring, or accepting supply chain risks under section 1326 of title 41, and complying with exclusion and removal orders issued under section 1323 of such title; and”</content></clause>
</quotedContent>.</content></subparagraph>
</paragraph>
</subsection>
<subsection class="firstIndent0 fontsize10" id="y39b85071-e830-11f0-a1e4-69761a48a15a" identifier="/us/pl/115/390/tII/s204/b" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="b">(b) </num><heading class="fontsize10"><inline class="smallCaps">Rule of Construction</inline><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b85072-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180"><ref href="/us/usc/t44/s3553">44 USC 3553 note</ref>.</p></sidenote>.—</heading><content>Nothing in this title shall be construed to alter or impede any authority or responsibility under <ref href="/us/usc/t44/s3553">section 3553 of title 44, United States Code</ref>.</content></subsection>
</section>
<section id="d140329e2900" identifier="/us/pl/115/390/tII/s205" style="-uslm-lc:I658143"><num class="fontsize12" value="205">SEC. 205. </num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="x39b85073-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180"><ref href="/us/usc/t41/s1321">41 USC 1321 note</ref>.</p></sidenote><heading>EFFECTIVE DATE.</heading><content style="-uslm-lc:I658120">  This title shall take effect on the date that is 90 days after the date of the enactment of this Act.</content></section>
</title>
<action>
<actionDescription style="-uslm-lc:I658030">Approved</actionDescription> <date date="2018-12-21">December 21, 2018</date>.</action>
</main>
<legislativeHistory>
<heading style="-uslm-lc:I658031"><inline class="underline">LEGISLATIVE HISTORY</inline>—<ref href="/us/bill/115/hr/7327">H.R. 7327</ref>:</heading>
<note>
<heading style="-uslm-lc:I658032">CONGRESSIONAL RECORD, Vol. 164 (2018):</heading>
<p class="indentUp4 firstIndent-1" id="x39b85074-e830-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658035">Dec. 19, considered and passed House and Senate.</p></note>
</legislativeHistory>
<endMarker>○</endMarker>
</pLaw>