Tap any paragraph to write a margin note. Your notes collect in the Desk below the text and file under cases with @. The side-by-side margin rail opens on a larger screen.

Code · BILL · 117th Congress · H.R. 7900 (Engrossed in House) — To authorize appropriations for fiscal year 2023 for military activities of the Department of Defense and for militar... · Sec. 6722

Sec. 6722. DHS software supply chain risk management

724 words·~3 min read·/bill/117/hr/7900/eh/section-6722

A research copy — for the controlling text, always check the official state or federal source. Not legal advice.

The Secretary of Homeland Security, acting through the Under Secretary, shall issue guidance with respect to new and existing covered contracts. In developing guidance under subsection (a), with respect to each new covered contract, as a condition on the award of such a contract, each contractor responding to a solicitation for such a contract shall submit to the covered officer— a planned bill of materials when submitting a bid proposal; and the certification and notifications described in subsection (e).
In developing guidance under subsection (a), with respect to each existing covered contract, each contractor with an existing covered contract shall submit to the covered officer— the bill of materials used for such contract, upon the request of such officer; and the certification and notifications described in subsection (e). With respect to a covered contract, in the case of a change to the information included in a bill of materials submitted pursuant to subsections (b)(1) and (c)(1), each contractor shall submit to the covered officer the update to such bill of materials, in a timely manner.
The certification and notifications referred to in subsections (b)(2) and (c)(2), with respect to a covered contract, are the following: A certification that each item listed on the submitted bill of materials is free from all known vulnerabilities or defects affecting the security of the end product or service identified in— the National Institute of Standards and Technology National Vulnerability Database; and any database designated by the Under Secretary, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency, that tracks security vulnerabilities and defects in open source or third-party developed software.
A notification of each vulnerability or defect affecting the security of the end product or service, if identified, through— the certification of such submitted bill of materials required under paragraph (1); or any other manner of identification. A notification relating to the plan to mitigate, repair, or resolve each security vulnerability or defect listed in the notification required under paragraph (2). In developing guidance under subsection (a), the Secretary shall instruct covered officers with respect to— the processes available to such officers enforcing subsections
(b)and (c); and when such processes should be used. The guidance required under subsection
(a)shall take effect on the date that is 180 days after the date of the enactment of this section. Not later than 1 year after the date of the enactment of this Act, the Comptroller General of the United States shall submit to the Secretary, the Committee on Homeland Security of the House of Representatives, and the Committee on Homeland Security and Governmental Affairs of the Senate a report that includes— a review of the implementation of this section; information relating to the engagement of the Department of Homeland Security with industry; an assessment of how the guidance issued pursuant to subsection
(a)complies with Executive Order 14208 (86 Fed. Reg. 26633; relating to improving the nation’s cybersecurity); and any recommendations relating to improving the supply chain with respect to covered contracts. In this section: The term bill of materials means a list of the parts and components (whether new or reused) of an end product or service, including, with respect to each part and component, information relating to the origin, composition, integrity, and any other information as determined appropriate by the Under Secretary. The term covered contract means a contract relating to the procurement of covered information and communications technology or services for the Department of Homeland Security. The term covered information and communications technology or services means the terms— information technology (as such term is defined in section 11101(6) of title 40, United States Code); information system (as such term is defined in section 3502(8) of title 44, United States Code); telecommunications equipment (as such term is defined in section 3(52) of the Communications Act of 1934 ( 47 U.S.C. 153(52) )); and telecommunications service (as such term is defined in section 3(53) of the Communications Act of 1934 ( 47 U.S.C. 153(53) )). The term covered officer means— a contracting officer of the Department; and any other official of the Department as determined appropriate by the Under Secretary. The term software means computer programs and associated data that may be dynamically written or modified during execution. The term Under Secretary means the Under Secretary for Management of the Department of Homeland Security.
Connectionstraces to 1
Traces to 1 document
2 references not yet in our index
  • EO 14208
  • 86 FR 26633
Citation graph
cites case law
Sec. 6722
DHS software supply chain risk management
Exec. Ord.EO 14208
Fed. Reg.86 FR 26633
Cites 3Cited by 0 across 0 sources
★   the supreme law of the land   ★
Don't Tread on Me
E Pluribus Unum — out of many, one

"If you don't know your rights, you don't have any."

Marginalia · a citizen's law index
A research desk, not legal advice. Always read the cited source before relying on a summary.
Questions or an issue? support@self-law.org
disclaimerMarginalia is a research index, not a law firm. Nothing on this site is legal, tax, or financial advice and no attorney–client relationship is formed by using it. Statutes, regulations, and case law change; summaries, search results, AI output, and member posts may be incomplete, out of date, or wrong. Any interpretation drawn from material on this site should be validated by a licensed attorney in your jurisdiction before you act on it.