Mike D. Rogers
Representative for Alabama · Republican · United States
“(8) An assessment of NATO's deterrence efforts in Romania, including a description and evaluation of-- (A) United States force posture in Romania, including any new rotations to Romania intended to enhance deterrence following the 2025 decision to end the rotational presence of a United States brigade; (B) consultations with NATO allies r…”
“(8) An assessment of NATO's deterrence efforts in Romania, including a description and evaluation of-- (A) United States force posture in Romania, including any new rotations to Romania intended to enhance deterrence following the 2025 decision to end the rotational presence of a United States brigade; (B) consultations with NATO allies r…”
“(a) Requirement for Risk-based Approach.--Section 3843 of title 10, United States Code, is amended to read as follows: ``Sec. 3843. Contractor business systems: monitoring and surveillance standards ``(a) Requirement for Risk-based Approach.--The Secretary shall implement an agile, streamlined risk-based approach to surveillance of contra…”
“(a) Requirement for Risk-based Approach.--Section 3843 of title 10, United States Code, is amended to read as follows: ``Sec. 3843. Contractor business systems: monitoring and surveillance standards ``(a) Requirement for Risk-based Approach.--The Secretary shall implement an agile, streamlined risk-based approach to surveillance of contra…”
“(b) Modification of Certain Certifications and Assessments.-- (1) Certifications.--Section 1249(b) of the National Defense Authorization Act for Fiscal Year 2026 (Public Law 119-60) is amended-- (A) in the matter preceding paragraph (1), by striking ``The certification described'' and inserting following: ``(1) In general.--Except as prov…”
“(b) Objectives.--The Commander shall ensure that the Cognitive Performance Enhancement Program-- (1) improves readiness, resilience, and recovery, using evidence-based holistic and proactive high-performance brain training that has a validated ability to scale cost- effectively across the special operations forces enterprise; [[Page H4842…”
The complete record
Every one of 4,912 lines we hold for Mike D. Rogers, in date order, each linked to its source. Free to read, in full, without an account. Page 64 of 99.
“(a) Procurement.--Subject to the availability of appropriations for such purpose, the Secretary of the Air Force, acting through the Commercial Space Office and in coordination with the FireGuard program of the National Guard and the Commander of the United States Northern Command, shall procure space-based commercial data and end products to support the efforts of the Department of Defense and the wildfire mission of the United States Northern Command by delivering timely, effective military support to the Federal Government and State, local, and Tribal governments to protect military [[Page H4865]] readiness and installations, provide emergency military support to civil authorities, and conduct proactive wildland fire management.”
“(b) Annual Updates.--Paragraph (3) of subsection (b) of such section is amended to read as follows: ``(3) Annual updates.--Not later than March 31 of each of 2027 through 2031, the Secretary shall submit to the congressional defense committees an update on the Spaceport of the Future initiative, including with respect to-- ``(A) project status; ``(B) estimated completion dates; ``(C) total costs; ``(D) any updated assessments of funding or infrastructure needs; and ``(E) the status of any policy recommendations described in paragraph (2)(D).''. SEC. 1605. PROCUREMENT OF COMMERCIAL SPACE-BASED DATA AND TO SUPPORT WILDFIRE RESILIENCE.”
“1177) is amended by adding at the end the following new subsection: ``(c) Program Requirements.-- ``(1) Single program.--The Secretary of the Air Force shall carry out the Spaceport of the Future initiative as a single program of the Space Force overseen by the portfolio acquisition executive for space access pursuant to section 1732 of title 10, United States Code. ``(2) Prioritized investments.--As a part of the defense budget materials (as defined in section 239 of title 10, United States Code) for each of fiscal years 2027 through 2031, the portfolio acquisition executive for space access shall submit to the congressional defense committees a list of prioritized investments required for infrastructure efforts under the Spaceport of the Future initiative.''.”
“2276 note) is amended-- (1) by striking ``the Secretary of Defense'' both places it appears and inserting ``the portfolio acquisition executive of the Space Force''; (2) by striking ``the Director of the National Reconnaissance Office'' and inserting ``the Director of the Office of Space Launch of the National Reconnaissance Office''; and (3) by striking ``the Director of National Intelligence'' and inserting ``the Director of the Office of Space Launch''. SEC. 1604. SPACEPORT OF THE FUTURE INITIATIVE. (a) Program Requirements.--Section 1608 of the National Defense Authorization Act for Fiscal Year 2026 (Public Law 119-60; 139 Stat.”
“(a) Extension of Transition Limitations and Reporting Requirements.--Section 2276a(e) of title 10, United States Code, is amended by striking ``fiscal years 2024, 2025, and 2026'' and inserting ``fiscal years 2024 through 2031''. (b) Notification of Use of Alternative Launch Procurement.--Section 1601(c) of the National Defense Authorization Act for Fiscal Year 2022 (Public Law 117-81; 10 U.S.C.”
“``(2) Of the amounts authorized to be appropriated or otherwise made available for fiscal year 2028 or any fiscal year thereafter for the travel expenses of the Secretary of a military department, not more than 90 percent may be obligated or expended during a fiscal year covered by a budget request for which the official designated under subsection (a)(1) did not make a certification under paragraph (1)(A).''. (2) Timing.--The Secretary of Defense shall designate the official under section 2279a of title 10, United States Code, as added by paragraph (1), by not later than 60 days after the date of the enactment of this Act. SEC. 1603. SPACE LAUNCH SUPPORT SERVICES AND ALTERNATIVE LAUNCH PROCUREMENT PROCESS.”
“``(c) Annual Certifications; Limitation on Availability of Funds.--(1) At the same time as the President submits to Congress the annual budget request under section 1105 of title 31 for a fiscal year, the official designated under subsection (a)(1) shall submit to the congressional defense committees, with respect to each military department-- ``(A) a certification that such budget request would fully fund the user equipment and ground control systems of the Department of Defense positioning, navigation, and timing enterprise; or ``(B) a notice that such budget request would not fully fund such user equipment and ground control systems.”
“``(b) Duties.--The Secretary-- ``(1) shall assign to the official designated under subsection (a)(1)-- ``(A) any duty the Secretary determines appropriate from among the duties carried out by the former Council on Oversight of the Department of Defense Positioning, Navigation, and Timing Enterprise as of January 1, 2026; and ``(B) any other duty the Secretary determines appropriate; and ``(2) may delegate to other officials of the Department any such duty described in paragraph (1)(A) not assigned to the official designated under subsection (a).”
“Oversight of the Department of Defense Positioning, Navigation, and Timing Enterprise ``(a) Designation.--(1) The Secretary of Defense, in consultation with the Chairman of the Joint Chiefs of Staff, shall designate a single official of the Department of Defense (other than the Chief Information Officer of the Department) as the principal official of the Department with responsibility for the oversight of the Department of Defense positioning, navigation, and timing enterprise. ``(2) The official designated under paragraph (1) shall report directly to the Deputy Secretary of Defense with respect to matters concerning the Department of Defense positioning, navigation, and timing enterprise (including alternative positioning, navigation, and timing efforts of the Department).”
“(2) Conforming amendment.--Section 1609(c) of the National Defense Authorization Act for Fiscal Year 2020 (Public Law 116-92; 10 U.S.C. 2273 note) is amended by striking ``, including the Space Rapid Capabilities Office''. SEC. 1602. REORGANIZATION OF OVERSIGHT OF THE DEPARTMENT OF DEFENSE POSITIONING, NAVIGATION, AND TIMING ENTERPRISE. (a) Repeal.--Section 2279b of title 10, United States Code, is repealed. (b) Designation of Official.-- (1) Requirement.--Chapter 135 of title 10, United States Code, is amended by inserting after section 2279 the following new section: ``Sec. 2279a.”
“(ii) In section 9016(b)(6)(B)-- (I) by striking clauses (iii), (iv), and (v) and inserting the following new clause: ``(iii) Oversee, direct, and synchronize acquisition projects for all space systems and programs of the Department of the Air Force.''; (II) by redesignating clause (vi) as clause (iv); and (III) in clause (iv), as so redesignated, by striking ``Effective as of'' and all that follows through ``serve'' and inserting ``Serve''. (B) National defense authorization act for fiscal year 2024.--Section 1608 of the National Defense Authorization Act for Fiscal Year 2024 (Public Law 118-31; 10 U.S.C. 2271 note) is repealed. (b) Elimination of Space Rapid Capabilities Office.-- (1) Repeal.--Section 2273a of title 10, United States Code, is repealed.”
“(2) Conforming amendments.-- (A) Title 10.--Title 10, United States Code, is amended as follows: (i) In section 4092-- (I) in subsection (a)(8)-- (aa) in the heading, by striking ``SDA'' and inserting ``Space force''; (bb) by striking ``The Director of the Space Development Agency'' and inserting ``The portfolio acquisition executive of the Space Force designated under section 1732 of this title with respect to missile warning and tracking''; and (cc) by striking ``the Agency.'' and inserting ``the Space Force.''; (II) in subsection (b)(1)(H)-- (aa) by striking ``in the case of the Space Development Agency'' and inserting ``in addition to any positions appointed under subparagraph (A), in the case of the Space Force''; and (bb) by striking ``the Agency'' both places it appears and inserting ``the Space Force''; and (III) in subsection (c)(2), by striking ``, the Space Development Agency'' and inserting ``, the Space Force''.”
“(c) Purpose.--The purpose of subsection (a) is to ensure that cybersecurity is treated by the Department as an element of operational readiness across the Department and to support senior leader decisionmaking, risk acceptance, and resource prioritization related to the security and resilience of the Department of Defense Information Network (DoDIN). (d) Termination.--The requirements of this section shall terminate on the date that is three years after the date of the enactment of this Act. TITLE XVI--SPACE ACTIVITIES, STRATEGIC PROGRAMS, AND INTELLIGENCE MATTERS Subtitle A--Space Activities SEC. 1601. REORGANIZATION OF ACQUISITION RESPONSIBILITIES OF THE SPACE FORCE. (a) Elimination of Space Development Agency.-- (1) Repeal.--Section 9087 of title 10, United States Code, is repealed.”
“(6) An assessment of how assessments under the program will incorporate and operationalize Critical Infrastructure Discovery and Evaluation (CIDE) activities conducted by the Department of Defense Cyber Defense Command on operational technology networks, including alignment of scope, methodology, data collection, reporting, and resourcing to ensure unity of effort and avoid duplication. (7) A description of any policy, authority, or resourcing gaps that inhibit full execution of the program as an operational readiness assessment.”
“(4) A description of actions taken or planned to address material risks identified through the program, including timelines, responsible organizations, and any resource constraints. (5) An initial plan, and subsequent progress reports, for incorporating operational technology (OT) environments into assessments carried out under the program to ensure a comprehensive operational readiness evaluation of mission- critical systems, weapon platforms, industrial control systems, and supporting infrastructure.”
“(b) Contents.--Each report required under subsection (a) shall include, for the period covered by the report, the following: [[Page H4864]] (1) An overview of the implementation status of the Cyber Operational Readiness Assessment program, including scope, methodology, and assessment cadence across the military departments and the defense agencies and Department of Defense field activities. (2) Aggregate and component-level findings on cyber operational readiness, including systemic risks, recurring deficiencies, and trends affecting mission assurance. (3) An assessment of operational resilience, including the ability of the Department of Defense to maintain essential functions, contain adversary activity, and recover from cyber incidents during contested operations.”
“(a) Semiannual Reports Required.--Not later than 180 days after the date of the enactment of this Act, and not less frequently than once every 180 days thereafter, the Secretary of Defense shall, acting through the Chief Information Officer of the Department of Defense and the Commander of the Department of Defense Cyber Defense Command (DCDC), submit to the congressional defense committees a semiannual report on the implementation of the Cyber Operational Readiness Assessment program of the Department of Defense Cyber Defense Command and the findings from such program.”
“(d) Report Elements.--Each report submitted under subsection (c) shall include the following: (1) Progress made toward roadmap milestones and modernization goals. (2) Updates to the roadmap, as appropriate. (3) Major risks, delays, or challenges affecting implementation. (4) Budgetary resources requested and obligated for modernization of such networks. (5) Any recommendations that the Secretary considers appropriate for legislative or funding actions to implement the roadmap. (e) Form of Roadmap and Reports.--The roadmap required by subsection (a) and the reports required by subsection (c) shall be submitted in classified form, but may include an unclassified summary. SEC. 1542. SEMIANNUAL REPORTS ON CYBER OPERATIONAL READINESS ASSESSMENT PROGRAM.”
“(7) An assessment of the extent to which such networks support the operational requirements of combatant commands, including the ability to enable integration with joint and mission partner environments. (8) Identification of governance, roles, and responsibilities for modernization of such networks across the Department. (9) Estimated resource requirements necessary to implement the roadmap. (c) Annual Report.--Not later than one year after the date of the enactment of this Act, and annually thereafter for each of the next five years, the Secretary shall submit to the congressional defense committees a report on progress in implementing the roadmap required under subsection (a).”
“(2) Target or reference architectures for modernized environments for such networks, including enterprise-level and component-level networks, as appropriate. (3) Milestones and timelines for transition from current environments to the target or reference architectures. (4) Plans to improve resilience, survivability, and operations of such networks in contested, degraded, or disconnected environments. (5) Plans to improve interoperability and data sharing across such networks and relevant mission partner environments, as appropriate. (6) An assessment of high-performance computing and distributed computing requirements, whether locally or in cloud environments, necessary to support real-time sensor data fusion, advanced analytics, and artificial intelligence capabilities.”
“ROADMAP FOR MODERNIZATION OF TOP SECRET AND SPECIAL ACCESS PROGRAM NETWORK ARCHITECTURES. (a) In General.--Not later than 180 days after the date of the enactment of this Act, the Secretary of Defense shall develop and submit to the congressional defense committees, and begin implementation of, a roadmap for the modernization of Department of Defense networks that process, store, or transmit information that is classified at the level of top secret or is designated as being within a special access program. (b) Elements.--The roadmap required under subsection (a) shall include the following elements: (1) An assessment of the current architecture, capacity, security posture, and technical limitations of such networks, including identification of major capability gaps, cybersecurity risks, infrastructure limitations, and technical debt.”
“(e) Briefing.--At least 30 days before the date on which the authority expires under subsection (f), the Secretary of the Air Force shall provide to the congressional defense committees a briefing that includes-- (1) a description of the data cleansing and correction challenges addressed through the program; (2) an assessment of any improvements in data accuracy, aircraft availability, and maintenance efficiency resulting from the program; and (3) an evaluation of the feasibility and advisability of expanding these capabilities to additional Air Force units operating the same aircraft types. (f) Expiration.--The authority to carry out the program under subsection (a) shall expire on the date that is one year after the date of the enactment of this Act. Subtitle C--Reports and Other Matters SEC. 1541.”
“(d) Partnerships.--In carrying out the program under subsection (a), the Secretary of the Air Force may partner with a federally funded research and development center, a University Affiliated Research Center, a center of excellence, a military service laboratory, or one or more private-sector entities with experience in deploying AI- powered maintenance intelligence capabilities that support data cleansing, parts forecasting, and sustainment modernization within the Air Force, as well as any other partners the Secretary deems necessary.”
“(c) Objectives.--The objectives of the program are to leverage AI-enabled software solutions to-- (1) cleanse and correct structured and unstructured maintenance and logistics data; (2) establish validated, high-fidelity ground-truth maintenance datasets to improve the performance and reliability of existing Air Force readiness, logistics, and decision-support systems; (3) reduce manual data correction burdens and improve interoperability with legacy maintenance information systems; (4) enhance sustainment efficiency, sortie generation, and scheduling accuracy through improved maintenance visibility; (5) increase situational awareness for tactical-level maintainers and operational leadership; (6) establish standardized, reusable maintenance data cleansing, correction, and integration frameworks designed to interoperate with and enhance existing Air Force maintenance, logistics, and readiness systems; and (7) enable scalable, repeatable integration of AI-enabled maintenance capabilities across the Air Force.”
“(a) In General.--Not later than 90 days after the date of the enactment of this Act, and subject to the availability of appropriations, the Secretary of the Air Force shall establish a pilot program to operationalize and expand artificial intelligence (AI)-enabled maintenance data cleansing and correction capabilities across the Air Force. This program will prioritize the improvement of aircraft availability and pilot production capacity by modernizing maintenance data quality, increasing the effectiveness of sustainment operations, and maximizing readiness of existing training aircraft fleets through enhanced data fidelity and decision support. (b) Scope.--The program under subsection (a) shall apply across the full portfolio of aircraft operating within Air Education and Training Command.”
“(g) Semiannual Reports.--Not less frequently than semiannually through December 31, 2032, the Secretary of Defense shall provide a report to the congressional defense committees regarding the implementation of the updates required by subsection (a), including-- (1) systems and use cases reviewed under the updates required by subsection (a), including whether such systems and use cases were approved, restricted, suspended, or subject to additional review; and (2) any significant acquisition, resourcing, sustainment, or programmatic impacts resulting from implementation of the updates required by subsection (a). SEC. 1525. EXPANSION OF AI-ENABLED MAINTENANCE INTELLIGENCE PLATFORMS ACROSS AIR EDUCATION AND TRAINING COMMAND.”
“(e) Interim Report.--Not later than 180 days after the date of the enactment of this Act, the Secretary shall provide a report to the congressional defense committees describing the progress of the Department toward completion of the updates required by subsection (a), including a preliminary assessment of the matters described in subsection (b). (f) Final Policy Briefing.--Not later than 30 days after the completion of the updates required by subsection (a), the Secretary shall provide a briefing to the congressional defense committees on-- (1) the updates completed under subsection (a); (2) the rationale supporting the updates, including the assessment of the Secretary with respect to each matter described in subsection (b); and (3) any recommendations for authorities, resources, or statutory changes.”
“(c) Compliance With Law.--The Secretary shall ensure that the policies and guidance required by subsection (a) are consistent with applicable provisions of Federal law, including section 1638 of the National Defense Authorization Act for Fiscal Year 2025 (Public Law 118-159; 10 U.S.C. 491 note), and applicable Department policies and regulations. (d) Continuity of Operations.--This section does not require the Secretary to suspend or terminate any ongoing operations, activities, or programs pending completion of the updates required by subsection (a).”
“[[Page H4863]] (b) Required Policy Elements.--In updating the policies and guidance required by subsection (a), the Secretary shall ensure such policies and guidance include-- (1) criteria for categorizing systems according to such factors as mission context, autonomy, human involvement, and operational consequence; (2) appropriate and operationally responsive requirements for approval, validation, oversight, and authorized operational use applicable to categories of systems identified pursuant to the criteria in paragraph (1); (3) realistic and combat-effective requirements for operator intervention, override mechanisms, and operational resilience; (4) requirements to preserve existing human command responsibility for the use of force involving autonomous systems or artificial intelligence-enabled systems, including procedures to identify the human commanders or operators responsible for authorizing, supervising, and terminating such use of force; (5) appropriate requirements for auditability, traceability, and accountability; (6) criteria and procedures for rapidly fielding capabilities following material changes to software, models, data, or operational context; (7) requirements for appropriate and operationally responsive risk mitigation measures and notifications applicable to systems granted conditional or temporary operational use; (8) requirements for operational testing, evaluation, and human training commensurate with mission risk and operational consequence, including training to promote calibrated reliance on artificial intelligence-enabled systems; and (9) processes and timelines for periodic review and reevaluation of approved systems and operational use cases.”
“(a) Policy Update Required.--Not later than 1 year after the date of the enactment of this Act, the Secretary of Defense shall update policies and guidance of the Department of Defense, including by revising Department of Defense Directive 3000.09 (relating to Autonomy in Weapon Systems) and establishing or revising such additional Department policies and guidance as may be appropriate, governing-- (1) autonomous and semi-autonomous weapon systems; and (2) artificial intelligence-enabled systems intended to support, recommend, or materially influence operational decisions associated with the employment of force, including systems used for operational planning, target development, weaponeering, or engagement recommendation.”
“(f) Definition.--In this section, the term ``Department enterprise AI platform'' means a centrally managed platform that hosts or provides AI services or applications for use across multiple elements of the Department, rather than for a single program, system, or mission application. SEC. 1524. UPDATE OF POLICY ON AUTONOMOUS AND ARTIFICIAL INTELLIGENCE-ENABLED SYSTEMS.”
“(d) Compliance With Requirements.--The Secretary shall ensure that the Framework complies with all applicable requirements for test and evaluation of Department systems in accordance with applicable law, policy, and guidance. (e) Metrics and Reporting.--The Chief Digital and Artificial Intelligence Officer shall-- (1) establish metrics to measure the time required to evaluate, authorize, deploy, and update AI systems on Department enterprise AI platforms; and (2) in each of fiscal years 2027, 2028, 2029, and 2030, submit an annual report to the congressional defense committees on progress toward achieving the objective stated in subsection (a).”
“(c) Integration With Other Frameworks.--The Secretary shall ensure that the rapid deployment of AI systems under the Framework is achieved in a manner that maintains security standards through integration with other relevant frameworks, including-- (1) the plans, strategies, and other matters relating to AI required by section 1544 of the National Defense Authorization Act for Fiscal Year 2024 (10 U.S.C. 4001 note); (2) the Defense-wide policy required by section 1512 of the National Defense Authorization Act for Fiscal Year 2026 (10 U.S.C. 394 note); and (3) the framework and other requirements required by section 1513 of the National Defense Authorization Act for Fiscal Year 2026 (10 U.S.C. 2224 note).”
“(5) Streamlined system authorization processes.--In coordination with the Chief Information Officer of the Department, establishment of streamlined processes for authorization of AI systems deployed on Department enterprise AI platforms, including reuse of authorization artifacts, common control inheritance, and continuous monitoring capabilities. (6) Registry and governance systems.--Implementation of registry and governance processes to track version history, performance, security status, and compliance for AI systems deployed on Department enterprise AI platforms.”
“(3) Security testing and evaluation.--Establishment of security testing and evaluation capabilities to support security assessments for AI systems deployed on Department enterprise AI platforms, including adversarial testing, supply chain risk assessments, and other security testing appropriate for AI systems, consistent with existing cybersecurity and test and evaluation policies. (4) Multi-classification deployment.--Establishment of capability to deploy AI systems on Department enterprise AI platforms across multiple classification levels, as appropriate, with appropriate security controls and data isolation.”
“(b) Elements.--The Framework shall include the following elements: (1) Vendor and model onboarding process.--Establishment of standardized processes for deploying AI systems onto Department enterprise AI platforms, including security reviews, technical assessments, and integration with other Department systems and platforms. (2) Common definitions and categories.--Common definitions or categories for AI systems deployed on Department enterprise AI platforms, including systems with agentic capabilities, to support acquisition clarity, testing, authorization, and operational adoption.”
“(a) Framework Required.--The Secretary of Defense, acting through the Chief Digital and Artificial Intelligence Officer of the Department of Defense, shall establish a framework for the rapid deployment of artificial intelligence (``AI''), to be known as the Artificial Intelligence Model Rapid Deployment Framework (in this section referred to as the ``Framework''), to enable the evaluation, authorization, and deployment of AI systems on Department enterprise AI platforms, as appropriate. The objective of the Framework shall be to enable deployment of such systems on such platforms within 30 days after public availability.”
“2224 note) is amended in subsection (a)-- (1) by amending paragraph (2) to read as follows: ``(2) Guidance for department systems and devices.--Not later than 30 days after the date of the enactment of the National Defense Authorization Act for Fiscal Year 2027, the Secretary of Defense shall issue Department of Defense-wide guidance for the identification of covered artificial intelligence companies and processes for the exclusion and removal of artificial intelligence developed by such companies from systems and devices of the Department.''; and (2) in paragraph (3)(B), by striking ``if'' and inserting ``on and after the date that is 90 days after the date on which''. SEC. 1523. ARTIFICIAL INTELLIGENCE MODEL RAPID DEPLOYMENT FRAMEWORK.”
“(2) Report.--Not later than one year after the date of the enactment of this Act, the Secretary shall submit to the congressional defense committees a report containing-- (A) the revised regulations required by subsection (b); and (B) any remaining barriers to full and timely implementation of such revised regulations. SEC. 1522. REQUIREMENT FOR GUIDANCE AND PROHIBITION ON USE OF ARTIFICIAL INTELLIGENCE OF CERTAIN ARTIFICIAL INTELLIGENCE COMPANIES. Section 1532 of the National Defense Authorization Act for Fiscal Year 2026 (10 U.S.C.”
“(c) Updates and Report.-- (1) Written updates.--Not later than 180 days after the date of the enactment of this Act, and every 90 days thereafter until the revised regulations required by subsection (b) are issued, the Secretary shall submit to the congressional defense committees a written update containing-- (A) a description of the progress made toward completing the revised regulations, along with specific actions taken and remaining milestones; (B) the most up-to-date working draft of the revised regulations, or an outline of such working draft in sufficient detail to demonstrate the manner in which, and the extent to which, the working draft implements section 2221; (C) a description of any anticipated barriers to full and timely issuance of the revised regulations and full and timely implementation of such regulations; (D) any recommendations for legislation to fully implement such revised regulations; and (E) if the Secretary has not issued such revised regulations within the period described in subsection (b), an explanation for the delay and the anticipated timeline for issuing the revised regulations.”
“1884). ``(b) Definition.--In this section, the term `lifecycle' includes stages such as development, prototyping, testing, fielding, modification, upgrading, licensing, sustainment, and retirement.''. (b) Issuance of Revised Regulations.-- (1) In general.--Not later than one year after the date of the enactment of this Act, the Secretary of Defense shall issue revised regulations to implement section 2221 of title 10, United States Code, as added by this section. (2) Notification.--Not later than 30 days after the Secretary issues the revised regulations under paragraph (1), the Secretary shall notify the congressional defense committees of the revisions.”
“Such guidance shall-- ``(1) reflect that amounts appropriated for operations and maintenance, procurement, or research, development, test, and evaluation may be used at each stage in the lifecycle of a software capability, consistent with applicable law; ``(2) clarify that such amounts may be used, as appropriate, for all activities at each such stage in the lifecycle of a software capability; ``(3) provide that, for any program or activity of the Department that requires a new software capability, the appropriations account primarily available for that program or activity shall be available for that new software capability; ``(4) not impose restrictions on the availability of funds for software capabilities, except as required by law; and ``(5) maintain consistency, to the maximum extent practicable, with Recommendation 11A of the final report (dated March 2024) of the Commission on Planning, Programming, Budgeting, and Execution Reform, as submitted under section 1004 of the National Defense Authorization Act for Fiscal Year 2022 (Public Law 117-81; 135 Stat.”
“Availability of appropriations accounts for full lifecycle of software capabilities: regulations ``(a) In General.--The Secretary of Defense shall ensure that the relevant financial management regulations of the Department provide guidance for the budgeting and execution of funds for software capabilities.”
“(8) The term ``security vulnerability'' has the meaning given that term in section 2200 of the Homeland Security Act of 2002 (6 U.S.C. 650). (9) The term ``simplified acquisition threshold'' has the meaning given that term in section 134 of title 41, United States Code. Subtitle B--Information Technology and Artificial Intelligence SEC. 1521. SOFTWARE PLANNING, PROGRAMMING, BUDGETING, AND EXECUTION REFORM. (a) In General.--Chapter 131 of title 10, United States Code, is amended by inserting after section 2220 the following new section: ``Sec. 2221.”
“(2) The term ``covered contractor'' means a contractor (as defined in section 7101 of title 41, United States Code)-- (A) whose contract is in an amount the same as or greater than the simplified acquisition threshold; or (B) that operates, manages, or maintains a Federal information system (as defined by section 11331 of title 40, United Stated Code) on behalf of an agency. (3) The term ``DFARS'' means the Department of Defense Supplement to the Federal Acquisition Regulation. (4) The term ``Executive department'' has the meaning given that term in section 101 of title 5, United States Code. (5) The term ``FAR'' means the Federal Acquisition Regulation. (6) The term ``NIST'' means the National Institute of Standards and Technology. (7) The term ``OMB'' means the Office of Management and Budget.”
“(4) Waiver.--The Chief Information Officer of the Department of Defense, in consultation with the National Manager for National Security Systems, may waive the security vulnerability disclosure policy requirements under paragraph (2) if the Chief Information Officer-- (A) determines that the waiver is necessary in the interest of national security or research purposes; and (B) not later than 30 days after granting a waiver, submits a notification and justification (including information about the duration of the waiver) to the Committees on Armed Services of the House of Representatives and the Senate. (f) Definitions.--In this section: [[Page H4862]] (1) The term ``agency'' has the meaning given the term in section 3502 of title 44, United States Code.”
“(2) Revisions.--Not later than 180 days after the date on which the review required under subsection (a) is completed, the Secretary shall revise the DFARS as necessary to incorporate requirements for covered contractors to receive information about a potential security vulnerability relating to an information system owned or controlled by a contractor, in performance of the contract. (3) Elements.--The Secretary shall ensure that the revision to the DFARS described in this subsection is carried out in accordance with the requirements of paragraphs (1) and (2) of subsection (c).”
“(e) Department of Defense Supplement to the Federal Acquisition Regulation.-- (1) Review.--Not later than 180 days after the date of the enactment of this Act, the Secretary of Defense shall review the Department of Defense Supplement to the Federal Acquisition Regulation contract requirements and language for contractor vulnerability disclosure programs and develop updates to such requirements designed to ensure that covered contractors implement a vulnerability disclosure policy consistent with NIST guidelines for contractors as required under section 5 of the IoT Cybersecurity Improvement Act of 2020 (15 U.S.C. 278g-3c).”
“(d) Waiver.--The head of an agency may waive the security vulnerability disclosure policy requirement under subsection (b) if-- (1) the agency Chief Information Officer determines that the waiver is necessary in the interest of national security or research purposes; and (2) if, not later than 30 days after granting a waiver, such head submits a notification and justification (including information about the duration of the waiver) to the Committee on Oversight and Government Reform of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate.”
“(c) Elements.--The update to the FAR pursuant to subsection (b) shall-- (1) to the maximum extent practicable, align with the security vulnerability disclosure process and coordinated disclosure requirements relating to Federal information systems under sections 5 and 6 of the IoT Cybersecurity Improvement Act of 2020 (15 U.S.C. 278g-3c and 278g-3d); and (2) to the maximum extent practicable, be aligned with industry best practices and Standards 29147 and 30111 of the International Standards Organization (or any successor standard) or any other appropriate, relevant, and widely used standard.”