← LEADERSHIP TERMINAL

US CONGRESS · SITTING

Mike D. Rogers

Representative for Alabama · Republican · United States

IN THEIR OWN WORDS

(8) An assessment of NATO's deterrence efforts in Romania, including a description and evaluation of-- (A) United States force posture in Romania, including any new rotations to Romania intended to enhance deterrence following the 2025 decision to end the rotational presence of a United States brigade; (B) consultations with NATO allies r…

CREC-2026-07-21-PT1-PGH4736 · READ IN THE CONGRESSIONAL RECORD

(8) An assessment of NATO's deterrence efforts in Romania, including a description and evaluation of-- (A) United States force posture in Romania, including any new rotations to Romania intended to enhance deterrence following the 2025 decision to end the rotational presence of a United States brigade; (B) consultations with NATO allies r…

NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

(a) Requirement for Risk-based Approach.--Section 3843 of title 10, United States Code, is amended to read as follows: ``Sec. 3843. Contractor business systems: monitoring and surveillance standards ``(a) Requirement for Risk-based Approach.--The Secretary shall implement an agile, streamlined risk-based approach to surveillance of contra…

NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

(a) Requirement for Risk-based Approach.--Section 3843 of title 10, United States Code, is amended to read as follows: ``Sec. 3843. Contractor business systems: monitoring and surveillance standards ``(a) Requirement for Risk-based Approach.--The Secretary shall implement an agile, streamlined risk-based approach to surveillance of contra…

CREC-2026-07-21-PT1-PGH4736 · READ IN THE CONGRESSIONAL RECORD

(b) Modification of Certain Certifications and Assessments.-- (1) Certifications.--Section 1249(b) of the National Defense Authorization Act for Fiscal Year 2026 (Public Law 119-60) is amended-- (A) in the matter preceding paragraph (1), by striking ``The certification described'' and inserting following: ``(1) In general.--Except as prov…

NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

(b) Objectives.--The Commander shall ensure that the Cognitive Performance Enhancement Program-- (1) improves readiness, resilience, and recovery, using evidence-based holistic and proactive high-performance brain training that has a validated ability to scale cost- effectively across the special operations forces enterprise; [[Page H4842…

NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

The complete record

Every one of 4,912 lines we hold for Mike D. Rogers, in date order, each linked to its source. Free to read, in full, without an account. Page 65 of 99.

  1. (2) Contents.--The recommendations required by paragraph (1) shall include updates to such requirements designed to ensure that covered contractors implement a vulnerability disclosure policy consistent with NIST guidelines for contractors as required under section 5 of the IoT Cybersecurity Improvement Act of 2020 (15 U.S.C. 278g-3c). (b) Procurement Requirements.--Not later than 180 days after the date on which the recommended contract language developed pursuant to subsection (a) is received, the Federal Acquisition Regulation Council shall review the recommended contract language and update the FAR as necessary to incorporate requirements for covered contractors to receive information about a potential security vulnerability relating to an information system owned or controlled by a contractor, in performance of the contract.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  2. (a) Recommendations.-- (1) In general.--Not later than 180 days after the date of the enactment of this Act, the Director of the Office of Management and Budget, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, the National Cyber Director, the Director of the National Institute of Standards and Technology, and any other appropriate head of an Executive department, shall-- (A) review the Federal Acquisition Regulation contract requirements and language for contractor vulnerability disclosure programs; and (B) recommend updates to such requirements and language to the Federal Acquisition Regulation Council.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  3. (2) Report and briefing.--Not later than the date that is six months after the date of the enactment of this Act, the Secretary shall provide the congressional defense committees with a report and briefing on the plan created under paragraph (1). The Secretary shall not carry out the pilot program until after the Secretary has provided the report and briefing. (d) Scope.--In carrying out the pilot program, the Secretary shall establish an initial cohort of not more than 20 members of the civilian cybersecurity reserve corps. SEC. 1507. FEDERAL CONTRACTOR VULNERABILITY DISCLOSURE POLICY.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  4. (c) Planning.-- (1) Plan.--Prior to carrying out the pilot program required by subsection (a), the Secretary shall create a detailed written plan for the program, which shall include-- (A) a concept of operations for the civilian cybersecurity reserve corps; (B) an assessment of the necessary legal and contractual requirements; (C) recruitment, assessment, and selection criteria and methodologies; (D) talent management processes and system prototypes; (E) defining the initial mission set and organization structure of the civilian cybersecurity reserve corps; (F) metrics with respect to cost and benefits that will be used to inform the Secretary's evaluation of the pilot program; and (G) any other matters that the Secretary considers appropriate.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  5. (b) Consideration of Prior Report.--In conducting the pilot program required by subsection (a), the Secretary shall take into consideration the findings and recommendations of the report required by section 1540 of the James M. Inhofe National Defense Authorization Act for Fiscal Year 2023 (Public Law 117-263; 136 Stat. 2914) (titled ``Independent Assessment of Civilian Cybersecurity Reserve for Department of Defense'' and dated October 2025).

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  6. (2) Follow-on briefing.--Not later than one year after the date of the enactment of this Act, the Secretary shall brief the congressional defense committees with an update on the implementation of the pilot program, including findings, data, and mission outcomes. SEC. 1506. CIVILIAN CYBERSECURITY RESERVE CORPS PILOT PROGRAM. (a) Program Required.--The Secretary of Defense shall carry out a pilot program to further evaluate the feasibility and advisability of creating and maintaining a civilian cybersecurity reserve corps to enable the Department of Defense and military services to provide qualified civilian manpower to the Department of Defense to effectively respond to significant cyber incidents or to assist in solving other exceptionally difficult cyber workforce-related challenges.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  7. (d) Briefings.-- (1) Initial briefing.--Not later than 120 days after the date of the enactment of this Act, the Secretary, in consultation with the Under Secretary, shall brief the congressional defense committees on the implementation of the pilot program, including-- (A) coordination between and among program offices, the Under Secretary, the commanders of the combatant commands, the operational component, and industry; (B) methods to reduce technical risk and promote competition, including shifting integration risk to industry through pre-integration and demonstration; and (C) plans to accelerate prototyping, independent assessment, and operational integration.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  8. (c) Modular Open Systems Architecture.--The pilot program shall employ modular open systems architecture standards and open interfaces to ensure interoperability, portability, and cybersecurity across platforms. The Secretary shall leverage lessons from prior autonomy and control system efforts while avoiding approaches that limit competition, inhibit innovation, or place primary integration responsibility on the Government where industry solutions are available.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  9. (a) Establishment.--The Secretary of the Navy, in consultation with the Under Secretary of Defense for Research and Engineering, shall establish a pilot program, to be known as the Autonomous Mission Pre-Integration Pilot Program, to assess industry-led approaches for pre-integration of autonomy services and multi-mission payloads on medium unmanned surface vehicles, utilizing a common, cybersecure operating system to enable cross-platform collaboration. (b) Objectives.--The pilot program shall develop and validate rapidly composable, multi-mission capabilities to support distributed maritime operations in contested environments, including pre-integration of-- (1) autonomy services and mission software; (2) kinetic and non-kinetic systems; (3) advanced sensors and communications; and (4) edge-based collaborative artificial intelligence.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  10. (b) Scope of Activities.--The activities described in subsection (a) shall, at a minimum, include-- (1) assessment of vulnerabilities and resilience of critical infrastructure and operational technology systems that support military operations, defense support to civil authorities, and homeland defense missions; (2) coordination with relevant Federal departments and agencies, State, local, Tribal, and territorial authorities, and private sector owners and operators, as appropriate; and (3) integration of cyber, operational technology, and physical effects relevant to disruption, degradation, or compromise of such systems. SEC. 1505. PILOT PROGRAM FOR AUTONOMOUS MISSION INTEGRATION OF UNMANNED SURFACE VEHICLES.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  11. [[Page H4861]] (g) Briefing.--Not later than 45 days after the date of the enactment of this Act, the Secretary shall provide a briefing to the congressional defense committees on preliminary findings of the review. SEC. 1504. INCLUSION OF CRITICAL INFRASTRUCTURE AND OPERATIONAL TECHNOLOGY SECURITY IN COMBATANT COMMAND PLANNING AND READINESS EXERCISES. (a) Requirement.--The Secretary of Defense shall direct the commanders of the combatant commands, consistent with the authorities provided under sections 164 and 167b of title 10, United States Code, to incorporate critical infrastructure security and operational technology security considerations into-- (1) planning activities conducted to execute national defense strategies; and (2) joint and combined planning, training, and readiness exercises.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  12. (2) Elements.--The report shall include-- (A) identification of the official designated as the single accountable official responsible for the cybersecurity of Department of Defense information networks, as specified in subsection (a)(1)(A); (B) a description of any realignment, consolidation, or modification made, or to be made, to the roles, responsibilities, relationships, and authorities of the officials, offices, elements, and organizations reviewed, as specified in subsection (a)(3)(A); (C) a description of any reassignment of functions, personnel, and resources made, or to be made, among the officials, offices, elements, and organizations reviewed, as specified in subsection (a)(3)(B); (D) a description of any duplicative functions eliminated, or to be eliminated, as set forth in subsection (a)(3)(C); (E) a description of any clarification or revision made, or to be made, to reporting relationships and lines of authority, as set forth in subsection (a)(3)(D); (F) a mapping of the responsibilities and authorities assigned as of the date of the enactment of this Act to each respective official, office, element, or organization reviewed (including an identification of whether the responsibility or authority is required by law to be assigned to such official, office, element, or organization, and an mapping of the responsibilities and authorities as they will be assigned after completion of the activities specified in subsection (a)(3); (G) a timeline for implementation of the activities specified in subsection (a)(3), under which all such activities shall be implemented not later than one year after the date of the enactment of this Act; (H) identification of any legislative recommendations, including any provisions of law requiring amendment, to fully implement the goals specified in subsection (a)(1) and the activities specified in subsection (a)(3); and (I) a justification for the new structure, including an explanation for how the new structure better achieves the goals specified in subsection (a)(1) than the current structure.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  13. (f) Report.-- (1) In general.--Not later than 90 days after the date of the enactment of this Act, the Secretary of Defense shall submit to the congressional defense committees a report on the results of the review conducted under subsection (a).

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  14. (d) Limitation on Reassignment or Elimination of Function.--The Secretary may not reassign or eliminate a function associated with an official, office, element, or organization for the purpose of carrying out this section unless the Secretary submits to the congressional defense committees a notification of the reassignment or elimination of the function and a period of 15 days has elapsed after the date on which the notification was submitted. (e) Rule of Construction.--Nothing in this section shall be construed to authorize the Secretary of Defense to modify, transfer, eliminate, or otherwise alter any role, responsibility, relationship, authority, function, or any other matter expressly required by law.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  15. (b) Preservation of Functions.--In carrying out subsection (a), the Secretary shall ensure that all functions necessary for the governance, defense, and operation of Department of Defense information networks are maintained, regardless of the organizational structure to which such functions are assigned. (c) Limitation on Establishment of New Office or Organization.--The Secretary may not establish a new office or organization for the purpose of carrying out this section unless the Secretary determines that such establishment is necessary to achieve the goals specified in subsection (a)(1) and consistent with applicable law.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  16. (3) Realignment.--As a result of the review, and in order to achieve the goals specified in paragraph (1), the Secretary may, consistent with applicable law-- (A) realign, consolidate, or modify the roles, responsibilities, relationships, and authorities of the officials, offices, elements, and organizations specified in paragraph (2); (B) reassign functions, personnel, and resources among such officials, offices, elements, and organizations; (C) eliminate duplicative functions; and (D) clarify or revise reporting relationships and lines of authority.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  17. (2) Scope.--The review conducted under this subsection shall include an assessment of the roles, responsibilities, relationships, and authorities among-- (A) the Chief Information Officer of the Department of Defense; (B) the Assistant Secretary of Defense for Cyber Policy; (C) the Principal Cyber Advisor to the Secretary of Defense; (D) the Commander of the United States Cyber Command; (E) the Department of Defense Cyber Defense Command; and (F) such other offices, elements, or organizations as the Secretary determines appropriate.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  18. (C) Eliminate structural overlap, duplication, and fragmentation across organizations responsible for cybersecurity, information technology, network defense, and defensive cyber operations. (D) Reduce overlapping responsibilities and ensure alignment of policy, strategy, budgetary oversight, and operational support necessary for the cybersecurity of Department of Defense information networks in an evolving threat environment.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  19. (a) Review and Realignment.-- (1) Review required.--The Secretary of Defense shall conduct a comprehensive review of the roles, responsibilities, relationships, authorities, and governance structures relating to cybersecurity, information technology, network defense, and defensive cyber operations within the Department of Defense in order to achieve the following goals: (A) Establish clear accountability for the cybersecurity of Department of Defense information networks, including identification of one official designated as the single accountable official responsible for the cybersecurity of Department of Defense information networks. (B) Improve the operational effectiveness, responsiveness, and unity of effort of Department-wide cybersecurity, information technology, network defense, and defensive cyber operations.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  20. ``(3) The term `covered AI vulnerability' means an exploitable weakness, vulnerability, or systemic issue in an artificial intelligence system or related component that could materially affect mission performance, compromise system integrity, create safety risk, or result in unauthorized or unintended behavior.''. SEC. 1503. REVIEW AND REALIGNMENT OF DEPARTMENT OF DEFENSE CYBERSECURITY RESPONSIBILITIES.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  21. ``(2) The term `covered AI incident' means an event in which an artificial intelligence system-- ``(A) causes unintended operational, safety, or security harm; ``(B) operates outside authorized parameters or approved safety, legal, or mission guardrails; ``(C) materially degrades mission performance or reliability in a real-world or operationally representative environment; ``(D) fails to respond to an operator disengage command; ``(E) operates in a manner that, under reasonably foreseeable circumstances, could have resulted in significant unintended operational, safety, or security harm; or ``(F) operates in a manner that raises concerns regarding system control and autonomy.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  22. ``(2) Each report under this subsection shall be submitted in unclassified form but may include a classified annex. ``(j) Definitions.--In this section: ``(1) The term `artificial intelligence' has the meaning given such term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  23. ``(i) Annual Report.--(1) In each of years 2027 through 2031, the Secretary shall submit to the congressional defense committees an annual report on the program. The report shall include-- ``(A) the number of reports made of incidents and vulnerabilities and the categorizations of such reports; ``(B) a summary of significant trends, recurring risks, systemic issues, and corrective actions taken in response; ``(C) in the case of any covered AI incident resulting in the loss of life of, or in bodily harm to, a member of the Army, Navy, Marine Corps, Air Force, or Space Force-- ``(i) a description of the incident, including the system or systems involved and the operational context; ``(ii) the date and time the incident occurred; ``(iii) an assessment of the cause and operational consequence of the incident; and ``(iv) any corrective actions taken; and ``(D) any recommendations for changes to testing, procurement, cybersecurity, or deployment policies relating to artificial intelligence systems.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  24. ``(g) Protection of Reports.--(1) The Secretary shall establish a protected disclosure process, informed by established vulnerability disclosure practices, through which members of the Armed Forces, civilian employees, contractors, and subcontractors at any tier may report covered AI incidents and covered AI vulnerabilities in good faith. ``(2) The Secretary shall ensure that a person making a report in good faith under paragraph (1) is not, on the basis of that report alone, subject to adverse contract action, subject to adverse personnel action, or otherwise retaliated against by the Department. ``(h) Protection of Information.--The Secretary shall establish procedures to protect sensitive, proprietary, and classified information submitted through the protected disclosure process under subsection (g).

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  25. ``(f) Department-wide and Program-level Matters.--(1) In the case of any incident or vulnerability categorized under subsection (e)(2)(A) or (B), the Secretary, acting through the official designated under subsection (d), shall coordinate any responses that the Secretary considers appropriate, such as remediation, retesting, mitigation measures, or deployment restrictions. ``(2) In addition, in the case of any incident or vulnerability described in subsection (e)(2)(A), the Secretary, acting through the official, shall require-- ``(A) a documented corrective action plan; and ``(B) validation that the mitigation measures, if any, in such plan have been implemented before continued operational use.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  26. The Secretary, acting through such official, shall receive and standardize reports, conduct trend analysis, identify recurring risks and failure modes, and issue guidance, alerts, and recommendations, as appropriate. ``(e) Reporting and Categorization.--(1) The Secretary shall require prompt reporting to the official designated under subsection (d) of-- ``(A) any covered AI incident; and ``(B) any covered AI vulnerability. ``(2) The Secretary, acting through the official, shall categorize each incident or vulnerability reported to the official according to whether the incident or vulnerability requires-- ``(A) a Department-wide response; ``(B) a response at the program level; or ``(C) a response at a local level.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  27. ``(c) Requirements for Program.--The program shall-- ``(1) be designed using practices drawn from established safety incident reporting programs, vulnerability disclosure programs, and programs to identify and develop lessons learned; ``(2) emphasize non-punitive reporting, protection of sensitive and proprietary information, and dissemination of lessons learned, as appropriate; and ``(3) include a mechanism to enable timely access to and sharing of relevant logs, system data, and model information as necessary to support analysis and response. ``(d) Designation of Official.--The Secretary shall designate an appropriate official for the reporting, tracking, analysis, and remediation of covered AI incidents and covered AI [[Page H4860]] vulnerabilities under this section.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  28. ``(b) Purpose.--The purpose of the program established under subsection (a) shall be to-- ``(1) identify recurring risks, failure modes, vulnerabilities, and systemic weaknesses in artificial intelligence systems, including risks or failure modes arising from human-machine teaming; ``(2) support mitigation of significant risks; and ``(3) inform testing, procurement, cybersecurity, and deployment decisions to improve the safety, security, reliability, and operational effectiveness of such systems.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  29. Chapter 131 of title 10, United States Code, is amended by inserting after section 2224a the following new section: ``Sec. 2224b. Artificial intelligence incident and vulnerability reporting program ``(a) In General.--The Secretary of Defense shall establish a centralized Department-wide program for the reporting, tracking, analysis, and remediation of covered AI incidents and covered AI vulnerabilities arising from the development, testing, procurement, fielding, or operation of artificial intelligence systems within the Department of Defense.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  30. (E) The approach to fielding data resilience capabilities for data that is mission critical or essential to the operation of Department of Defense information systems and national security systems, including immutable backups that preserve logically separated copies isolated from external networks, and continuous monitoring of backup environments to detect tampering, insider threats, and malicious corruption. (2) Form.--The strategy under paragraph (1) shall be submitted in unclassified form, but may contain a classified annex. (3) Definition.--In this subsection, the term ``recovery time objective'' means the maximum allowable time the Secretary of Defense determines necessary to restore critical functions and data following a cyberattack. SEC. 1502. DEPARTMENT OF DEFENSE AI INCIDENT AND VULNERABILITY REPORTING PROGRAM.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  31. (c) Data Recovery Strategy.-- (1) Submission to committees.--Not later than 90 days after the date of the enactment of this Act, the Secretary of Defense shall submit to the congressional defense committees a data recovery strategy for the Department of Defense that includes information relating to the following: (A) Recovery time objectives for such strategy. (B) The approach to accomplish such objectives. (C) Oversight processes with respect to such strategy. (D) The funds necessary to carry out such strategy.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  32. (3) Report.--Not later than one year after the establishment of the pilot program under paragraph (1), the Secretary shall submit to the congressional defense committees a report on the pilot program that includes-- (A) an assessment of the effectiveness of the capabilities fielded under the pilot program in supporting recovery time objectives established under section 391c of title 10, United States Code, as added by subsection (a); (B) the cost of fielding such capabilities; and (C) a recommendation on whether to extend such capabilities Department-wide. (4) Definition.--In this subsection, the term ``covered system'' means an information system or national security system of the Department of Defense that stores or processes data that is mission critical, as identified pursuant to subsection (a)(1)(A) of such section 391c.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  33. (2) Scope.--The Secretary shall carry out the pilot program under paragraph (1) across not fewer than three covered systems selected by the Secretary, prioritizing covered systems with the highest concentration of data that is mission critical or essential to the operation of Department of Defense information systems and national security systems.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  34. (b) Data Resilience Pilot Program.-- (1) Establishment.--Not later than 180 days after the date of the enactment of this Act, the Secretary of Defense shall establish a pilot program to assess the feasibility and effectiveness of fielding data resilience capabilities for data that is mission critical or essential to the operation of Department of Defense information systems and national security systems, including-- (A) immutable backups that preserve logically separated copies of data isolated from external networks by means of software, firewalls, or other controls; and (B) continuous monitoring of backup environments to detect tampering, insider threats, and malicious corruption.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  35. ``(b) Definition.--In this section, the term `recovery time objective' means the maximum allowable time the Secretary of Defense determines necessary to restore critical functions and data following a cyberattack.''.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  36. Data recovery requirements ``(a) Mandatory Recovery Time Objectives.--(1) The Secretary of Defense shall, with respect to each element of the Department of Defense, carry out the following: ``(A) Identify data that is mission critical or essential to the operation of Department of Defense information systems and national security systems. ``(B) Not later than 180 days after the date of the enactment of this section, establish mandatory recovery time objectives for data so identified. ``(2) Each recovery time objective established under paragraph (1) shall satisfy the following requirements: ``(A) Be based upon the type of data to which such objective applies, including with respect to threat exposure. ``(B) Be updated in response to intelligence on evolving threats.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  37. (2) The term ``National Defense Stockpile'' means the stockpile provided for in section 3 of the Strategic and Critical Materials Stockpiling Act (50 U.S.C. 98b). (3) The term ``United States person'' has the meaning given such term in section 7701(a)(30) of the Internal Revenue Code of 1986. TITLE XV--CYBERSPACE-RELATED MATTERS Subtitle A--Cybersecurity SEC. 1501. DATA RECOVERY REQUIREMENTS AND STRATEGY. (a) Data Recovery Requirements.--Chapter 19 of title 10, United States Code, is amended by inserting after section 391b the following new section: ``Sec. 391c.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  38. Such report shall include-- (1) an assessment of the operational effectiveness of each traceability system evaluated under the pilot program; (2) an assessment of the impacts of such system on defense readiness an surge capacity; (3) an assessment of the implications of such system for National Defense Stockpile management and replenishment; (4) an assessment of the cost, scalability, and integration of such system with existing Department of Defense procurement systems; and (5) recommendations for expansion of the pilot program or permanent authorization of a traceability requirement for defense-critical supply chains. (i) Definitions.--In this section: (1) The term ``covered materials'' means any material listed in subsection (d)(1).

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  39. (h) Report.--Not later than two years after the date on which the Secretary of Defense establishes the pilot program under subsection (a), the Secretary shall submit to the congressional defense committees a report assessing the results of the pilot program.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  40. (g) Briefing.--Not later than one year after the date on which the Secretary of Defense establishes the pilot program under subsection (a), the Secretary shall provide a briefing to the Committee on Armed Services of the House of Representatives. Such briefing shall include-- (1) a description of each traceability system being evaluated under the pilot program, including an assessment of how such system satisfied the technical requirements under subsection (d); (2) the criteria and process used to select a traceability service provider for the pilot program, including how provider eligibility requirements under subsection (c) were assessed and enforced; (3) the timeline and status of pilot program implementation milestones; and (4) any challenges or resource requirements encountered in establishing the pilot programs.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  41. (f) Phased Expansion.-- (1) Phase i.--During the period beginning on the date the pilot program is established under subsection (a) and ending on September 30, 2028, the Secretary of Defense shall implement a traceability system for materials managed by the Defense Logistics Agency, with priority given to covered materials designated as critical to weapons systems production. (2) Phase ii.--Subject to the results of the report required under subsection (h), the Secretary of Defense may expand the traceability system to covered materials procured under defense contracts subject to the Defense Federal Acquisition Regulation Supplement, beginning not earlier than October 1, 2029.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  42. (e) Enforcement.--The Secretary of Defense may enforce compliance with the requirements of this section through-- (1) suspension or termination of contracts with entities that fail to comply with traceability system requirements under this section; (2) withholding of payments for contractors or subcontractors that fail to provide required traceability documentation; and (3) exclusion from future defense contracts of entities that repeatedly fail to meet traceability system requirements under this section.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  43. (2) Technical requirements.--Any contract entered into under this section shall require that [[Page H4859]] the traceability system provided under such contract-- (A) provides end-to-end visibility of covered materials from point of extraction through processing, transportation, and end use in defense articles or defense services; (B) verifies the origin, chain of custody, mass balance, purity, and processing history of covered materials; (C) maintains tamper-resistant, immutable, and time-stamped records of custody events, transformation events, and compliance status for covered materials; (D) employs cryptographic mechanisms to protect sensitive commercial and national security data while enabling verification by authorized security personnel; (E) enables continuous auditing, anomaly detection, and identification and assessment of supply chain threats; and (F) integrates with existing Department of Defense procurement, intelligence monitoring, and risk assessment frameworks, including support compliance audits conducted under section 252.225-7052 of the Defense Federal Acquisition Regulation, or successor regulations.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  44. (d) Traceability System.-- (1) Covered materials.--Any contract entered into under this section shall require that the traceability system provided under such contract traces the following materials: (A) Titanium and titanium alloys. (B) Cobalt. (C) Rare earth elements and permanent magnet materials. (D) Lithium and battery-grade materials. (E) Such other strategic and critical materials as the Secretary of Defense determines are necessary to support defense production and surge requirements.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  45. (c) Traceability Providers.-- (1) Requirements for providers.--The Secretary of Defense shall require that any entity that enters into a contract under this section-- (A) be organized under the laws of the United States; (B) be owned and controlled by a United States person; and (C) not be subject to foreign ownership or control or influence by any foreign government. (2) Contract requirements.--Any contract entered into under this section shall require that the entity operate exclusively as a noncustodial digital traceability and verification service and shall not-- (A) extract, process, refine, transport, store, broker, finance, or take title to any covered material; or (B) exercise physical control, custody, or possession of any covered material.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  46. In carrying out the pilot program, the Secretary of Defense shall seek to-- (1) improve the ability of the Department of Defense to rapidly mobilize and allocate materials during national emergencies or contingencies; and (2) inform potential future Department-wide implementation of traceability requirements for defense-critical supply chains. (b) Contracts.--In carrying out the pilot program, the Secretary of Defense shall seek to enter into contracts with appropriate entities to provide traceability systems in accordance with this section.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  47. There is hereby authorized to be appropriated for fiscal year 2027 from the Armed Forces Retirement Home Trust Fund the sum of $77,000,000 for the operation of the Armed Forces Retirement Home. SEC. 1413. CRITICAL MINERALS TRACEABILITY PILOT PROGRAM. (a) Establishment.--Not later than 180 days after the date of the enactment of this Act, the Secretary of Defense shall establish a pilot program within the Defense Logistics Agency to develop and evaluate traceability systems for essential materials managed by the Agency, including materials held in or acquired for the National Defense Stockpile.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  48. (c) Use of Transferred Funds.--For the purposes of subsection (b) of such section 1704, facility operations for which funds transferred under subsection (a) may be used are operations of the Captain James A. Lovell Federal Health Care Center, consisting of the North Chicago Veterans Affairs Medical Center, the Navy Ambulatory Care Center, and supporting facilities designated as a combined Federal medical facility under an operational agreement covered by section 706 of the Duncan Hunter National Defense Authorization Act for Fiscal Year 2009 (Public Law 110-417; 122 Stat. 4500). SEC. 1412. AUTHORIZATION OF APPROPRIATIONS FOR ARMED FORCES RETIREMENT HOME.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  49. 2129), is amended by striking ``September 30, 2027'' and inserting ``September 30, 2028''. (b) Authority for Transfer of Funds.--Of the funds authorized to be appropriated for section 1405 and available for the Defense Health Program for operation and maintenance, $174,000,000 may be transferred by the Secretary of Defense to the Joint Department of Defense-Department of Veterans Affairs Medical Facility Demonstration Fund established by subsection (a)(1) of section 1704 of the National Defense Authorization Act for Fiscal Year 2010 (Public Law 111-84; 123 Stat. 2571). For purposes of subsection (a)(2) of such section 1704, any funds so transferred shall be treated as amounts authorized and appropriated specifically for the purpose of such a transfer.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD

  50. (b) Authorization of Appropriations.--Section 53209 of title 46, United States Code, is amended by striking ``$10,000,000 for each of the fiscal years 2021 through 2035'' and inserting ``$30,000,000 for each of the fiscal years 2027 through 2040''. Subtitle B--Other Matters SEC. 1411. EXTENSION OF AUTHORITIES FOR FUNDING AND MANAGEMENT OF JOINT DEPARTMENT OF DEFENSE- DEPARTMENT OF VETERANS AFFAIRS MEDICAL FACILITY DEMONSTRATION FUND FOR CAPTAIN JAMES A. LOVELL HEALTH CARE CENTER, ILLINOIS. (a) In General.--Section 1704(e) of the National Defense Authorization Act for Fiscal Year 2010 (Public Law 111-84; 123 Stat. 2573), as most recently amended by section 1421(a) of the National Defense Authorization Act for Fiscal Year 2025 (Public Law 118-159; 138 Stat.

    NATIONAL DEFENSE AUTHORIZATION ACT FOR FISCAL YEAR 2027 · 2026-07-21 · READ IN THE CONGRESSIONAL RECORD