This bill strengthens transparency requirements for defense contractors that have operations in China. It amends existing law to require companies performing defense contracts to disclose whether Chinese government agencies or companies have requested or obtained access to their data under China's National Intelligence Law or similar regulations. For contractors providing software services to the Defense Department, the bill also requires them to describe their process for reporting software vulnerabilities to Chinese authorities and to notify U.S. affiliates of any flaws within 48 hours of reporting them to China. The Department of Defense must revise its acquisition regulations within 180 days of the bill's enactment to enforce these notification requirements and ensure the department receives information about vulnerabilities reported to Chinese authorities. The legislation applies to any contractor that develops software in China while also holding U.S. defense contracts.
Take Action
Your position
Add a comment
to comment on this bill.
Annotate the text
Highlight any passage on the Summary or Full Text tab to attach a note. Annotations appear on the Annotations tab.