The SAFE Supply Chains Act requires federal agencies to purchase information and communications technology hardware, including embedded software and firmware, only from original equipment manufacturers or their authorized resellers, rather than from unverified third-party sellers. This is meant to reduce the risk of counterfeit, tampered, or insecure tech products entering the federal supply chain. Agency heads can waive the requirement if a purchase is needed for legitimate scientific research or to avoid disrupting mission-critical operations, but they must notify the Office of Management and Budget in writing and justify the exception. Agencies are also directed to help vendors who currently don't qualify learn how to become authorized resellers, and OMB must report annually to Congress for six years on how many waivers are granted and what agencies are doing to reduce reliance on them. The law takes effect one year after enactment and does not authorize any new funding to implement it.
Take Action
Your position
Add a comment
to comment on this bill.
Annotate the text
Highlight any passage on the Summary or Full Text tab to attach a note. Annotations appear on the Annotations tab.