“(a) In General.—Beginning not later than 1 year after the date on which the employment codes are assigned to employees pursuant to section 303(b)(2), and annually thereafter through 2022, the head of each Federal agency, in consultation with the Director, the Director of the National Institute of Standards and Technology, and the Secretary of Homeland Security, shall—“(1) identify information technology, cybersecurity, or other cyber-related work roles of critical need in the agency’s workforce; and
“(2) submit a report to the Director that—“(A) describes the information technology, cybersecurity, or other cyber-related roles identified under paragraph (1); and
“(B) substantiates the critical need designations.
“(b) Guidance.—The Director shall provide Federal agencies with timely guidance for identifying information technology, cybersecurity, or other cyber-related roles of critical need, including—“(1) current information technology, cybersecurity, and other cyber-related roles with acute skill shortages; and
“(2) information technology, cybersecurity, or other cyber-related roles with emerging skill shortages.
“(c) Cybersecurity Needs Report.—Not later than 2 years after the date of the enactment of this Act [Dec. 18, 2015], the Director, in consultation with the Secretary of Homeland Security, shall—“(1) identify critical needs for information technology, cybersecurity, or other cyber-related workforce across all Federal agencies; and
“(2) submit a progress report on the implementation of this section to the appropriate congressional committees.