Federal
Small Manufacturer Cybersecurity Enhancement Act
Source: Congress.gov ·
1,227 words in original text
Plain English summary not yet available
The full original text is available below. Check back soon as we process this bill.
I
116TH CONGRESS
2D SESSION
H. R. 7265
To improve assistance provided by the Hollings Manufacturing Extension
Partnership to small manufacturers in the defense industrial supply
chain on matters relating to cybersecurity, and for other purposes.
IN THE HOUSE OF REPRESENTATIVES
JUNE 18, 2020
Mr. PANETTA (for himself, Mr. WILSON of South Carolina, Ms. SLOTKIN, Mr.
MITCHELL, Mr. RUPPERSBERGER, Mr. RESCHENTHALER, Ms. STEVENS,
Mr. CARBAJAL, and Mr. SUOZZI) introduced the following bill; which was
referred to the Committee on Armed Services
A BILL
To improve assistance provided by the Hollings Manufac-
turing Extension Partnership to small manufacturers in
the defense industrial supply chain on matters relating
to cybersecurity, and for other purposes.
Be it enacted by the Senate and House of Representa-
1
tives of the United States of America in Congress assembled,
2
SECTION 1. SHORT TITLE.
3
This Act may be cited as the ‘‘Small Manufacturer
4
Cybersecurity Enhancement Act’’.
5
SEC. 2. FINDINGS.
6
Congress finds the following:
7
VerDate Sep 11 2014
23:23 Jul 10, 2020
Jkt 099200
PO 00000
Frm 00001
Fmt 6652
Sfmt 6201
E:\BILLS\H7265.IH
H7265
kjohnson on DSK79L0C42PROD with BILLS
2
•HR 7265 IH
(1) The Office of the Director of National Intel-
1
ligence stated in its 2019 Worldwide Threat Assess-
2
ment that United States adversaries and strategic
3
competitors will increasingly use cyber capabilities—
4
including cyber espionage, attack, and influence—to
5
seek political, economic, and military advantage over
6
the United States and its allies.
7
(2) The Department of Defense recognizes that
8
small manufacturers operating in the defense supply
9
chain are particularly vulnerable to cyber attacks be-
10
cause they frequently lack the necessary human and
11
financial resources to protect themselves.
12
(3) The Department of Defense is imple-
13
menting its Cybersecurity Maturity Model Certifi-
14
cation (CMMC) to protect Controlled Unclassified
15
Information and critical United States technology
16
and information from cyber theft and hacking. All
17
defense contractors will need to comply with CMMC.
18
(4) The Undersecretary of Defense for Acquisi-
19
tion and Sustainment has stated that smaller com-
20
panies in the defense supply chain might not be able
21
to afford the Department of Defense’s increasingly
22
demanding cybersecurity requirements, but that the
23
Department is committed to ensuring that such
24
companies get the resources they need to comply.
25
VerDate Sep 11 2014
23:23 Jul 10, 2020
Jkt 099200
PO 00000
Frm 00002
Fmt 6652
Sfmt 6201
E:\BILLS\H7265.IH
H7265
kjohnson on DSK79L0C42PROD with BILLS
3
•HR 7265 IH
(5) According to the Bureau of Labor Statis-
1
tics, there are more than 347,000 manufacturing es-
2
tablishments in the United States, of which 72 per-
3
cent have fewer than 20 employees and 99 percent
4
have fewer than 500 employees.
5
(6) During the past 7 years the Hollings Manu-
6
facturing Extension Partnership (MEP) Centers
7
have worked closely with the Department of Defense
8
to bolster the resilience of the defense industrial
9
base supply chain by providing cybersecurity services
10
to small manufacturers. The MEP Centers have
11
worked with more than 26,000 small- and medium-
12
sized manufacturers nationwide in fiscal year 2019
13
alone.
14
(7) Hollings Manufacturing Extension Partner-
15
ship Centers are located in all 50 States and provide
16
a nationwide network that is—
17
(A) raising the awareness of small manu-
18
facturers to cyber threats;
19
(B) helping small manufacturers comply
20
with new Department of Defense cybersecurity
21
requirements; and
22
(C) helping small manufacturers under-
23
stand that if they do not comply with new De-
24
partment of Defense cybersecurity require-
25
VerDate Sep 11 2014
23:23 Jul 10, 2020
Jkt 099200
PO 00000
Frm 00003
Fmt 6652
Sfmt 6201
E:\BILLS\H7265.IH
H7265
kjohnson on DSK79L0C42PROD with BILLS
4
•HR 7265 IH
ments, then they risk losing their defense con-
1
tracts.
2
(8) The Hollings Manufacturing Extension
3
Partnership Centers are well-positioned to aid small
4
manufacturing companies in the defense supply
5
chain in complying with cybersecurity requirements
6
to protect controlled unclassified information rel-
7
evant to defense manufacturing supply chains.
8
SEC. 3. ASSISTANCE FOR SMALL MANUFACTURERS IN THE
9
DEFENSE INDUSTRIAL SUPPLY CHAIN ON
10
MATTERS RELATING TO CYBERSECURITY.
11
(a) IN GENERAL.—Subject to the availability of ap-
12
propriations, the Secretary of Defense, acting through the
13
Office of Economic Adjustment and in consultation with
14
the Director of the National Institute of Standards and
15
Technology, may make grants to a Center established
16
under the Hollings Manufacturing Extension Partnership
17
for the purpose of providing cybersecurity services to small
18
manufacturers.
19
(b) CRITERIA.—The Secretary shall establish and
20
publish in the Federal Register criteria for selecting grant
21
recipients under this section.
22
(c) USE OF FUNDS.—Grant funds under this sec-
23
tion—
24
VerDate Sep 11 2014
23:23 Jul 10, 2020
Jkt 099200
PO 00000
Frm 00004
Fmt 6652
Sfmt 6201
E:\BILLS\H7265.IH
H7265
kjohnson on DSK79L0C42PROD with BILLS
5
•HR 7265 IH
(1) shall be used by a Center to provide small
1
manufacturers with cybersecurity services related
2
to—
3
(A) compliance with the cybersecurity re-
4
quirements of the Department of Defense Sup-
5
plement to the Federal Acquisition Regulation,
6
including awareness, assessment, evaluation,
7
preparation, and implementation of cybersecu-
8
rity services; and
9
(B) achieving compliance with the Cyberse-
10
curity Maturity Model Certification framework
11
of the Department of Defense; and
12
(2) may be used by a Center to employ trained
13
personnel to deliver cybersecurity services to small
14
manufacturers.
15
(d) REPORTS.—The Secretary shall submit to the
16
congressional defense committees a biennial report on
17
grants awarded under this section. To the extent prac-
18
ticable, each such report shall include the following with
19
respect to the years covered by the report:
20
(1) The number of small manufacturing compa-
21
nies assisted.
22
(2) A description of the cybersecurity services
23
provided.
24
VerDate Sep 11 2014
23:23 Jul 10, 2020
Jkt 099200
PO 00000
Frm 00005
Fmt 6652
Sfmt 6201
E:\BILLS\H7265.IH
H7265
kjohnson on DSK79L0C42PROD with BILLS
6
•HR 7265 IH
(3) A description of the cybersecurity matters
1
addressed.
2
(4) An analysis of the operational effectiveness
3
and cost-effectiveness of the cybersecurity services
4
provided.
5
(e) TERMINATION.—The authority of the Secretary
6
of Defense to make grants under this section shall termi-
7
nate on the date that is five years after the date of the
8
enactment of this Act.
9
(f) DEFINITIONS.—In this section:
10
(1) CENTER.—The term ‘‘Center’’ has the
11
meaning given that term in section 25(a) of the Na-
12
tional Institute of Standards and Technology Act
13
(15 U.S.C. 278k(a)).
14
(2) CONGRESSIONAL DEFENSE COMMITTEES.—
15
The term ‘‘congressional defense committees’’ has
16
the meaning given that term in section 101(a)(16)
17
of title 10, United States Code.
18
(3) SMALL MANUFACTURER.—The term ‘‘small
19
manufacturer’’ has the meaning given that term in
20
section 1644(g) of the John S. McCain National De-
21
fense Authorization Act for Fiscal Year 2019 (Pub-
22
lic Law 115–232; 10 U.S.C. 2224 note).
23
Æ
VerDate Sep 11 2014
23:23 Jul 10, 2020
Jkt 099200
PO 00000
Frm 00006
Fmt 6652
Sfmt 6301
E:\BILLS\H7265.IH
H7265
kjohnson on DSK79L0C42PROD with BILLS
Important: This plain English summary was generated by AI and is provided for informational purposes only.
It is not legal advice. Always consult the official bill text on Congress.gov
or a qualified attorney for legal matters.