(a)
In general— Beginning not later than 1 year after the date on which the employment codes are assigned to employees pursuant to section 3(b)(2), and annually through 2021, the head of each Federal agency, in consultation with the Director and the Secretary, shall—
(1)
identify Cybersecurity Work Categories and Specialty Areas of critical need in the agency’s cybersecurity workforce; and
(2)
submit a report to the Director that—
(A)
describes the Cybersecurity Work Categories and Specialty Areas identified under paragraph (1); and
(B)
substantiates the critical need designations.
(b)
Guidance— The Director shall provide Federal agencies with timely guidance for identifying Cybersecurity Work Categories and Specialty Areas of critical need, including—
(1)
current Cybersecurity Work Categories and Specialty Areas with acute skill shortages; and
(2)
Cybersecurity Work Categories and Specialty Areas with emerging skill shortages.
(c)
Cybersecurity critical needs report— Not later than 18 months after the date of the enactment of this Act, the Director, in consultation with the Secretary, shall—
(1)
identify Specialty Areas of critical need for cybersecurity workforce across all Federal agencies; and
(2)
submit a progress report on the implementation of this section to the appropriate congressional committees.