(a)
Establishment of program—
(1)
In general— The Secretary shall establish a voluntary program to identify and certify covered products with superior cybersecurity and data security through voluntary certification and labeling of, and other forms of communication about, covered products and subsets of covered products that meet industry-leading cybersecurity and data security benchmarks to enhance cybersecurity and protect data.
(2)
Grades— Labels applied to products under the Cyber Shield program—
(B)
may be in the form of different grades that display the extent to which a product meets the industry-leading cybersecurity and data security benchmarks.
(b)
Consultation— Not later than 90 days after the date of enactment of this Act, the Secretary shall establish a process for consulting interested parties, the Secretary of Health and Human Services, the Commissioner of Food and Drugs, the Secretary of Homeland Security, and other Federal agencies in carrying out the Cyber Shield program.
(c)
Duties— In carrying out the Cyber Shield program, the Secretary—
(1)
shall—
(A)
establish and maintain cybersecurity and data security benchmarks, by convening and consulting interested parties and other Federal agencies, for products with the Cyber Shield label to ensure that those products perform better than their less secure counterparts; and
(B)
in carrying out subparagraph (A)—
(i)
engage in an open public review and comment process;
(ii)
in consultation with the Advisory Committee, identify and apply cybersecurity and data security benchmarks to different subsets of covered products based on—
(I)
cybersecurity and data security risk;
(II)
the sensitivity of the information collected, transmitted, or stored by the product; and
(III)
product functionality; and
(iii)
to the extent possible, incorporate existing benchmarks when establishing and maintaining cybersecurity and data security benchmarks;
(2)
may not establish benchmarks under paragraph (1) that are—
(A)
arbitrary, capricious, an abuse of discretion, or otherwise not in accordance with law; or
(B)
unsupported by evidence;
(3)
shall permit a manufacturer or distributor of a covered product to display a Cyber Shield label reflecting the extent to which the product meets the industry-leading cybersecurity and data security benchmarks established under paragraph (1);
(4)
shall promote technologies that are compliant with the cybersecurity and data security benchmarks established by the Secretary as the preferred technologies in the marketplace for—
(A)
enhancing cybersecurity; and
(5)
shall work to enhance public awareness of the Cyber Shield label, including through public outreach, education, research and development, and other means;
(6)
shall preserve the integrity of the Cyber Shield label;
(7)
if helpful in fulfilling the obligation under paragraph (6), may elect to not treat a covered product as a Cyber Shield-certified product until the product meets appropriate conformity standards, which may include—
(A)
testing by an accredited third-party certifying laboratory or other entity in accordance with the Cyber Shield program; and
(B)
certification by the laboratory or entity described in subparagraph (A) as meeting the applicable cybersecurity and data security benchmarks established by the Secretary;
(8)
not less frequently than once every 2 years after establishing cybersecurity and data security benchmarks for a product category under paragraph (1), shall review and, if appropriate, update the cybersecurity and data security benchmarks for that product category;
(9)
shall solicit comments from interested parties and the Advisory Committee prior to establishing or revising a Cyber Shield product category or benchmark (or prior to the effective date of the establishment or revision of a product category or benchmark);
(10)
upon adoption of a new or revised product category or benchmark, shall provide reasonable notice to interested parties of any changes (including effective dates) to product categories or benchmarks, along with—
(A)
an explanation of the changes; and
(B)
as appropriate, responses to comments submitted by interested parties; and
(11)
shall provide appropriate lead time prior to the applicable effective date for a new or a significant revision to a product category or benchmark, taking into account the timing requirements of the manufacturing, product marketing, and distribution process for the product or products addressed.
(d)
Deadlines— Not later than 2 years after the date of enactment of this Act, the Secretary shall establish cybersecurity and data security benchmarks for covered products under subsection (c)(1), which shall take effect not later than 60 days after the date on which the benchmarks are established.
(e)
Administration— The Secretary, in consultation with the Advisory Committee, may enter into a contract with a third party to administer the Cyber Shield program if—
(1)
the third party is an impartial administrator; and
(2)
entering into the contract improves the cybersecurity and data security of covered products.
(f)
Program evaluation—
(1)
In general— Not later than 4 years after the date of enactment of this Act, and not less frequently than every 2 years thereafter, the Inspector General of the Department of Commerce shall evaluate the Cyber Shield program.
(2)
Requirements— In conducting an evaluation under paragraph (1), the Inspector General of the Department of Commerce shall—
(A)
evaluate the extent to which the cybersecurity and data security benchmarks established under the Cyber Shield program address cybersecurity and data security threats;
(B)
assess how the benchmarks have evolved to meet emerging cybersecurity and data security threats;
(C)
conduct covert testing to evaluate the integrity of certification testing; and
(D)
assess the costs to businesses of participating in the Cyber Shield program.