Congress finds the following:
(1)
According to the Bureau of Labor Statistics, there are more than 347,000 manufacturing establishments in the United States, of which 72 percent have fewer than 20 employees and 99 percent have fewer than 500 employees.
(2)
Independent studies from the National Defense Industry Association, the Defense Science Board, the Alliance for Manufacturing Foresight, and the McKinsey Global Institute have highlighted—
(A)
the centrality of small manufacturers to United States manufacturing supply chains for domestic economic growth;
(B)
the vulnerability of such manufacturers to the defense industrial base for national security; and
(C)
the vulnerability of such manufacturers to cybersecurity threats and breaches.
(3)
As of December 31, 2017, Department of Defense suppliers must comply with new, tougher cybersecurity requirements to ensure adequate security to protect controlled unclassified information relevant to defense manufacturing supply chains. The requirements call for defense suppliers to implement and create a plan of action to respond to the guidance developed by the National Institute of Standards and Technology.
(4)
The Department of Commerce has found significant cybersecurity vulnerability of small manufacturers. A survey of 9,000 contract facilities documented that 6,650 small facilities lagged behind medium and large firms across a broad range of 20 cybersecurity indicators. For several indicators, fewer than half of small firms had cybersecurity measures in place.
(5)
Over the past 5 years the national network of centers operating as part of the Hollings Manufacturing Extension Partnership has worked closely with the Department of Defense to bolster the resilience of the defense industrial base supply chain. Since 2013, such centers have completed more than 2,500 projects with 1,650 companies that are suppliers to the Department of Defense.
(6)
In 2017, the Hollings Manufacturing Extension Partnership interacted with more than 1,000 small manufacturers on the cybersecurity requirements of the Department of Defense. This work by the Hollings Manufacturing Extension Partnership has revealed a significant lack of awareness of the Department of Defense cybersecurity requirements and a deficiency of financial and technical resources required to manage cybersecurity risks. If cybersecurity vulnerabilities remain unaddressed, defense supply chains face a higher likelihood of serious and exploitable vulnerabilities, as well as a substantial reduction in the number of suppliers compliant with Department of Defense requirements, and thereby ineligible to provide products and services to the Department of Defense.
(7)
The Hollings Manufacturing Extension Partnership is well positioned to aid suppliers of the Department of Defense in complying with cybersecurity requirements of the Department to ensure adequate security to protect controlled unclassified information relevant to defense manufacturing supply chains.