Congress finds the following:
(1)
The Office of the Director of National Intelligence stated in its 2019 Worldwide Threat Assessment that United States adversaries and strategic competitors will increasingly use cyber capabilities—including cyber espionage, attack, and influence—to seek political, economic, and military advantage over the United States and its allies.
(2)
The Department of Defense recognizes that small manufacturers operating in the defense supply chain are particularly vulnerable to cyber attacks because they frequently lack the necessary human and financial resources to protect themselves.
(3)
The Department of Defense is implementing its Cybersecurity Maturity Model Certification (CMMC) to protect Controlled Unclassified Information and critical United States technology and information from cyber theft and hacking. All defense contractors will need to comply with CMMC.
(4)
The Undersecretary of Defense for Acquisition and Sustainment has stated that smaller companies in the defense supply chain might not be able to afford the Department of Defense’s increasingly demanding cybersecurity requirements, but that the Department is committed to ensuring that such companies get the resources they need to comply.
(5)
According to the Bureau of Labor Statistics, there are more than 347,000 manufacturing establishments in the United States, of which 72 percent have fewer than 20 employees and 99 percent have fewer than 500 employees.
(6)
During the past 7 years the Hollings Manufacturing Extension Partnership (MEP) Centers have worked closely with the Department of Defense to bolster the resilience of the defense industrial base supply chain by providing cybersecurity services to small manufacturers. The MEP Centers have worked with more than 26,000 small- and medium-sized manufacturers nationwide in fiscal year 2019 alone.
(7)
Hollings Manufacturing Extension Partnership Centers are located in all 50 States and provide a nationwide network that is—
(A)
raising the awareness of small manufacturers to cyber threats;
(B)
helping small manufacturers comply with new Department of Defense cybersecurity requirements; and
(C)
helping small manufacturers understand that if they do not comply with new Department of Defense cybersecurity requirements, then they risk losing their defense contracts.
(8)
The Hollings Manufacturing Extension Partnership Centers are well-positioned to aid small manufacturing companies in the defense supply chain in complying with cybersecurity requirements to protect controlled unclassified information relevant to defense manufacturing supply chains.