Not later than 2 years after the date of enactment of this Act, the Comptroller General of the United States shall report to Congress on the actions the Federal Government has taken to support the cybersecurity of commercial satellite systems, which shall include information on—
(1)
the extent to which Federal agencies are reliant on commercial satellite systems owned wholly or in part or controlled by foreign entities, and how Federal agencies mitigate associated cybersecurity risks; and
(2)
the extent to which Federal agencies are reliant on commercial satellite systems with physical structures, such as satellite ground control systems, in foreign countries, and how Federal agencies mitigate associated cybersecurity risks.