(a)
Process for covered voting systems—
(1)
In general— The Director of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security and the Election Assistance Commission (in consultation with the Technical Guidelines Development Committee and the Standards Board of the Commission), shall jointly establish a voluntary process to test for and monitor covered voting systems for cybersecurity vulnerabilities. Such process shall include the following:
(A)
Mitigation strategies and other remedies.
(B)
Notice to the Commission and appropriate entities of the results of testing conducted pursuant to such process.
(2)
Implementation— The Director shall implement the process established under paragraph (1) at the request of the Commission.
(b)
Labeling for voting systems— The Commission (in consultation with the Technical Guidelines Development Committee and the Standards Board of the Commission), shall establish a process to provide for the deployment of appropriate labeling available through the website of the Commission to indicate that covered voting systems passed the most recent cybersecurity testing pursuant to the process established under subsection (a).
(c)
Rules of construction— The process established under subsection (a), including the results of any testing carried out pursuant to this section, shall not affect—
(1)
the certification status of equipment used in the administration of an election for Federal office under the Help America Vote Act of 2002; or
(2)
the authority of the Commission to so certify such equipment under such Act.
(d)
Definition— In this section, the term covered voting systems means equipment used in the administration of an election for Federal office that is certified in accordance with versions of Voluntary Voting System Guidelines under the Help America Vote Act of 2002 under which such equipment is not required to be tested for cybersecurity vulnerabilities.