---
kind: "section"
citation: "22 U.S.C. § 9229"
title: "22"
title_heading: "Foreign Relations and Intercourse"
number: "9229"
heading: "Report on and imposition of sanctions to address persons responsible for knowingly engaging in significant activities undermining cybersecurity"
release: "119-102"
date: "2026-07-12"
url: "https://uscodex.org/usc/22/9229"
units:
  - "Chapter 99 — North Korea Sanctions and Policy Enhancement"
  - "Subchapter II — Sanctions Against North Korean Proliferation, Human Rights Abuses, and Illicit Activities"
---

# §9229. Report on and imposition of sanctions to address persons responsible for knowingly engaging in significant activities undermining cybersecurity

- (a) **Report required—**
  - (1) **In general—** The President shall submit to the [appropriate congressional committees](/usc/22/9202.md?p=3) a report that describes [significant activities undermining cybersecurity](/usc/22/9202.md?p=14) aimed against the United States Government or any [United States person](/usc/22/9202.md?p=16) and conducted by the [Government of North Korea](/usc/22/9202.md?p=6), or a person owned or controlled, directly or indirectly, by the [Government of North Korea](/usc/22/9202.md?p=6) or any person acting for or on behalf of that Government.
  - (2) **Information—** The report required under [paragraph (1)](#a-1) shall include—
    - (A) the identity and nationality of persons that have knowingly engaged in, directed, or provided material [support](/usc/22/7432.md?p=12) to conduct [significant activities undermining cybersecurity](/usc/22/9202.md?p=14) described in [paragraph (1)](#a-1);
    - (B) a description of the conduct engaged in by each person identified;
    - (C) an assessment of the extent to which a foreign government has provided material [support](/usc/22/7432.md?p=12) to the [Government of North Korea](/usc/22/9202.md?p=6) or any person acting for or on behalf of that Government to conduct [significant activities undermining cybersecurity](/usc/22/9202.md?p=14); and
    - (D) a United States strategy to counter [North Korea](/usc/22/9202.md?p=11)’s efforts to conduct [significant activities undermining cybersecurity](/usc/22/9202.md?p=14) against the United States, that includes efforts to engage foreign governments to halt the capability of the [Government of North Korea](/usc/22/9202.md?p=6) and persons acting for or on behalf of that Government to conduct [significant activities undermining cybersecurity](/usc/22/9202.md?p=14).
  - (3) **Submission and form—**
    - (A) **Submission—** The report required under [paragraph (1)](#a-1) shall be submitted not later than 90 days after October 25, 2018, and every 180 days thereafter for 5 years.
    - (B) **Form—** The report required under [paragraph (1)](#a-1) shall be submitted in an unclassified form, but may include a classified annex.
- (b) **Designation of persons—** The President shall designate under [section 9214(a) of this title](/usc/22/9214.md?p=a) any person identified in the report required under [subsection (a)(1)](#a-1) that knowingly engages in [significant activities undermining cybersecurity](/usc/22/9202.md?p=14) through the use of computer networks or systems against [foreign persons](/usc/22/9202.md?p=5), governments, or other entities on behalf of the [Government of North Korea](/usc/22/9202.md?p=6).

## Source credit

(Pub. L. 114–122, title II, § 209, Feb. 18, 2016, 130 Stat. 110; Pub. L. 115–272, title III, § 303(c)(1), Oct. 25, 2018, 132 Stat. 4157.)

## Notes

### Editorial Notes

### Amendments

2018—Subsec. (a)(3)(A). Pub. L. 115–272 substituted “not later than 90 days after October 25, 2018, and every 180 days thereafter for 5 years” for “not later than 90 days after February 18, 2016, and every 180 days thereafter”.

### Executive Documents

### Delegation of Functions

For delegation of certain functions of President under this section, see Memorandum of President of the United States, May 18, 2016, 81 F.R. 37479, set out as a note under section 9212 of this title.
