---
kind: "section"
citation: "42 U.S.C. § 18933"
title: "42"
title_heading: "The Public Health and Welfare"
number: "18933"
heading: "Software security and authentication"
release: "119-102"
date: "2026-07-12"
url: "https://uscodex.org/usc/42/18933"
units:
  - "Chapter 163 — Research and Development, Competition, and Innovation"
  - "Subchapter II — National Institute of Standards and Technology for the Future"
  - "Part A — Measurement Research"
---

# §18933. Software security and authentication

- (a) **Vulnerabilities in open source software—** The [Director](/usc/42/18921.md?p=1) shall assign severity metrics to identified vulnerabilities with open source software and produce voluntary guidance to assist the entities that maintain open source software repositories to discover and mitigate vulnerabilities.
- (b) **Artificial intelligence-enabled defenses—** The [Director](/usc/42/18921.md?p=1) shall carry out research and testing to improve the effectiveness of [artificial intelligence](/usc/42/18901.md?p=1)-enabled cybersecurity, including by generating optimized data sets to train [artificial intelligence](/usc/42/18901.md?p=1) defense systems and evaluating the performance of varying network architectures at strengthening network security.
- (c) **Authentication of Institute software—** The [Director](/usc/42/18921.md?p=1) shall ensure all software released by the [Institute](/usc/42/18921.md?p=4) is digitally signed and maintained to enable stakeholders to verify its authenticity and integrity upon installation and execution.
- (d) **Assistance to Inspectors General—** Subject to available funding, the [Director](/usc/42/18921.md?p=1) shall provide technical assistance to improve the education and training of individual Federal [agency](/usc/42/8262.md?p=1) Inspectors General and staff who are responsible for the annual independent evaluation they are required to perform of the information security program and [practices](/usc/42/17061.md?p=19) of Federal [agencies](/usc/42/8262.md?p=1) under [section 3555 of title 44](/usc/44/3555.md).
- (e) **Software supply chain security practices—**
  - (1) **In general—** The [Director](/usc/42/18921.md?p=1) shall, in coordination with industry, academia, and other Federal [agencies](/usc/42/8262.md?p=1), as appropriate, develop a set of security outcomes and [practices](/usc/42/17061.md?p=19), including security controls, control enhancements, supplemental guidance, or other supporting information to enable software developers and operators to identify, assess, and manage cybersecurity risks over the full lifecycle of software products.
  - (2) **Outreach—** The [Director](/usc/42/18921.md?p=1) shall conduct outreach and coordination activities to share technical expertise with Federal [agencies](/usc/42/8262.md?p=1), relevant industry stakeholders, and standards development organizations, as appropriate, to encourage the voluntary adoption of the software lifecycle security [practices](/usc/42/17061.md?p=19) by Federal [agencies](/usc/42/8262.md?p=1) and industry stakeholders.

## Source credit

(Pub. L. 117–167, div. B, title II, § 10224, Aug. 9, 2022, 136 Stat. 1478.)
