---
kind: "section"
citation: "42 U.S.C. § 18935"
title: "42"
title_heading: "The Public Health and Welfare"
number: "18935"
heading: "Dissemination of resources for research institutions"
release: "119-102"
date: "2026-07-12"
url: "https://uscodex.org/usc/42/18935"
units:
  - "Chapter 163 — Research and Development, Competition, and Innovation"
  - "Subchapter II — National Institute of Standards and Technology for the Future"
  - "Part A — Measurement Research"
---

# §18935. Dissemination of resources for research institutions

- (a) **Dissemination of resources for research institutions—**
  - (1) **In general—** Not later than one year after August 9, 2022, the [Director](/usc/42/18921.md?p=1) shall, using the authorities of the [Director](/usc/42/18921.md?p=1) under subsections (c)(15) and (e)(1)(A)(ix) of [section 272 of title 15](/usc/15/272.md), disseminate and make publicly available tailored resources to help qualifying institutions identify, assess, manage, and reduce their cybersecurity risk related to conducting research.
  - (2) **Requirements—** The [Director](/usc/42/18921.md?p=1) shall ensure that the resources disseminated pursuant to [paragraph (1)](#a-1)—
    - (A) are generally applicable and usable by a wide range of qualifying institutions;
    - (B) vary with the nature and size of the qualifying institutions, and the nature and sensitivity of the data collected or stored on the information systems or devices of the qualifying institutions;
    - (C) include elements that promote awareness of simple, basic controls, a workplace cybersecurity culture, and third-party stakeholder relationships, to assist qualifying institutions in mitigating common cybersecurity risks;
    - (D) include case studies, examples, and scenarios of practical application;
    - (E) are outcomes-based and can be implemented using a variety of technologies that are commercial and off-the-shelf; and
    - (F) to the extent practicable, are based on international [technical standards](/usc/42/18901.md?p=29).
  - (3) **National cybersecurity awareness and education program—** The [Director](/usc/42/18921.md?p=1) shall ensure that the resources disseminated under [paragraph (1)](#a-1) are consistent with the efforts of the [Director](/usc/42/18921.md?p=1) under [section 7443 of title 15](/usc/15/7443.md).
  - (4) **Updates—** The [Director](/usc/42/18921.md?p=1) shall review periodically and update the resources under [paragraph (1)](#a-1) as the [Director](/usc/42/18921.md?p=1) determines appropriate.
  - (5) **Voluntary resources—** The use of the resources disseminated under [paragraph (1)](#a-1) shall be considered voluntary.
- (b) **Other Federal cybersecurity requirements—** Nothing in this section may be construed to supersede, alter, or otherwise affect any cybersecurity requirements applicable to Federal [agencies](/usc/42/8262.md?p=1).
- (c) **Definitions—** In this section:
  - (1) **Qualifying institutions—** The term “qualifying institutions” means institutions of higher education that are awarded in excess of $50,000,000 per year in total Federal research funding.
  - (2) **Resources—** The term “resources” means guidelines, tools, best [practices](/usc/42/17061.md?p=19), [technical standards](/usc/42/18901.md?p=29), methodologies, and other ways of providing information.

## Source credit

(Pub. L. 117–167, div. B, title II, § 10229, Aug. 9, 2022, 136 Stat. 1481.)
