---
kind: "section"
citation: "6 U.S.C. § 1523"
title: "6"
title_heading: "Domestic Security"
number: "1523"
heading: "Federal cybersecurity requirements"
release: "119-102"
date: "2026-07-12"
url: "https://uscodex.org/usc/6/1523"
units:
  - "Chapter 6 — Cybersecurity"
  - "Subchapter II — Federal Cybersecurity Enhancement"
---

# §1523. Federal cybersecurity requirements

- (a) **Implementation of Federal cybersecurity standards—** Consistent with [section 3553 of title 44](/usc/44/3553.md), the [Secretary](/usc/6/1521.md?p=8), in consultation with the [Director](/usc/6/1521.md?p=5), shall exercise the authority to issue binding operational directives to assist the [Director](/usc/6/1521.md?p=5) in ensuring timely [agency](/usc/6/1501.md?p=1) adoption of and compliance with policies and standards promulgated under [section 11331 of title 40](/usc/40/11331.md)[^1] for securing [agency information systems](/usc/6/1521.md?p=2).
- (b) **Cybersecurity requirements at agencies—**
  - (1) **In general—** Consistent with policies, standards, guidelines, and directives on information security under subchapter II of [chapter 35](/usc/44/chch35.md) of title 44 and the standards and guidelines promulgated under [section 11331 of title 40](/usc/40/11331.md) and except as provided in [paragraph (2)](#b-2), not later than 1 year after December 18, 2015, the head of each [agency](/usc/6/1501.md?p=1) shall—
    - (A) identify sensitive and mission critical data stored by the [agency](/usc/6/1501.md?p=1) consistent with the inventory required under the first [subsection (c)](#c) (relating to the inventory of major [information systems](/usc/6/1501.md?p=9)) and the second [subsection (c)](#c) (relating to the inventory of [information systems](/usc/6/1501.md?p=9)) of [section 3505 of title 44](/usc/44/3505.md);
    - (B) assess access controls to the data described in [subparagraph (A)](#b-1-A), the need for readily accessible storage of the data, and individuals’ need to access the data;
    - (C) encrypt or otherwise render indecipherable to unauthorized users the data described in [subparagraph (A)](#b-1-A) that is stored on or transiting [agency information systems](/usc/6/1521.md?p=2);
    - (D) implement a single sign-on trusted identity platform for individuals accessing each public website of the [agency](/usc/6/1501.md?p=1) that requires user authentication, as developed by the [Administrator](/usc/6/701.md?p=1) of General Services in collaboration with the [Secretary](/usc/6/1521.md?p=8); and
    - (E) implement identity management consistent with [section 7464 of title 15](/usc/15/7464.md), including multi-factor authentication, for—
      - (i) remote access to an [agency information system](/usc/6/1521.md?p=2); and
      - (ii) each user account with elevated privileges on an [agency information system](/usc/6/1521.md?p=2).
  - (2) **Exception—** The requirements under [paragraph (1)](#b-1) shall not apply to an [agency information system](/usc/6/1521.md?p=2) for which—
    - (A) the head of the [agency](/usc/6/1501.md?p=1) has personally certified to the [Director](/usc/6/1521.md?p=5) with particularity that—
      - (i) operational requirements articulated in the certification and related to the [agency information system](/usc/6/1521.md?p=2) would make it excessively burdensome to implement the cybersecurity requirement;
      - (ii) the cybersecurity requirement is not necessary to secure the [agency information system](/usc/6/1521.md?p=2) or [agency](/usc/6/1501.md?p=1) information stored on or transiting it; and
      - (iii) the [agency](/usc/6/1501.md?p=1) has taken all necessary steps to secure the [agency information system](/usc/6/1521.md?p=2) and [agency](/usc/6/1501.md?p=1) information stored on or transiting it; and
    - (B) the head of the [agency](/usc/6/1501.md?p=1) or the designee of the head of the [agency](/usc/6/1501.md?p=1) has submitted the certification described in [subparagraph (A)](#b-2-A) to the [appropriate congressional committees](/usc/6/1521.md?p=3) and the [agency](/usc/6/1501.md?p=1)’s authorizing committees.
  - (3) **Construction—** Nothing in this section shall be construed to alter the authority of the [Secretary](/usc/6/1521.md?p=8), the [Director](/usc/6/1521.md?p=5), or the [Director](/usc/6/1521.md?p=5) of the National Institute of Standards and Technology in implementing subchapter II of chapter 35 of title 44. Nothing in this section shall be construed to affect the National Institute of Standards and Technology standards process or the requirement under section 3553(a)(4) of such title or to discourage continued improvements and advancements in the technology, standards, policies, and guidelines used to promote Federal information security.
- (c) **Exception—** The requirements under this section shall not apply to the [Department](/usc/6/101.md?p=5) of Defense, a [national security system](/usc/6/1521.md?p=7), or an element of the [intelligence community](/usc/6/1521.md?p=6).

## Footnotes

[^1]: See References in Text note below.

## Source credit

(Pub. L. 114–113, div. N, title II, § 225, Dec. 18, 2015, 129 Stat. 2967.)

## Notes

### Editorial Notes

### References in Text

The text of section 11331 of title 40, referred to in subsec. (a), was generally amended by Pub. L. 117–167, div. B, title II, § 10246(f), Aug. 9, 2022, 136 Stat. 1492, so as to provide for the prescription by the Secretary of Commerce of standards and guidelines pertaining to Federal information systems.
