Title 15 › Chapter 7— NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY › § 278g–3e
Agency leaders must not buy, renew, or use Internet of Things (IoT) devices if their agency Chief Information Officer (CIO) finds the device stops the agency from meeting the required security standards and guidance. That rule applies even to contracts and subcontracts below the simplified acquisition threshold. The agency head can allow an exception if the CIO says it is needed for national security, for research, or if the device is protected by other effective security methods. The Office of Management and Budget (OMB) must create a standard process for CIOs to use when deciding these exceptions. Every 2 years during the 6-year period starting on December 4, 2020, the Comptroller General must report to the House Oversight Committee, the House Homeland Security Committee, and the Senate Homeland Security and Governmental Affairs Committee. The report must review how the OMB process is working, offer best practices for buying IoT devices, and list the number, types, and legal reasons for any waivers given in the prior 2-year period. Reports must be unclassified but may include a classified annex. The ban begins 2 years after December 4, 2020.
Full Legal Text
Commerce and Trade, Source: USLM XML via OLRC
Legislative History
Reference
Citation
15 U.S.C. § 278g–3e
Title 15, Commerce and Trade
Last Updated
Apr 3, 2026
Release point: 119-73not60