Skip to main content
Rule2023-12925

Securing the Information and Communications Technology and Services Supply Chain; Connected Software Applications

Primary source

Metadata and text below are from the Federal Register, a public-domain U.S. government work. Always verify the official published version before relying on it for any legal matter.

Published
June 16, 2023
Effective
July 17, 2023

Issuing agencies

Commerce Department

Abstract

On November 26, 2021, the Department of Commerce (Department) published a Notice of Proposed Rulemaking (NPRM) proposing to amend Department regulations, "Securing the Information and Communications Technology Supply Chain," to implement provisions of Executive Order 14034, "Protecting Americans' Sensitive Data from Foreign Adversaries" (E.O. 14034). This final rule responds to, and adopts changes based on, the comments received to the NPRM. Consistent with the factors enumerated in E.O. 14034, the final rule amends the Securing the Information and Communications Technology Supply Chain regulations to provide additional criteria that the Secretary may consider when determining whether ICTS transactions involving connected software applications present undue or unacceptable risks (as those terms are defined in the regulations). The final rule also adds definitions for "end-point computing devices" and "via the internet" for the purposes of this rule to clarify the definition of connected software applications provided in E.O. 14034.

Indexed from Federal Register on June 16, 2023.

This is legal information, not legal advice. Laws vary by jurisdiction and change frequently. Always verify current law with official sources and consult a licensed attorney in your jurisdiction for advice on your specific situation.