ConceptioArchiveCode of Federal Regulations (eCFR)
Code of Federal Regulations (eCFR)public full text

15 CFR Part 791 — Securing the Information and Communications Technology and Services Supply Chain

Office of the Federal Register (NARA) · Code of Federal Regulations (eCFR, Office of the Federal Register)
Code of Federal Regulations (eCFR) · Legal · License: Public Domain
Open Source ↗
bureauofindustryandsecuritycommercedepartmentofcommerceforeigntrade
united states, us regulation, us federal regulation, code of federal regulations, cfr, federal regulation, 15, 791, part 791, 15 cfr 791, 15 cfr part 791, commerce, and, foreign, trade, bureau of industry and security, department of commerce, information and communications technology and services regulations

PART 791—SECURING THE INFORMATION AND COMMUNICATIONS TECHNOLOGY AND SERVICES SUPPLY CHAIN Authority: 50 U.S.C. 1701 et seq.; et seq.; Source: 86 FR 4923, Jan. 19, 2021, unless otherwise noted. Redesignated at 89 FR 58265, July 18, 2024. Editorial Note: Nomenclature changes to part 791 appear at 89 FR 96892, Dec. 6, 2024. Subpart A—General § 791.1 Purpose. (a) This part sets forth the procedures by which the Secretary may: (1) Determine whether any acquisition, importation, transfer, installation, dealing in, or use of any information and communications technology or service, including but not limited to connected software applications, (ICTS Transaction) that has been designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of foreign adversaries poses certain undue or unacceptable risks as identified in the Executive Order 13873. For purposes of these regulations, the Secretary will consider information and communications technology and services (ICTS) to be designed, developed, manufactured, or supplied by a person owned by, controlled by, or subject to the jurisdiction of a foreign adversary where such a person operates, manages, maintains, repairs, updates, or services the ICTS; (2) Issue a determination to prohibit an ICTS Transaction; (3) Direct the timing and manner of the cessation of the ICTS Transaction; (4) Consider factors that may mitigate the risks posed by the ICTS Transaction. (b) The Secretary will evaluate ICTS Transactions under this rule, which include, but are not limited to, classes of transactions, on a case-by-case basis. The Secretary, in consultation with appropriate agency heads specified in Executive Order 13873 and other relevant governmental bodies, as appropriate, shall make an Initial Determination as to whether to prohibit a given ICTS Transaction or propose mitigation measures, by which the ICTS Transaction may be permitted. Parties may submit information in response to theInitial Determination, including a response to the Initial Determination and any supporting materials and/or proposed measures to remediate or mitigate the risks identified in the Initial Determination as posed by the ICTS Transaction at issue. Upon consideration of the parties' submissions, the Secretary will issue a Final Determination prohibiting the transaction, not prohibiting the transaction, or permitting the transaction subject to the adoption of measures determined by the Secretary to sufficiently mitigate the risks associated with the ICTS Transaction. The Secretary shall also engage in coordination and information sharing, as appropriate, with international partners on the application of this part. [88 FR 39357, June 16, 2023, as amended at 89 FR 96892, Dec. 6, 2024] § 791.2 Definitions. Appropriate agency heads Commercial item Connected software application Covered ICTS Transaction Dealing in Department End-point computing device Entity Executive Order Foreign adversary ICTS Transaction IEEPA et seq. Importation Information and communications technology or services ICTS Party or parties to a Transaction Person Person owned by, controlled by, or subject to the jurisdiction or direction of a foreign adversary (1) Any person, wherever located, who acts as an agent, representative, or employee, or any person who acts in any other capacity at the order, request, or under the direction or control, of a foreign adversary or of a person whose activities are directly or indirectly supervised, directed, controlled, financed, or subsidized in whole or in majority part by a foreign adversary; (2) Any person, wherever located, who is a citizen or resident of a foreign adversary or a country controlled by a foreign adversary, and is not a United States citizen or permanent resident of the United States; (3) Any corporation, partnership, association, or other organization with a principal place of business in, headquartered in, incorporated in, or otherwise organized under the laws of a foreign adversary or a country controlled by a foreign adversary; or (4) Any corporation, partnership, association, or other organization, wherever organized or doing business, that is owned or controlled by a foreign adversary, to include circumstances in which any person identified in paragraphs (1) through (3) of this definition possesses the power, direct or indirect, whether or not exercised, through the ownership of a majority or a dominant minority of the total outstanding voting interest in an entity, board representation, proxy voting, a special share, contractual arrangements, formal or informal arrangements to act in concert, or other means, to determine, direct, or decide important matters affecting an entity. Secretary Sensitive personal data (1) Personally-identifiable information, including: (i) Financial data that could be used to analyze or determine an individual's financial distress or hardship; (ii) The set of data in a consumer report, as defined under 15 U.S.C. 1681a, unless such data is obtained from a consumer reporting agency for one or more purposes identified in 15 U.S.C. 1681b(a); (iii) The set of data in an application for health insurance, long-term care insurance, professional liability insurance, mortgage insurance, or life insurance; (iv) Data relating to the physical, mental, or psychological health condition of an individual; (v) Non-public electronic communications, including email, messaging, or chat communications, between or among users of a U.S. business's products or services if a primary purpose of such product or service is to facilitate third-party user communications; (vi) Geolocation data collected using positioning systems, cell phone towers, or WiFi access points such as via a mobile application, vehicle GPS, other onboard mapping tool, or wearable electronic device; (vii) Biometric enrollment data including facial, voice, retina/iris, and palm/fingerprint templates; (viii) Data stored and processed for generating a Federal, State, Tribal, Territorial, or other government identification card; (ix) Data concerning U.S. Government personnel security clearance status; or (x) The set of data in an application for a U.S. Government personnel security clearance or an application for employment in a position of public trust; or (2) Genetic information, which includes the results of an individual's genetic tests, including any related genetic sequencing data, whenever such results, in isolation or in combination with previously released or publicly available data, constitute identifiable data. Such results shall not include data derived from databases maintained by the U.S. Government and routinely provided to private parties for purposes of research. For purposes of this paragraph, “genetic test” shall have the meaning provided in 42 U.S.C. 300gg-91(d)(17). Undue or unacceptable risk United States person Via the internet [86 FR 4923, Jan. 19, 2021, as amended at 88 FR 39357, June 16, 2023; 89 FR 96892, Dec. 6, 2024] § 791.3 Scope of Covered ICTS Transactions. (a) The Secretary may continue review under § 791.103(b) of this part for any ICTS Transaction that: (1) Is conducted by any person subject to the jurisdiction of the United States or involves property subject to the jurisdiction of the United States; (2) Involves any property in which any foreign country or a national thereof has any interest of any nature whatsoever, whether direct or indirect (including through an interest in a contract for the provision of the technology or service); (3) Is initiated, pending, or completed on or after January 19, 2021, regardless of when any contract applicable to the transaction is entered into, dated, or signed or when any license, permit, or authorization applicable to such transaction was granted. Any act or service with respect to an ICTS Transaction, such as execution of any provision of a managed services contract, installation of software updates, or the conducting of repairs, that occurs on or after January 19, 2021 may be deemed an ICTS Transaction within the scope of this part, even if the contract was initially entered into, or the activity commenced, prior to January 19, 2021; and (4) Involves ICTS and software, hardware, or any other product or service integral to one of the following: (i) Information and communications hardware and software, including (A) Wireless local area networks; (B) Mobile networks; (C) Satellite payloads; (D) Satellite operations and control; (E) internet-enabled sensors, cameras, and any other end-point surveillance or monitoring device, or any device that includes these components such as drones; (F) Routers, modems, and any other networking devices; (G) Cable access points; (H) Wireline access points; (I) Core networking systems; (J) Long- and short-haul networks; (ii) Data hosting, computing or storage, including software, hardware, or any other product or service integral to data hosting or computing services, including software-defined services such as virtual private servers, that uses, processes, or retains, or is expected to use, process, or retain, sensitive personal data of United States persons, including: (A) internet hosting services; (B) Cloud-based or distributed computing and data storage; (C) Managed services; and (D) Content delivery services; (iii) Connected software applications, including software designed primarily to enable connecting with and communicating via the internet, which is accessible through cable, telephone line, wireless, or satellite or other means, that is in use by United States persons at any point over the twelve (12) months preceding an ICTS Transaction, including connected software applications, such as but not limited to, desktop applications, mobile applications, gaming applications, and web-based applications; (iv) Critical infrastructure, including any subsectors of the chemical, commercial facilities, communications, critical manufacturing, dams, defense industrial base, emergency services, energy, financial services, food and agriculture, government services and facilities, health care and public health, information technology, nuclear reactors, materials, and waste, transportation systems, and water and wastewater systems sectors, and (v) Critical and emerging technologies, including advanced network sensing and signature management; advanced computing; artificial intelligence; clean energy generation and storage; data privacy, data security, and cybersecurity technologies; highly automated, autonomous, and uncrewed systems and robotics; integrated communication and networking technologies; positioning, navigation, and timing technologies; quantum information and enabling technologies; semiconductors and microelectronics; and biotechnology. (b) The Secretary will not continue review of an ICTS Transaction under § 791.103 if the Secretary finds that: (1) The ICTS Transaction involves the acquisition of ICTS items by a United States person as a party to a transaction authorized under a U.S. government-industrial security program; or (2) The Committee on Foreign Investment in the United States (CFIUS) is conducting a review, investigation, or assessment, or has concluded action on, the specific ICTS Transaction as a covered transaction under section 721(a)(4) of the Defense Production Act of 1950, as amended, and its implementing regulations. [86 FR 4923, Jan. 19, 2021, as amended at 88 FR 39358, June 16, 2023; 89 FR 96893, Dec. 6, 2024] § 791.4 Determination of foreign adversaries. (a) The Secretary has determined that the following foreign governments or foreign non-government persons have engaged in a long-term pattern or serious instances of conduct significantly adverse to the national security of the United States or security and safety of United States persons and, therefore, constitute foreign adversaries solely for the purposes of the Executive Order, this rule, and any subsequent rule: (1) The People's Republic of China, including the Hong Kong Special Administrative Region and the Macau Special Administrative Region (China); (2) Republic of Cuba (Cuba); (3) Islamic Republic of Iran (Iran); (4) Democratic People's Republic of Korea (North Korea); (5) Russian Federation (Russia); and (6) Venezuelan politician Nicolás Maduro (Maduro Regime). (b) The Secretary's determination of foreign adversaries is solely for the purposes of the Executive Order, this rule, and any subsequent rule promulgated pursuant to the Executive Order. Pursuant to the Secretary's discretion, the list of foreign adversaries will be revised as determined to be necessary. Such revisions will be effective immediately upon publication in the Federal Register (c) The Secretary's determination is based on multiple sources, including but not limited to: (1) National Security Strategy of the United States; (2) The Director of National Intelligence's Worldwide Threat Assessments of the U.S. Intelligence Community; (3) The National Cyber Strategy of the United States of America; and (4) Reports and assessments from the U.S. Intelligence Community, the U.S. Departments of Justice, State and Homeland Security, and other relevant sources. (d) The Secretary will periodically review this list in consultation with appropriate agency heads and may add to, subtract from, supplement, or otherwise amend this list. Any amendment to this list will apply to any ICTS Transaction that is initiated, pending, or completed on or after the date that the list is amended. [86 FR 4923, Jan. 19, 2021. Redesignated at 89 FR 58265, July 18, 2024, as amended at 89 FR 96893, Dec. 6, 2024] § 791.5 Effect on other laws. Nothing in this part shall be construed as altering or affecting any other authority, process, regulation, investigation, enforcement measure, or review provided by or established under any other provision of Federal law, including prohibitions under the National Defense Authorization Act of 2019, the Federal Acquisition Regulations, or IEEPA, or any other authority of the President or the Congress under the Constitution of the United States. § 791.6 Amendment, modification, or revocation. Except as otherwise provided by law, any determinations, prohibitions, or decisions issued under this part may be amended, modified, or revoked, in whole or in part, at any time. § 791.7 Public disclosure of records. Public requests for agency records related to this part will be processed in accordance with the Department of Commerce's Freedom of Information Act regulations, 15 CFR part 4, or other applicable law and regulation. Subpart B—Review of ICTS Transactions § 791.100 General. In implementing this part, the Secretary of Commerce may: (a) Consider any and all relevant information held by, or otherwise made available to, the Federal Government that is not otherwise restricted by law for use for this purpose, including: (1) Publicly available information; (2) Confidential business information, as defined in 19 CFR 201.6, or proprietary information; (3) Classified National Security Information, as defined in Executive Order 13526 (December 29, 2009) and its predecessor executive orders, and Controlled Unclassified Information, as defined in Executive Order 13556 (November 4, 2010); (4) Information obtained from state, local, tribal, or foreign governments or authorities; (5) Information obtained from parties to a transaction, including records related to such transaction that any party uses, processes, or retains, or would be expected to use, process, or retain, in their ordinary course of business for such a transaction; (6) Information obtained through the authority granted under sections 2(a) and (c) of the Executive Order and IEEPA, as set forth in § 791.101 of this part; (7) Information provided by any other U.S. Government national security body, in each case only to the extent necessary for national security purposes, and subject to applicable confidentiality and classification requirements, including the Committee for the Assessment of Foreign Participation in the United States Telecommunications Services Sector and the Federal Acquisitions Security Council and its designated information-sharing bodies; (8) Information or referrals provided by any other U.S. Government agency, department, or other regulatory body; and (9) Information provided voluntarily by private industry. (b) Consolidate the review of any ICTS Transactions with other transactions already under review where the Secretary determines that the transactions raise the same or similar issues, or that are otherwise properly consolidated; (c) Determine, in consultation with the appropriate agency heads, whether an ICTS Transaction involves ICTS designed, developed, manufactured, or supplied, by persons owned by, controlled by, or subject to the jurisdiction or direction of a foreign adversary, and in making a determination, the Department may consider the following: (1) Whether the person or its suppliers have headquarters, research, development, manufacturing, test, distribution, or service facilities, or other operations in a foreign country, including one controlled by, or subject to the jurisdiction of, a foreign adversary; (2) Ties between the person—including its officers, directors or similar officials, employees, consultants, or contractors—and a foreign adversary; (3) Laws and regulations of any foreign adversary in which the person is headquartered or conducts operations, including research and development, manufacturing, packaging, and distribution; and (4) Any other criteria that the Secretary deems appropriate; (d) Determine, in consultation with the appropriate agency heads, whether a Covered ICTS Transaction poses an undue or unacceptable risk, considering the following: (1) Threat assessments and reports prepared by the Director of National Intelligence pursuant to section 5(a) of the Executive Order; (2) Removal or exclusion orders issued by the Secretary of Homeland Security, the Secretary of Defense, or the Director of National Intelligence (or their designee) pursuant to recommendations of the Federal Acquisition Security Council, under 41 U.S.C. 1323; (3) Relevant provisions of the Defense Federal Acquisition Regulation (48 CFR ch. 2) and the Federal Acquisition Regulation (48 CFR ch. 1), and their respective supplements; (4) The written assessment produced pursuant to section 5(b) of the Executive Order, as well as the entities, hardware, software, and services that present vulnerabilities in the United States as determined by the Secretary of Homeland Security pursuant to that section; (5) Actual or potential threats to execution of a “National Critical Function” identified by the Department of Homeland Security Cybersecurity and Infrastructure Security Agency; (6) The nature, degree, and likelihood of consequence to the United States public and private sectors that could occur if ICTS vulnerabilities were to be exploited; and (7) Any other source or information that the Secretary deems appropriate; and (e) In the event the Secretary finds that unusual and extraordinary harm to the national security of the United States is likely to occur if all of the procedures specified herein are followed, deviate from these procedures in a manner tailored to protect against that harm. [86 FR 4923, Jan. 19, 2021. Redesignated at 89 FR 58265, July 18, 2024, as amended at 89 FR 96893, Dec. 6, 2024] § 791.101 Information to be furnished on demand. (a) Pursuant to the authority granted to the Secretary under sections 2(a), 2(b), and 2(c) of the Executive Order and IEEPA, the Secretary may require any person to furnish under oath, in the form of reports or otherwise, at any time as may be required by the Secretary, complete information relative to any act or transaction, subject to the provisions of this part. The Secretary may require that such reports include the production of any books, contracts, letters, papers, or other hard copy or electronic documents relating to any such act, transaction, or property, in the custody or control of the persons required to make such reports. Reports with respect to transactions may be required from before, during, or after such transactions. The Secretary may, through any person or agency, conduct investigations, hold hearings, administer oaths, examine witnesses, receive evidence, take depositions, and require by subpoena the attendance and testimony of witnesses and the production of any books, contracts, letters, papers, and other hard copy or documents relating to any matter under investigation, regardless of whether any report has been required or filed in connection therewith. (b) For purposes of paragraph (a) of this section, the term “document” includes any written, recorded, or graphic matter or other means of preserving thought or expression (including in electronic format), and all tangible things stored in any medium from which information can be processed, transcribed, or obtained directly or indirectly, including correspondence, memoranda, notes, messages, contemporaneous communications such as text and instant messages, letters, emails, spreadsheets, metadata, contracts, bulletins, diaries, chronological data, minutes, books, reports, examinations, charts, ledgers, books of account, invoices, air waybills, bills of lading, worksheets, receipts, printouts, papers, schedules, affidavits, presentations, transcripts, surveys, graphic representations of any kind, drawings, photographs, images, graphs, video or sound recordings, and motion pictures or other media such as film. (c) Persons providing documents to the Secretary pursuant to this section must produce documents in a format useable to the Department of Commerce, which may be detailed in the request for documents or otherwise agreed to by the parties. [86 FR 4923, Jan. 19, 2021. Redesignated at 89 FR 58265, July 18, 2024, as amended at 89 FR 96894, Dec. 6, 2024] § 791.102 Confidentiality of information. (a) Information or documentary materials, not otherwise publicly or commercially available, submitted or filed with the Secretary under this part will not be released publicly except to the extent required by law. (b) The Secretary may, subject to appropriate confidentiality and classification requirements, disclose information or documentary materials that are not otherwise publicly or commercially available and referenced in paragraph (a) of this section in the following circumstances: (1) Pursuant to any administrative or judicial proceeding; (2) Pursuant to an act of Congress; (3) Pursuant to a request from any duly authorized committee or subcommittee of Congress; (4) Pursuant to a request from any domestic governmental entity or any foreign governmental entity of a United States ally or partner, but only to the extent necessary for national security purposes; (5) Where the parties or a party to a transaction have consented, the information or documentary material that is not otherwise publicly or commercially available may be disclosed to third parties; (6) Where the Secretary has determined that at least one Covered ICTS Transaction related to the information or documents presents an undue or unacceptable risk, and disclosure to the public or to affected third parties is necessary to prevent or significantly reduce imminent harm to U.S. national security, or the security and safety of United States persons; and (7) Any other purpose authorized by law. (c) This section shall continue to apply with respect to information and documentary materials that are not otherwise publicly or commercially available and submitted to or obtained by the Secretary even after the Secretary issues a Final Determination pursuant to § 791.109. (d) The provisions of 18 U.S.C. 1905, relating to fines and imprisonment and other penalties, shall apply with respect to the disclosure of information or documentary material provided to the Secretary under these regulations. [86 FR 4923, Jan. 19, 2021. Redesignated and amended at 89 FR 58265, July 18, 2024; 89 FR 96894, Dec. 6, 2024] § 791.103 Review of ICTS Transactions. (a) After considering materials described in § 791.100(a), the Secretary may, at the Secretary's discretion, initiate a review of an ICTS Transaction. (b) As part of the review, the Secretary will assess whether the transaction: (1) Constitutes a Covered ICTS Transaction, as described in § 791.3; (2) Involves ICTS designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of a foreign adversary, as described in § 791.100(c); and (3) Poses an undue or unacceptable risk as described in §§ 791.100(d) and 791.103(c). (c) In assessing whether the Covered ICTS Transaction poses an undue or unacceptable risk, the Secretary may evaluate, among other relevant factors, the following criteria: (1) The nature and characteristics of the ICTS at issue in the Covered ICTS Transaction, including technical capabilities, applications, and market share considerations; (2) The nature and degree of the ownership, control, direction, or jurisdiction exercised by the foreign adversary or foreign adversary persons over the design, development, manufacture, or supply at issue in the Covered ICTS Transaction, to include: (i) The ownership, control, or management by persons that support a foreign adversary's military, intelligence, or proliferation activities; and (ii) The ownership, control, or management by persons involved in malicious cyber-enabled activities; (3) The statements and actions of the foreign adversary at issue in the Covered ICTS Transaction; (4) The statements and actions of the persons involved in the design, development, manufacture, or supply of the ICTS at issue in the Covered ICTS Transaction; (5) The statements and actions of the parties to the Covered ICTS Transaction; (6) Whether the Covered ICTS Transaction poses a discrete or persistent threat; (7) The nature and characteristics of the customer base, business relationships, and operating locations of the parties to the Covered ICTS Transaction; (8) Whether there is an ability to otherwise mitigate the risks posed by the Covered ICTS Transaction; (9) The severity of the harm posed by the Covered ICTS Transaction on at least one of the following: (i) Health, safety, and security; (ii) Critical infrastructure; (iii) Sensitive data; (iv) The economy; (v) Foreign policy; (vi) The natural environment; and (vii) National Essential Functions (as defined by Federal Continuity Directive-2 (FCD-2)); (10) The likelihood that the Covered ICTS Transaction will result in the threatened harm; and (11) For ICTS Transactions involving connected software applications: (i) the number and sensitivity of the users with access to the connected software application; (ii) the scope and sensitivity of any data collected by the connected software application; (iii) any use of the connected software application to conduct surveillance that enables espionage, including through a foreign adversary's access to sensitive or confidential government or business information, or sensitive personal data; (iv) whether there is regular, thorough, and reliable third-party auditing of the connected software application; and (v) the extent to which identified risks have been or can be mitigated using measures that can be verified by independent third parties. (d) If the Secretary finds that an ICTS Transaction does not meet the criteria of paragraph (b) of this section: (1) The transaction shall no longer be under review; and (2) Future review of the transaction shall not be precluded, where additional information becomes available to the Secretary. [89 FR 96894, Dec. 6, 2024] § 791.104 First interagency notification. (a) If the Secretary assesses that an ICTS Transaction meets the criteria under § 791.103(b), the Secretary shall memorialize that assessment, provide the assessment to the appropriate agency heads, and offer the appropriate agency heads twenty-one (21) days to comment in writing on the Secretary's assessment. (b) If the Secretary does not receive written comments on the assessment from an appropriate agency head within twenty-one (21) days of notification, the Secretary may presume that agency has no comments. (c) The Secretary may, at the Secretary's discretion, modify or revise the assessment based on comments received from the appropriate agency heads. The Secretary retains discretion to make an Initial Determination, as provided in § 791.105, regardless of the comments received. [89 FR 96895, Dec. 6, 2024] § 791.105 Initial Determination. (a) If, after notifying the appropriate agency heads as required by § 791.104 and considering any comments received, the Secretary determines that the Covered ICTS Transaction does not meet the criteria set forth in § 791.103: (1) The transaction shall no longer be under review; and (2) Future review of the transaction shall not be precluded, where additional information becomes available to the Secretary. (b) If, after notifying the appropriate agency heads as required by § 791.104 and considering any comments received, the Secretary determines that the Covered ICTS Transaction meets the criteria set forth in § 791.103, the Secretary shall: (1) Make a written Initial Determination, which shall be dated and signed by the Secretary, that: (i) Explains why the ICTS Transaction meets the criteria set forth in § 791.103; (ii) Sets forth whether the Secretary proposes to prohibit the Covered ICTS Transaction or to impose mitigation measures, by which the Covered ICTS Transaction may be permitted; and (iii) Provides information regarding the factual basis supporting the decision that is set forth pursuant to subparagraph (ii) above; (2) Provide at least twenty-one (21) calendar days' notice to the appropriate agency heads of the proposed Initial Determination prior to taking any action under 791.105(b)(3); and (3) Notify a party or the parties to the Covered ICTS Transaction by: (i) Serving a copy of the Initial Determination to the identified parties to the Covered ICTS Transaction when the Covered ICTS Transaction under review consists of a single transaction or a set of transactions between a limited number of parties (for example, the sale of ICTS by a company with a foreign nexus to an identified United States person); or (ii) Serving a copy of the Initial Determination to the person whose ICTS the Secretary determines constitutes the Covered ICTS Transactions under review when the number of U.S. parties or users acquiring, importing, transferring, installing, dealing in, or using the ICTS is unknown or unidentified, or notice to such U.S. parties or users is not feasible or appropriate (for example, when individual consumers purchase the ICTS through an online service or at a retail location). (c) Notwithstanding the fact that the Initial Determination to prohibit or propose mitigation measures on an ICTS Transaction may, in whole or in part, rely upon classified national security information, or sensitive but unclassified information, the Initial Determination will contain no classified national security information, nor reference thereto, and, at the Secretary's discretion, may not contain controlled unclassified information. (d) Notwithstanding paragraph (b)(3) of this section, the Secretary may, at the Secretary's discretion, determine to publish any notice of an Initial Determination in the Federal Register [89 FR 96895, Dec. 6, 2024] § 791.106 Recordkeeping requirement. Upon notification that an ICTS Transaction is under review, such as, though not limited to, through a demand for information or documents related to an ICTS Transaction under § 791.101 or a notification that an Initial Determination concerning an ICTS Transaction has been made, a notified person must immediately take steps to retain any and all records relating to such Transaction and must retain such records for no less than ten (10) years following a Final Determination made under § 791.109 or as otherwise indicated in the Final Determination. If a notified person receives no notification that an Initial Determination concerning an ICTS Transaction has been made within ten (10) years of notification that an ICTS Transaction is under review, then the recordkeeping obligation will extend for ten (10) years following the initial notification of an ICTS Transaction review unless the notified person is informed otherwise by the Secretary. [89 FR 96895, Dec. 6, 2024] § 791.107 Procedures governing response and mitigation. Within 30 days of service of the Secretary's Initial Determination pursuant to § 791.105, a party to a transaction may respond to the Initial Determination or assert that the circumstances resulting in the Initial Determination no longer apply, and thus seek to have the Initial Determination rescinded or mitigated pursuant to the following administrative procedures: (a) A party may submit arguments or evidence that the party believes establishes that insufficient basis exists for the Initial Determination, including any prohibition of the ICTS Transaction; (b) A party may propose remedial steps on the party's part, such as corporate reorganization, disgorgement of control of the foreign adversary, engagement of a compliance monitor, or similar steps, which the party believes would negate the basis for the Initial Determination; (c) All submissions under this section must be made in writing. (1) The Secretary may, for good cause, extend the time to provide a written submission pursuant to this section. (2) Any extensions granted pursuant to this section shall not exceed thirty (30) days. (3) A written submission to the Secretary pursuant to this section may not exceed fifty (50) pages without approval from the Secretary prior to the expiration of time for a party's response. (4) A written submission to the Secretary may include business confidential information. Any business confidential information must be clearly and specifically demarcated. Publicly available information should not be marked business confidential. (d) A party responding to the Secretary's Initial Determination may request a meeting with the Department, and the Department may, at its discretion, agree or decline to conduct such meetings prior to making a Final Determination pursuant to § 791.109; (e) This rule creates no right in any person to obtain access to information in the possession of the U.S. Government that was considered in making the Initial Determination, to include classified national security information or sensitive but unclassified information; and (f) If the Department receives no response from the parties within 30 days after service of the Initial Determination to the parties, the Secretary may issue a Final Determination without the need to engage in the consultation process provided in section 791.108 of this rule. [86 FR 4923, Jan. 19, 2021. Redesignated and amended at 89 FR 58265, July 18, 2024; 89 FR 96895, Dec. 6, 2024] § 791.108 Interagency consultation on the Final Determination. (a) Upon receipt of any submission by a party to a transaction under § 791.107, the Secretary shall consider whether and how the information provided—including proposed mitigation measures—affects an Initial Determination. (b) After considering the effect of any submission by a party to a transaction under § 791.107 consistent with paragraph (a) of this section, the Secretary shall provide notice in writing of the proposed Final Determination and consult with and seek concurrence from all appropriate agency heads prior to issuing a Final Determination as to whether the Covered ICTS Transaction shall be prohibited, not prohibited, or permitted pursuant to the adoption of negotiated mitigation measures. (c) If the appropriate agency heads under paragraph (b) of this section concur, the Secretary shall issue a Final Determination pursuant to § 791.109. If an appropriate agency head provides no response within fourteen (14) days of the agency receiving the notice in writing of the proposed Final Determination, the Secretary may presume concurrence. If an agency objects to the Final Determination, such objection must be submitted by the agency's Deputy Secretary or equivalent or higher level within the 14 days. [89 FR 96896, Dec. 6, 2024] § 791.109 Final Determination. (a) For each Covered ICTS Transaction for which the Secretary issues an Initial Determination, the Secretary shall issue a Final Determination as to whether the Covered ICTS Transaction is: (1) Prohibited; (2) Not prohibited; or (3) Permitted, at the Secretary's discretion, pursuant to the adoption of mitigation measures. (b) Unless the Secretary, at the Secretary's sole discretion, determines in writing that additional time is necessary, the Secretary shall issue the Final Determination within 180 days of serving the Initial Determination pursuant to § 791.105(b)(3). (c) If the Secretary determines that a Covered ICTS Transaction is prohibited, the Secretary shall direct the means that the Secretary assesses to be necessary to address the undue or unacceptable risk posed by the Covered ICTS Transaction. (d) The Final Determination shall: (1) Be written, signed, and dated; (2) Describe the Secretary's determination; (3) Be unclassified and contain no reference to classified national security information; (4) Consider and address any information received from a party or parties to the transaction; (5) Direct, if applicable, the timing and manner of the cessation of the Covered ICTS Transaction; (6) Explain, if applicable, that a Final Determination that the Covered ICTS Transaction is not prohibited does not preclude the future review of transactions related in any way to the Covered ICTS Transaction; (7) Include, if applicable, a description of the mitigation measures agreed upon by the party or parties to the transaction and the Secretary; (8) State the penalties a party will face if it fails to comply fully with any mitigation agreement or direction, including violations of IEEPA, or other violations of law; and (9) Include, if applicable, how the Department may transition a mitigation agreement to a prohibition should a party or parties fail to comply with any mitigation agreement or obligations, or violate IEEPA or other law. (e) The written, signed, and dated Final Determination shall be sent to: (1) The party or parties to the transaction that are identified in the Final Determination via registered U.S. mail and electronic mail; and (2) The appropriate agency heads. (f) The Secretary shall publish a notice of any Final Determination to prohibit an ICTS Transaction in the Federal Register. Federal Register. Federal Register [89 FR 96896, Dec. 6, 2024] § 791.110 Classified national security information. In any review of a determination made under this part, if the determination was based on classified national security information, such information may be submitted to the reviewing court ex parte in camera. Subpart C—Enforcement § 791.200 Penalties. (a) Prohibited activities. (2) No person shall aid, abet, counsel, command, induce, facilitate, procure, or otherwise engage in conduct with knowledge that such conduct is prohibited by, or contrary to a Final Determination issued under this part, unless authorized by the Secretary. (3) No person shall be a party to an ICTS Transaction in a manner that is contrary to any direction, regulation, or condition published under this part. (4) No person shall aid, abet, counsel, command, induce, facilitate, procure, or otherwise engage in conduct with knowledge that such conduct is contrary to the terms of a mitigation agreement under this part. (5) Any ICTS Transaction that has the purpose of evading or avoiding, causes a violation of, or attempts to violate, any of the prohibitions set forth in this section is prohibited. (6) Any conspiracy formed to violate any of the prohibitions set forth in this section is prohibited. (7) Any approval, financing, facilitation, or guarantee by a United States person, wherever located, of an ICTS Transaction by a foreign person where the ICTS Transaction by that foreign person would be prohibited by this order if performed by a United States person or within the United States, is prohibited. (8) No person may, whether directly or indirectly through any other person, make any false or misleading representation, statement, or certification, or falsify or conceal any material fact, to the Department: (i) In the course of an ICTS Transaction review, in order to secure a benefit or avoid a prohibition, including in proposing and agreeing to mitigation measures; or (ii) In connection with the preparation, submission, issuance, use, or maintenance of any report filed or required to be filed pursuant to this part. (9) Additional requirements: (i) For purposes of paragraph (a)(8), any representation, statement, or certification made by any person shall be deemed to be continuing in effect until the person notifies the Department in accordance with paragraph (a)(9)(ii). (ii) Any person who makes a representation, statement, or certification to the Department relating to any ICTS Transaction review shall notify the Department, in writing, of any change of any material fact or intention from that previously represented, stated, or certified, immediately upon receipt of any information that would lead a reasonably prudent person to know that a change of material fact or intention had occurred or may occur in the future. (b) Maximum penalties Civil penalty. (i) Notice of the penalty, including a written explanation of the penalized conduct specifying the laws and regulations allegedly violated and the amount of the proposed penalty, and notifying the recipient of a right to make a written petition within 30 days as to why a penalty should not be imposed, shall be served on the person. (ii) The Secretary shall review any presentation and issue a final administrative decision within 30 days of receipt of the petition. (2) Criminal penalty. (3) Any civil penalties authorized in this section may be recovered in a civil action brought by the United States in U.S. district court. (c) Adjustments to penalty amounts. (2) The criminal penalties provided in IEEPA are subject to adjustment pursuant to 18 U.S.C. 3571. (d) Available penalties. [89 FR 96896, Dec. 6, 2024] Subpart D—ICTS Supply Chain: Connected Vehicles Source: 90 FR 5414, Jan. 16, 2025, unless otherwise noted. § 791.300 Purpose and scope. The inclusion in connected vehicles of certain ICTS designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of certain foreign adversaries poses undue or unacceptable risks to U.S. national security. To address these undue or unacceptable risks, it is the purpose of this subpart to: (a) Prohibit ICTS transactions that involve certain software and hardware that are designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of the People's Republic of China (PRC) or the Russian Federation (Russia), as defined in § 791.4, and that directly enable connected vehicle Automated Driving Systems (ADS) or Vehicle Connectivity Systems (VCS), as defined in this subpart; (b) Implement Declarations of Conformity to provide a mechanism for connected vehicle manufacturers and VCS hardware importers to communicate to BIS that they have conducted supply chain due diligence, and to confirm that no prohibited transactions, as defined in this subpart, have knowingly occurred; (c) Provide for the issuance of general authorizations for certain transactions that would otherwise be prohibited by this subpart, but where certain factors described in the authorizations reduce the risk to an acceptable level; (d) Provide a mechanism to apply for specific authorizations for certain transactions that would otherwise be prohibited by this subpart, where the undue or unacceptable risks can be reasonably mitigated, based on criteria and conditions that are specifically constructed for each applicant; and (e) Incentivize connected vehicle manufacturers, VCS hardware importers, and related suppliers to adopt and enhance measures to help secure the U.S. ICTS supply chain for connected vehicles. § 791.301 Definitions. The following definitions apply only to this subpart. For additional definitions applicable to all of part 791, see Automated Driving System Completed connected vehicle Connected vehicle Connected vehicle manufacturer (1) Manufactures or assembles completed connected vehicles in the United States for sale in the United States; (2) Imports completed connected vehicles for sale in the United States; and/or (3) Integrates ADS software on a completed connected vehicle for sale in the United States. A connected vehicle manufacturer may also be a VCS hardware importer, as defined herein, if VCS hardware has already been installed in a connected vehicle when the connected vehicle manufacturer imports it. Covered software Declarant FCC ID Number (1) Grantee code; and (2) Product code. Foreign interest, Hardware Bill of Materials (HBOM) Import importing imported. Item Knowingly Model year Person owned by, controlled by, or subject to the jurisdiction or direction of a foreign adversary (1) Any person, wherever located, who acts as an agent, representative, or employee, or any person who acts in any other capacity at the order, request, or under the direction or control, of a foreign adversary or of a person whose activities are directly or indirectly supervised, directed, controlled, financed, or subsidized in whole or in majority part by a foreign adversary; (2) Any person, wherever located, who is a citizen or resident of a foreign adversary or a country controlled by a foreign adversary, and is not a United States citizen or permanent resident of the United States; (3) Any corporation, partnership, association, or other organization with a principal place of business in, headquartered in, incorporated in, or otherwise organized under the laws of a foreign adversary or a country controlled by a foreign adversary; or (4) Any corporation, partnership, association, or other organization, wherever organized or doing business, that is owned or controlled by a foreign adversary, to include circumstances in which any person identified in paragraphs (1) through (3) of this definition possesses the power, direct or indirect, whether or not exercised, through the ownership of a majority or a dominant minority of the total outstanding voting interest in an entity, board representation, proxy voting, a special share, contractual arrangements, formal or informal arrangements to act in concert, or other means, to determine, direct, or decide important matters affecting an entity. Prohibited transactions Sale sell selling. Software Bill of Materials (SBOM) United States Vehicle Connectivity System (VCS) (1) enables the transmission, receipt, conversion, or processing of automotive sensing ( e.g., (2) enables the transmission, receipt, conversion, or processing of ultrawideband communications to directly enable physical vehicle access ( e.g., (3) enables the receipt, conversion or processing of unidirectional radio frequency bands ( e.g., (4) supplies or manages power for the VCS. VCS hardware e.g., VCS hardware importer (1) VCS hardware for further manufacturing, incorporation, or integration into a completed connected vehicle that is intended to be sold or operated in the United States; or (2) VCS hardware that has already been installed, incorporated, or integrated into a connected vehicle, or a subassembly thereof, that is intended to be sold as part of a completed connected vehicle in the United States. § 791.302 Prohibited VCS hardware transactions. (a) VCS hardware importers are prohibited from knowingly importing into the United States VCS hardware that is designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of the PRC or Russia. (b) In the context of this subpart, VCS hardware will not be considered to be designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of the PRC or Russia, based solely on the country of citizenship of one or more natural persons who are employed by, contracted by, or otherwise similarly engaged in such actions through the entity designing, developing, manufacturing, or supplying the hardware. § 791.303 Prohibited covered software transactions. (a) Connected vehicle manufacturers are prohibited from knowingly importing into the United States completed connected vehicles that incorporate covered software that is designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of the PRC or Russia. (b) Connected vehicle manufacturers are prohibited from knowingly selling within the United States completed connected vehicles that incorporate covered software that is designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of the PRC or Russia. (c) In the context of this subpart, covered software will not be considered to be designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of the PRC or Russia, based solely on the country of citizenship of one or more natural persons who are employed by, contracted by, or otherwise similarly engaged in such actions through the entity designing, developing, manufacturing, or supplying the software. § 791.304 Related prohibited transactions. Connected vehicle manufacturers who are owned by, controlled by, or subject to the jurisdiction or direction of the PRC or Russia, are prohibited from knowingly selling in the United States completed connected vehicles that incorporate VCS hardware or covered software, regardless of whether such VCS hardware or covered software is designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of the PRC or Russia. These connected vehicle manufacturers are also prohibited from offering commercial services in the United States that utilize completed connected vehicles that incorporate ADS. § 791.305 Declaration of Conformity. (a) Requirements VCS hardware: (i) The name and address of the VCS hardware importer, to include identifying information for an individual point of contact (including name, email address, and phone number); (ii) If known, the FCC ID Number associated with the VCS hardware and, if applicable, of the subcomponents contained therein; (iii) If known, the make and model of the connected vehicle(s) for which the VCS hardware is intended, or already integrated; (iv) A certification that the VCS hardware described in the Declaration of Conformity was not designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of the PRC or Russia; (v) A certification that the declarant has conducted due diligence (with or without the use of third-party assessments) to inform the above certification, and the declarant or a delegated third party maintains documentation (either through an HBOM or otherwise) and third-party assessments (as applicable) in support of the above certification, which can be made available upon request by BIS; (vi) Identification as to who maintains the documentation and third-party assessments (as applicable) as certified above; (vii) A certification that the declarant has taken all possible measures, either contractually or otherwise, to ensure any necessary documentation and assessments from suppliers will be furnished to BIS upon request either by the declarant, or, in cases including confidential business information, directly by the supplier; and (viii) If applicable, an indication as to whether the submission is an update to a prior Declaration of Conformity, and if so, the date of the last submission. (2) Covered software: (i) The name and address of the connected vehicle manufacturer, to include information identifying an individual point of contact (including name, email address, and phone number); (ii) The make, model, trim, and Vehicle Identification Number (VIN) series applicable to the completed connected vehicles that incorporate the covered software; (iii) A certification that the covered software described in the Declaration of Conformity was not designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of the PRC or Russia; (iv) A certification that the declarant has conducted due diligence (with or without the use of third-party assessments) to inform the above certification, and the declarant or a delegated third party maintains documentation (either through an SBOM or otherwise) and third-party assessments (as applicable) that are sufficient to identify, at minimum, the author name, timestamp, component name, and supplier name of all proprietary additions to the development of the covered software, which can be made available upon request by BIS; (v) Identification as to who maintains the documentation and third-party assessments (as applicable) as certified above; (vi) A certification that the declarant has taken all possible measures, either contractually or otherwise, to ensure any necessary documentation and assessments from suppliers will be furnished to BIS upon request either by the declarant, or, in cases including confidential business information, directly by the supplier; and (vii) If applicable, an indication as to whether the submission is an update to a prior Declaration of Conformity and the date of the last submission. (b) Certification. (1) For purposes of this section, a duly authorized designee is: (i) In the case of a partnership, any general partner thereof; (ii) In the case of a corporation, the chief executive officer, or any officer with the authority to bind the corporation; (iii) An employee with authority to make certifications on behalf of the company as designated by a person in (i) or (ii); and (iv) In the case of an entity lacking partners and officers, any individual manager, or designated agent who has been explicitly authorized by the board of directors or equivalent to sign contracts and make legally binding agreements on behalf of the entity. (c) Additional information. (d) Reliance on third-party assessments. (e) Material changes. (1) The discovery, by the declarant, of an omission, inaccuracy, or error in the information provided to BIS in a prior Declaration of Conformity that could reasonably mislead as to the true source of VCS hardware or covered software in question. (2) Covered software updates alone do not constitute a material change unless an additional condition above is true. (f) Change in circumstance. (g) Deadline to submit Declarations of Conformity. (1) Connected vehicle manufacturers shall submit a Declaration of Conformity at least 60 days prior to the first import or first sale of each model year of completed connected vehicle that incorporates covered software. Declarants may submit a single Declaration of Conformity for all connected vehicles that use the same covered software, grouped by make, model, and VIN series. (2) VCS hardware importers shall submit a Declaration of Conformity at least 60 days prior to the first import of VCS hardware for each model year for units associated with a vehicle model year, or calendar year for units not associated with a vehicle model year. VCS hardware importers may submit a single Declaration of Conformity detailing all VCS hardware models that will be imported in the model year or calendar year. (3) Connected vehicle manufacturers and VCS hardware importers must notify BIS of any material change to the information conveyed in a previously submitted Declaration of Conformity by submitting a revised Declaration of Conformity within 60 days following the discovery of such change. A declarant's obligation to inform BIS of material changes to the information ceases 10 years after submission of the original Declaration of Conformity for that model year or calendar year. (h) Annual updates to Declarations of Conformity. (1) Where there are no material changes to the covered software for a subsequent model year of completed connected vehicles, the connected vehicle manufacturer may submit a confirmation no later than one year after the previous submission, certifying that the prior information remains accurate, and that associates the new relevant model year of vehicles to an existing Declaration of Conformity. (2) Where there are no material changes to the VCS hardware for a subsequent model year of completed connected vehicles (if known) or calendar year, the VCS hardware importer may submit a confirmation no later than one year after the previous submission, certifying that the prior information remains accurate, and that associates the new relevant model year of vehicles (if known) to an existing Declaration of Conformity. (i) Submission instructions. https://www.bis.gov/OICTS. (j) Verification. (k) Connected vehicle introduced by means of false information in the Declaration of Conformity. (l) Exemptions. § 791.306 General authorizations. (a) Overview. (b) General course of procedure. https://www.bis.gov/OICTS Federal Register (c) Relationship with specific authorizations. (d) Instructions. (e) Change in circumstance. (1) If the connected vehicle manufacturer or VCS hardware importer determines that articles subject to a general authorization have been used outside the conditions of the general authorization, it must, within 30 days of such a determination, cease any prohibited conduct, conduct an internal inquiry, and submit to BIS a report identifying any prohibited transactions, the number of connected vehicles or VCS hardware units implicated, and proposed remedial measures. (2) [Reserved] (f) Verification. (g) Restrictions. (1) BIS has notified, either directly or through an advisory opinion, the VCS hardware importer or connected vehicle manufacturer is not eligible for a general authorization; or (2) The VCS hardware importer or connected vehicle manufacturer is owned by, controlled by, or subject to the jurisdiction or direction of the PRC or Russia. § 791.307 Specific authorizations. (a) Prohibited transactions authorized. (b) Policy. (c) Applications for specific authorizations. (1) The identity of the parties engaged in the transaction, including relevant corporate identifiers and information sufficient to identify the ultimate beneficial ownership of the transacting parties; (2) An overview of the VCS hardware or covered software that is designed, developed, manufactured, or supplied by a person owned by, controlled by, or subject to the jurisdiction or direction of the PRC or Russia, including persons responsible for assembling and packaging VCS hardware or covered software; (3) If known, the make, model, and trim of the connected vehicle(s) in which the VCS hardware or covered software will be integrated; (4) The intended function of the VCS hardware or covered software; (5) Documentation to support the information contained in the application, such as any ISO/SAE 21434 Threat Analysis and Risk Assessments (if available); (6) An assessment of the applicant's ability to limit PRC or Russian government access to, or influence over the design, development, manufacture, or supply of the VCS hardware or covered software; (7) Security standards used by the applicant with respect to the VCS hardware or covered software; and (8) Other actions and proposals such as technical controls ( e.g., e.g., (d) Application submission procedures and timing. https://www.bis.gov/OICTS. (e) Additional conditions. (f) Information to be supplied. (g) Review and decisions. (h) Processing period. (i) Scope. (i) Between the parties identified in the specific authorization; (ii) With respect to the otherwise prohibited transaction(s) described in the authorization; and (iii) If the conditions specified in the specific authorization are satisfied. The applicant must inform any other parties identified in the specific authorization of the authorization's scope and specific conditions. (2) As a condition for the issuance of any specific authorization, BIS may require the applicant to submit third-party assessments or SBOMs/HBOMs as may be prescribed in the specific authorization or otherwise communicated to the applicant by BIS. Reports should be sent in accordance with the instructions provided in the applicable specific authorization. (3) Any materially false or misleading representation in or otherwise associated with the application, or in any document submitted in connection with the application under this section, shall cause the specific authorization to be deemed void as of the date of issuance, and the applicant may incur penalties as specified in § 791.318. (j) Verification. (k) Effect of denial. (l) Effect of specific authorization. (2) No regulation, ruling, instruction, or authorization permits any prohibited transaction under this subpart unless the regulation, ruling, instruction or authorization is issued by BIS and specifically refers to this subpart. No regulation, ruling, instruction, or authorization referring to this subpart shall be deemed to permit any prohibited transaction prohibited by any provision of this subpart unless the regulation, ruling, instruction, or authorization specifically refers to such provision. Any specific authorization permitting any otherwise prohibited transaction has the effect of removing those prohibitions from the transaction, but only to the extent specifically stated by the terms of the specific authorization. Unless the specific authorization otherwise specifies, such an authorization does not create any right, duty, obligation, claim, or interest in, or with respect to, any property that would not otherwise exist under ordinary principles of law. (3) Nothing contained in this subpart shall be construed to supersede the requirements established under any other provision of law or to relieve a person from any requirement to obtain an authorization from another department or agency of the U.S. Government in compliance with applicable laws and regulations subject to the jurisdiction of that department or agency. (4) Specific authorizations will be approved for a duration of no less than one (1) model year or calendar year except as provided in § 791.307(m). (m) Exceptions. (1) 2027 model years that include covered software and are actively being sold or imported as of the effective date of this rule; (2) Covered software and VCS hardware supply chains that are affected by force majeure events; (3) As a result of a corporate merger, investment, acquisition, joint venture, or conversion of equity (such as from debt) that occurs during model year production; (4) As a result of the closure or relocation of facilities involved in the production of covered software or VCS hardware; and (5) Other instances as determined by BIS. (n) Records. (o) Amendment, modification, or rescission. § 791.308 Exemptions. (a) VCS hardware importers may engage in prohibited transactions described in § 791.302 without an authorization as required under §§ 791.306 and 791.307, and are exempt from submitting Declarations of Conformity with respect to all other transactions, as described in § 791.305 provided that: (1) For VCS hardware units not associated with a vehicle model year, the import of the VCS hardware occurs prior to January 1, 2029; or (2) The VCS hardware is associated with a vehicle model year prior to 2030, the VCS hardware is imported as part of a connected vehicle with a model year prior to 2030, or the VCS hardware is imported for purposes of repair or warranty for a connected vehicle with a model year prior to 2030. (b) Connected vehicle manufacturers may engage in prohibited transactions described in § 791.303 without authorization as required under § 791.306 or § 791.307 and are exempt from submitting Declarations of Conformity with respect to all other transactions, as described in § 791.305, provided that the completed connected vehicle that incorporates covered software described in § 791.303(a)(1) was manufactured prior to model year 2027. (c) Connected vehicle manufacturers who are owned by, controlled by, or subject to the jurisdiction or direction of the PRC or Russia may engage in prohibited transactions described in § 791.304 without authorization as required under § 791.306 or § 791.307, and are exempt from submitting Declarations of Conformity to all other transactions, provided that the completed connected vehicle that incorporates VCS hardware and/or covered software was manufactured prior to model year 2027. § 791.309 Appeals. (a) Scope. (1) Denial of an application for a specific authorization; (2) Suspension or revocation of an issued specific authorization; or (3) Determination of ineligibility for a general authorization. (b) Designated appeals reviewer and coordinator. (c) Appeals procedures Filing. (2) Content of appeal. (3) Request for informal hearing. (d) Informal hearing procedures Presentations. (2) Evidence. (3) Procedural questions. (4) Transcript. (5) Report. (e) Amicus filings. (f) Decisions. (g) Effect of appeal. § 791.310 Advisory opinions. (a) VCS hardware importers and connected vehicle manufacturers may request an advisory opinion from BIS to determine whether a prospective transaction is subject to a prohibition, or requirement under this subpart. The requestor must have a direct financial interest in the substance of the question(s) presented, and the submission must include the name of the parties to the transaction. (b) Requests for advisory opinions must be delivered to BIS as specified on its website, https://www.bis.gov/OICTS. (c) Persons submitting advisory opinion requests are encouraged to provide as much information as possible to assist BIS in making a determination, to include the following information: (1) The name, title, telephone, and email address of the submitter; (2) The submitter's complete address, comprised of street address, city, state, country, and postal code; (3) All available information identifying the parties to the prospective transaction; (4) Information regarding the VCS hardware and/or covered software and any descriptive literature, brochures, technical specifications, or papers that provide sufficient technical detail to enable BIS to verify whether the prospective transaction would constitute a prohibited transaction as defined in this subpart; (5) For connected vehicle manufacturers: the make, model, and trim level, or other identifying information of the completed connected vehicle; (6) For VCS hardware importers: the identification of the system; and, if known, the make, model, and trim of the group of completed connected vehicles for which the equipment is intended; and (7) Any other information that the submitter believes to be material to the prospective transaction. (d) BIS may consider third-party materials on a case-by-case basis as part of its review of an advisory opinion request. Each person that submits an advisory opinion request or information in support of another party's advisory opinion request shall provide any additional information or documents that BIS may thereafter request in its review of the matter. (e) BIS shall issue an advisory opinion within 60 days of the request unless it notifies the requester within that 60-day period that more time is required. Failure or delays by the applicant in submitting additional information requested by BIS may delay or prevent BIS's ability to issue an advisory opinion. (f) Each advisory opinion can be relied upon by the requesting party or parties to the extent the disclosures made pursuant to this subpart were accurate and complete and to the extent the disclosures continue to reflect circumstances accurately and completely after the date of the issuance of the advisory opinion. An advisory opinion will not restrict enforcement actions by any agency other than BIS. It will not affect a requesting party's obligations to any other agency or under any statutory or regulatory provision other than those specifically discussed in the advisory opinion. (g) BIS may publish on its website an advisory opinion that may be of broad interest to the public, with redactions where necessary to protect Confidential Business Information. (h) BIS may, at its sole discretion, decline to issue an advisory opinion within 60 days after receipt of the request. § 791.311 “Is-informed” notices. (a) BIS may inform VCS hardware importers or connected vehicle manufacturers either individually by specific notice or, for larger groups, through a separate notice published in the Federal Register , (b) Specific notice that a specific authorization is required may be given only by, or at the direction of, the Under Secretary or a BIS official designated by the Under Secretary. § 791.312 Recordkeeping. (a) Except as otherwise provided herein, or through subsequent communication with BIS, VCS hardware importers, connected vehicle manufacturers, and/or third-party assessors (if applicable) shall keep all primary business records related to the execution of each transaction for which a Declaration of Conformity, general authorization, or specific authorization would be required under § 791.305, § 791.306, or § 791.307. Primary business records include contracts, import records, commercial invoices, bills of sale, corporate policy documentation, and reports produced by third parties created for the purposes of compliance with this rule. Regardless of whether these transactions are effectuated pursuant to a general authorization, specific authorization, or otherwise, such records shall be available for examination for at least 10 years after the date of such transactions. (b) Third-party assessors are required to maintain all records relating to third-party verification or assessment of a U.S. person's compliance with this rule. § 791.313 Reports to be furnished on demand. (a) VCS hardware importers and connected vehicle manufacturers must furnish, under oath, in the form of reports or as otherwise specified by BIS, and at any time as may be required by BIS, complete information regarding any transaction involving the import of VCS hardware or the import or sale of completed connected vehicles incorporating covered software. This requirement applies regardless of whether such transaction is affected pursuant to a general or specific authorization or otherwise, subject to the provisions of this subpart. BIS may require that such reports include the production of any books, contracts, letters, papers, or other hard copy or electronic documents relating to any transactions, in the custody or control of the persons required to make such reports. Reports being submitted to BIS pursuant to this section must be retained for a period of 10 years, as specified in § 791.312. (b) BIS may, through any person or agency, conduct investigations, hold hearings, administer oaths, examine witnesses, receive evidence, take depositions, and require by subpoena the attendance and testimony of witnesses and the production of any books, contracts, letters, papers, and other hard copy or electronic documents relating to any matter under investigation, regardless of whether any report has been required or filed in connection therewith. (c) Persons providing records to BIS pursuant to this section shall follow the electronic filing instructions on BIS's website, https://www.bis.gov/OICTS. § 791.314 Confidential business information. (a) Confidential business information. (b) Submission procedures. et seq. (c) Confidentiality of information. § 791.315 Third-party verification and assessments. (a) Overview. (b) Third-party assessors. (1) The third-party assessor cannot be a person owned by, controlled by, or subject to the jurisdiction or direction of the PRC or Russia. (2) In determining the reasonableness of an entity's reliance on a third-party assessment, BIS will consider the independence of the third-party, including any financial incentives between the third-party and the entity. (c) Scope. (1) identify and examine the VCS hardware importer or connected vehicle manufacturer's VCS hardware and covered software supply chains in relation to the prohibitions in this subpart; (2) examine compliance relating to each Declaration of Conformity, general authorization, or specific authorization pursuant to which an entity is conducting transactions; (3) use a reliable methodology to conduct the third-party verification; and (4) acknowledge that the assessment may be used by the U.S. government to verify compliance. (d) Assessment. (1) identify the suppliers of each relevant component and describe the nature of any foreign interest; (2) describe the methodology undertaken, including the policies and other documents reviewed, personnel interviewed, and any facilities, equipment, or systems examined; (3) describe the effectiveness of the VCS hardware importer or connected vehicle manufacturer's corporate policies related to compliance with this rule; (4) for VCS hardware importers or connected vehicle manufacturers conducting transactions under the auspices of a general authorization or specific authorization, describe any vulnerabilities or deficiencies in the implementation of the authorization; and (5) recommend any improvements or changes to policies, practices, or other aspects to maintain compliance with this subpart, as applicable to each transaction. (e) Recordkeeping. § 791.316 Finding of violation. (a) When issued. (i) Determines that there has occurred a violation of any provision of this subpart, or a violation of the provisions of any exemption, general authorization, specific authorization, regulation, order, directive, instruction, or prohibition issued by or pursuant to the direction or authorization of the Secretary pursuant to this subpart or otherwise under IEEPA; (ii) Considers it important to document the occurrence of a violation; and (iii) Concludes that an administrative response is warranted but that a civil monetary penalty is not the most appropriate response. (2) An initial finding of violation shall be in writing and may be issued whether or not another agency has taken any action with respect to the matter. (b) Response Right to respond. (2) Deadline for response; default determination. (i) Computation of time for response. (ii) Extensions of time for response. (3) Form and method of response. (4) Information that should be included in response. (c) Determination Determination that a finding of violation is warranted. (2) Determination that a finding of violation is not warranted. § 791.317 Pre-penalty notice; settlement. (a) When required. (b) Response Right to respond. (2) Deadline for response. (i) Computation of time for response. (ii) Extensions of time for response. (3) Form and method of response. (4) Information that should be included in response. (c) Representation. (d) Settlement. § 791.318 Penalties. (a) Section 206 of the International Emergency Economic Powers Act (50 U.S.C. 1705) (IEEPA) is applicable to violations of the provisions of any general authorization, specific authorization, regulation, order, directive, instruction, or prohibition issued by or pursuant to the direction or authorization of the Secretary of Commerce (Secretary) pursuant to this subpart or otherwise under IEEPA. (1) A civil penalty not to exceed the amount set forth in section 206 of IEEPA may be imposed on any person who violates, attempts to violate, conspires to violate, or causes a violation of any exemption, general authorization, specific authorization, regulation, order, directive, instruction, or prohibition issued under this subpart. (2) A person who willfully commits, willfully attempts to commit, willfully conspires to commit, or aids or abets in the commission of a violation of any exemption, general authorization, specific authorization, regulation, order, directive, instruction, or prohibition issued under this subpart is subject to criminal penalties and may, upon conviction, be fined not more than $1,000,000, or if a natural person, be imprisoned for not more than 20 years, or both. (b) The civil penalties provided in IEEPA are subject to adjustment pursuant to the Federal Civil Penalties Inflation Adjustment Act of 1990 (Pub. L. 101-410, as amended, 28 U.S.C. 2461 note). (c) The criminal penalties provided in IEEPA are subject to adjustment pursuant to 18 U.S.C. 3571. (d) Pursuant to 18 U.S.C. 1001, whoever, in any matter within the jurisdiction of the executive, legislative, or judicial branch of the U.S. Government, knowingly and willfully falsifies, conceals, or covers up by any trick, scheme, or device a material fact; or makes any materially false, fictitious, or fraudulent statement or representation; or makes or uses any false writing or document knowing the same to contain any materially false, fictitious, or fraudulent statement or entry shall be fined under title 18, United States Code, imprisoned, or both. (e) Violations of this subpart may also be subject to other applicable laws and therefore may be subject to additional penalties not specified in this section. § 791.319 Penalty imposition. (a) If, after considering any written response to the pre-penalty notice and any relevant facts, including voluntary disclosure of a violation, BIS determines that there was a violation by the alleged violator named in the pre-penalty notice and that a civil monetary penalty is appropriate, BIS may issue a penalty notice to the violator containing a determination of the violation and the imposition of the monetary penalty. (b) The issuance of the penalty notice shall constitute final agency action. The violator may seek judicial review of that final agency action in Federal district court. § 791.320 Administrative collection; referral to United States Department of Justice. In the event that the violator does not pay the penalty imposed pursuant to this subpart or make payment arrangements acceptable to BIS, the matter may be referred for administrative collection measures by the United States Department of the Treasury or to the United States Department of Justice for appropriate action to recover the penalty in a civil suit in a Federal district court. § 791.321 Severability. If any provision of this subpart is held to be invalid or unenforceable by its terms, or as applied to any person or circumstance, or stayed pending further agency action or judicial review, the provision is to be construed so as to continue to give the maximum effect to the provision permitted by law, unless such holding will be one of utter invalidity or unenforceability, in which event the provision will be severable from this part and will not affect the remainder thereof.

Related documents

Record · ID 505968 · SHA-256 7d46e50810e55a4c
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.