Files
Fabio 76b8ec33a7 Legal corpus: the complete U.S. Code (59,740 sections, all 53 titles)
Ingested titles 12–51 and 54 from OLRC USLM XML @119-100 (the whole Code
now, uniform edition; Title 53 is reserved/empty). LegalText 11,221 ->
59,740; repo total 105,704 records. Deterministic (byte-identical rerun,
verified on Title 42's 8,356 sections); make check green. make
legal-us-code default now covers every title.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-06 10:51:44 -04:00

4.3 KiB
Raw Permalink Blame History

type, title, description, jurisdiction, corpus, kind, title_number, title_name, chapter_number, chapter_name, section, citation, status, release_point, release_date, source, source_url, source_identifier, source_file, source_hash, raw_snapshot_hash, text_hash, retrieved_at, confidence, tags
type title description jurisdiction corpus kind title_number title_name chapter_number chapter_name section citation status release_point release_date source source_url source_identifier source_file source_hash raw_snapshot_hash text_hash retrieved_at confidence tags
LegalText 50 U.S.C. § 3242 Annual reports on certain cyber vulnerabilities procured by intelligence community and foreign commercial providers of cyber vulnerabilities us united_states_code code_section 50 WAR AND NATIONAL DEFENSE 44 NATIONAL SECURITY 3242 50 U.S.C. § 3242 current 119-100 2026-06-26 official https://uscode.house.gov/download/releasepoints/us/pl/119/100/xml_usc50@119-100.zip /us/usc/t50/s3242 data/legal/raw/us/code/title-50/usc50.xml 22e38204db10f9ba501e9935c19c1be49fa530e33d31547695368be50b21caa4 708c288b5448617cab7b03b8011860274671c9aec56686858b910a06948cd7ac 56c1fe1866c9bed4edb2b642e70c6fa768cac174a273fb1351c4e9a336c5e723 2026-07-04 official
legal
us-code

50 U.S.C. § 3242 - Annual reports on certain cyber vulnerabilities procured by intelligence community and foreign commercial providers of cyber vulnerabilities

Text

(a) Annual reports On an annual basis through 2026, the Director of the Central Intelligence Agency and the Director of the National Security Agency, in coordination with the Director of National Intelligence, shall jointly submit to the congressional intelligence committees a report containing information on foreign commercial providers and the cyber vulnerabilities procured by the intelligence community through foreign commercial providers.

(b) Elements Each report under subsection (a) shall include, with respect to the period covered by the report, the following:

(1) A description of each cyber vulnerability procured through a foreign commercial provider, including—

(A) a description of the vulnerability;

(B) the date of the procurement;

(C) whether the procurement consisted of only that vulnerability or included other vulnerabilities;

(D) the cost of the procurement;

(E) the identity of the commercial provider and, if the commercial provider was not the original supplier of the vulnerability, a description of the original supplier;

(F) the country of origin of the vulnerability; and

(G) an assessment of the ability of the intelligence community to use the vulnerability, including whether such use will be operational or for research and development, and the approximate timeline for such use.

(2) An assessment of foreign commercial providers that—

(A) pose a significant threat to the national security of the United States; or

(B) have provided cyber vulnerabilities to any foreign government that—

(i) has used the cyber vulnerabilities to target United States persons, the United States Government, journalists, or dissidents; or

(ii) has an established pattern or practice of violating human rights or suppressing dissent.

(3) An assessment of whether the intelligence community has conducted business with the foreign commercial providers identified under paragraph (2) during the 5-year period preceding the date of the report.

(c) Form Each report under subsection (a) may be submitted in classified form.

(d) Definitions In this section:

(1) Commercial provider The term “commercial provider” means any person that sells, or acts as a broker, for a cyber vulnerability.

(2) Cyber vulnerability The term “cyber vulnerability” means any tool, exploit, vulnerability, or code that is intended to compromise a device, network, or system, including such a tool, exploit, vulnerability, or code procured by the intelligence community for purposes of research and development.

(July 26, 1947, ch. 343, title XI, § 1112, as added Pub. L. 117103, div. X, title VIII, § 822(a), Mar. 15, 2022, 136 Stat. 1020.)

Notes

Statutory Notes and Related Subsidiaries

First ReportPub. L. 117103, div. X, title VIII, § 822(b), Mar. 15, 2022, 136 Stat. 1021, provided that: “Not later than 90 days after the date of the enactment of this Act [Mar. 15, 2022], the Director of the Central Intelligence Agency and the Director of the National Security Agency shall jointly submit the first report required under section 1112 of the National Security Act of 1947 [50 U.S.C. 3242], as added by subsection (a).”