Us Code § 2662 - Reporting on penetrations of networks of contractors and subcontractors

Full text of Us Code United States Code § 2662 — Reporting on penetrations of networks of contractors and subcontractors, with citation guidance and answers to common questions.

§ 2662. Reporting on penetrations of networks of contractors and subcontractors

(a) Procedures for reporting penetrations

The Administrator shall establish procedures that require each contractor and subcontractor to report to the Chief Information Officer when a covered network of the contractor or subcontractor that meets the criteria established pursuant to subsection (b) is successfully penetrated.

(b) Establishment of criteria for covered networks

(1) In general

The Administrator shall, in consultation with the officials specified in paragraph (2), establish criteria for covered networks to be subject to the procedures for reporting penetrations under subsection (a).

(2) Officials specified

The officials specified in this paragraph are the following officials of the Administration:

(A) The Deputy Administrator for Defense Programs.

(B) The Associate Administrator for Acquisition and Project Management.

(C) The Chief Information Officer.

(D) Any other official of the Administration the Administrator considers necessary.

(c) Procedure requirements

(1) Rapid reporting

(A) In general

The procedures established pursuant to subsection (a) shall require each contractor or subcontractor to submit to the Chief Information Officer a report on each successful penetration of a covered network of the contractor or subcontractor that meets the criteria established pursuant to subsection (b) not later than 60 days after the discovery of the successful penetration.

(B) Elements

Subject to subparagraph (C), each report required by subparagraph (A) with respect to a successful penetration of a covered network of a contractor or subcontractor shall include the following:

(i) A description of the technique or method used in such penetration.

(ii) A sample of the malicious software, if discovered and isolated by the contractor or subcontractor, involved in such penetration.

(iii) A summary of information created by or for the Administration in connection with any program of the Administration that has been potentially compromised as a result of such penetration.

(C) Avoidance of delays in reporting

If a contractor or subcontractor is not able to obtain all of the information required by subparagraph (B) to be included in a report required by subparagraph (A) by the date that is 60 days after the discovery of a successful penetration of a covered network of the contractor or subcontractor, the contractor or subcontractor shall—

(i) include in the report all information available as of that date; and

(ii) provide to the Chief Information Officer the additional information required by subparagraph (B) as the information becomes available.

(2) Access to equipment and information by Administration personnel

Concurrent with the establishment of the procedures pursuant to subsection (a), the Administrator shall establish procedures to be used if information owned by the Administration was in use during or at risk as a result of the successful penetration of a covered network—

(A) in order to—

(i) in the case of a penetration of a covered network of a management and operating contractor, enhance the access of personnel of the Administration to Government-owned equipment and information; and

(ii) in the case of a penetration of a covered network of a contractor or subcontractor that is not a management and operating contractor, facilitate the access of personnel of the Administration to the equipment and information of the contractor or subcontractor; and


(B) which shall—

(i) include mechanisms for personnel of the Administration to, upon request, obtain access to equipment or information of a contractor or subcontractor necessary to conduct forensic analysis in addition to any analysis conducted by the contractor or subcontractor;

(ii) provide that a contractor or subcontractor is only required to provide access to equipment or information as described in clause (i) to determine whether information created by or for the Administration in connection with any program of the Administration was successfully exfiltrated from a network of the contractor or subcontractor and, if so, what information was exfiltrated; and

(iii) provide for the reasonable protection of trade secrets, commercial or financial information, and information that can be used to identify a specific person.

(3) Dissemination of information

The procedures established pursuant to subsection (a) shall allow for limiting the dissemination of information obtained or derived through such procedures so that such information may be disseminated only to entities—

(A) with missions that may be affected by such information;

(B) that may be called upon to assist in the diagnosis, detection, or mitigation of cyber incidents;

(C) that conduct counterintelligence or law enforcement investigations; or

(D) for national security purposes, including cyber situational awareness and defense purposes.

(d) Definitions

In this section:

(1) Chief Information Officer

The term "Chief Information Officer" means the Associate Administrator for Information Management and Chief Information Officer of the Administration.

(2) Contractor

The term "contractor" means a private entity that has entered into a contract or contractual action of any kind with the Administration to furnish supplies, equipment, materials, or services of any kind.

(3) Covered network

The term "covered network" includes any network or information system that accesses, receives, or stores—

(A) classified information; or

(B) sensitive unclassified information germane to any program of the Administration, as determined by the Administrator.

(4) Subcontractor

The term "subcontractor" means a private entity that has entered into a contract or contractual action with a contractor or another subcontractor to furnish supplies, equipment, materials, or services of any kind in connection with another contract in support of any program of the Administration.

(Pub. L. 107–314, div. D, title XLV, §4511, as added Pub. L. 116–283, div. C, title XXXI, §3131(a), Jan. 1, 2021, 134 Stat. 4383.)

Part B—Classified Information

About This Section

50 U.S.C. § 2662 is part of Title 50 of the United States Code. The United States Code is the official codification of federal statutes maintained by the Office of the Law Revision Counsel of the U.S. House of Representatives. Congress amends the Code through new public laws, which are eventually incorporated into the relevant title.

This section may be cited in legal writing as 50 U.S.C. § 2662. For the most current official text, including any recent amendments, use the official source links below. Do not rely on this page as the sole authority for legal citation or litigation.

How to Read This Statute

Statutes are organized by title, chapter, section, and subsection. Pay attention to words like "shall," "may," "and," and "or," because they determine whether a requirement is mandatory or permissive and whether multiple conditions must all be met. Historical notes and amendments often appear at the end of a section.

Using This Page

This page is intended for research and educational use. Lawyers, students, journalists, and compliance professionals can use it as a starting point, but should always verify the current text through an official government source before relying on it for legal advice, filings, or compliance decisions.

Sources

Source: official Us Code text · Last verified 2026-08-27

Frequently Asked Questions About Us Code § 2662

What does United States Code § 2662 cover?

Section 2662 ("Reporting on penetrations of networks of contractors and subcontractors") is part of the United States Code, the codified statutory law of Us Code. It sets out the legal rule or procedure described in the text above. Statutes are amended regularly, so always verify against the official source.

How do I cite Us Code § 2662?

A common citation format is "United States Code § 2662" (Us Code). Legal writing may require the code abbreviation, section number, and year or edition. Match the style required by your court, professor, or publisher.

Is this the official text of Us Code law?

No. This page is for research and education and may not include the most recent amendments. For official current law, check the Us Code official source linked on this page or consult a licensed Us Code attorney.

How does Us Code § 2662 apply to my situation?

Statutes are interpreted in context, and application depends on your specific facts. Only a licensed attorney in Us Code can advise on how this section applies to you. Contact your state or local bar association for a referral.

Sources & Verification

Not legal advice. Verify against the official source and consult a licensed attorney in Us Code.