Us Code § 9229 - Report on and imposition of sanctions to address persons responsible for knowingly engaging in significant activities undermining cybersecurity

Full text of Us Code United States Code § 9229 — Report on and imposition of sanctions to address persons responsible for knowingly engaging in significant activities undermining cybersecurity, with citation guidance and answers to common questions.

§ 9229. Report on and imposition of sanctions to address persons responsible for knowingly engaging in significant activities undermining cybersecurity

(a) Report required

(1) In general

The President shall submit to the appropriate congressional committees a report that describes significant activities undermining cybersecurity aimed against the United States Government or any United States person and conducted by the Government of North Korea, or a person owned or controlled, directly or indirectly, by the Government of North Korea or any person acting for or on behalf of that Government.

(2) Information

The report required under paragraph (1) shall include—

(A) the identity and nationality of persons that have knowingly engaged in, directed, or provided material support to conduct significant activities undermining cybersecurity described in paragraph (1);

(B) a description of the conduct engaged in by each person identified;

(C) an assessment of the extent to which a foreign government has provided material support to the Government of North Korea or any person acting for or on behalf of that Government to conduct significant activities undermining cybersecurity; and

(D) a United States strategy to counter North Korea's efforts to conduct significant activities undermining cybersecurity against the United States, that includes efforts to engage foreign governments to halt the capability of the Government of North Korea and persons acting for or on behalf of that Government to conduct significant activities undermining cybersecurity.

(3) Submission and form

(A) Submission

The report required under paragraph (1) shall be submitted not later than 90 days after October 25, 2018, and every 180 days thereafter for 5 years.

(B) Form

The report required under paragraph (1) shall be submitted in an unclassified form, but may include a classified annex.

(b) Designation of persons

The President shall designate under section 9214(a) of this title any person identified in the report required under subsection (a)(1) that knowingly engages in significant activities undermining cybersecurity through the use of computer networks or systems against foreign persons, governments, or other entities on behalf of the Government of North Korea.

(Pub. L. 114–122, title II, §209, Feb. 18, 2016, 130 Stat. 110; Pub. L. 115–272, title III, §303(c)(1), Oct. 25, 2018, 132 Stat. 4157.)


Editorial Notes

Amendments

2018—Subsec. (a)(3)(A). Pub. L. 115–272 substituted "not later than 90 days after October 25, 2018, and every 180 days thereafter for 5 years" for "not later than 90 days after February 18, 2016, and every 180 days thereafter".


Executive Documents

Delegation of Functions

For delegation of certain functions of President under this section, see Memorandum of President of the United States, May 18, 2016, 81 F.R. 37479, set out as a note under section 9212 of this title.

About This Section

22 U.S.C. § 9229 is part of Title 22 of the United States Code. The United States Code is the official codification of federal statutes maintained by the Office of the Law Revision Counsel of the U.S. House of Representatives. Congress amends the Code through new public laws, which are eventually incorporated into the relevant title.

This section may be cited in legal writing as 22 U.S.C. § 9229. For the most current official text, including any recent amendments, use the official source links below. Do not rely on this page as the sole authority for legal citation or litigation.

How to Read This Statute

Statutes are organized by title, chapter, section, and subsection. Pay attention to words like "shall," "may," "and," and "or," because they determine whether a requirement is mandatory or permissive and whether multiple conditions must all be met. Historical notes and amendments often appear at the end of a section.

Using This Page

This page is intended for research and educational use. Lawyers, students, journalists, and compliance professionals can use it as a starting point, but should always verify the current text through an official government source before relying on it for legal advice, filings, or compliance decisions.

Sources

Source: official Us Code text · Last verified 2026-08-27

Frequently Asked Questions About Us Code § 9229

What does United States Code § 9229 cover?

Section 9229 ("Report on and imposition of sanctions to address persons responsible for knowingly engaging in significant activities undermining cybersecurity") is part of the United States Code, the codified statutory law of Us Code. It sets out the legal rule or procedure described in the text above. Statutes are amended regularly, so always verify against the official source.

How do I cite Us Code § 9229?

A common citation format is "United States Code § 9229" (Us Code). Legal writing may require the code abbreviation, section number, and year or edition. Match the style required by your court, professor, or publisher.

Is this the official text of Us Code law?

No. This page is for research and education and may not include the most recent amendments. For official current law, check the Us Code official source linked on this page or consult a licensed Us Code attorney.

How does Us Code § 9229 apply to my situation?

Statutes are interpreted in context, and application depends on your specific facts. Only a licensed attorney in Us Code can advise on how this section applies to you. Contact your state or local bar association for a referral.

Sources & Verification

Not legal advice. Verify against the official source and consult a licensed attorney in Us Code.