S.Amdt. 3557Senate119th Congress (2025-2027)2nd degree
To require the Inspector General of the Department of Defense to conduct an audit of foreign exposure from Department of Defense cloud computing contracts and to require the Secretary of Defense to update guidance to reduce, mitigate, or eliminate risk.
Sponsored by
Sen. Elissa Slotkin (D-MI)
Submitted August 1, 2025
Legislative Activity
Stay on top of the latest movement without scrolling through every action
Floor
Latest Action
Senate amendment agreed to: Amendment SA 3557 agreed to in Senate by Voice Vote.
October 9, 2025
View full timeline
Floor
Senate amendment agreed to: Amendment SA 3557 agreed to in Senate by Voice Vote.
October 9, 2025
Floor
Senate amendment proposed (on the floor): Amendment SA 3557 proposed by Senator Wicker for Senator Slotkin to Amendment SA 3748.
October 9, 2025
Floor
Amendment SA 3557 proposed by Senator Wicker for Senator Slotkin to Amendment SA 3748. (consideration: CR S7074-7086)
October 9, 2025
Floor
Amendment SA 3557 agreed to in Senate by Voice Vote.
October 9, 2025
Floor
Senate amendment submitted
August 1, 2025
Text
Submitted
SA 3557. Ms. SLOTKIN submitted an amendment intended to be proposed by her to the bill S. 2296, to authorize appropriations for fiscal year 2026 for military activities of the Department of Defense, for military construction, and for defense activities of the Department of Energy, to prescribe military personnel strengths for such fiscal year, and for other purposes; which was ordered to lie on the table; as follows: At the appropriate place in title XVI, insert the following: SEC. 16__. AUDIT AND UPDATED GUIDANCE TO REDUCE, MITIGATE, OR ELIMINATE RISK FROM CLOUD COMPUTING CONTRACTS WITH FOREIGN EXPOSURE. (a) Review of Foreign Exposure From Department of Defense Cloud Computing Contracts.-- (1) Audit required.--The Inspector General of the Department of Defense shall conduct an audit of cloud computing contracts for the Department of Defense to assess the risk of exposure of sensitive information, including data, systems architecture details, procedures, or other controlled unclassified information, as a result of policies that may have allowed computer scientists or engineers from foreign countries of concern to access proposed software updates to underlying cloud computing infrastructure or operating systems. (2) Elements.--The audit conducted pursuant to paragraph (1) shall cover the following: (A) Determination of how many cloud computing contracts the Department has that may be or have been supported by employees located in foreign countries of concern or are citizens of foreign countries of concern. [[Page S5322]] (B) Identification of policies or clauses in such cloud computing contracts that allow for the use of so called ``digital escorts'', computer scientists, or engineers from foreign countries of concern. (C) Assessment of agreements in place that use so called ``digital escorts'' to provide oversight to employees from foreign countries of concern, including identification of instances in which such authorities were used during the period beginning on January 1, 2022, and ending on the date of the enactment of this Act. (D) Assessment of the national security risks that stem from cloud computing contracts that use labor from foreign countries of concern. (E) Recommendations on ways to reduce, mitigate, or eliminate risk from initiatives such as so called ``digital escorting'', or the use of computer scientists or engineers from foreign countries of concern. (3) Report to congress.--Not later than July 1, 2026, the Inspector General shall submit to the Committee on Armed Services of the Senate and the Committee on Armed Services of the House of Representatives a report setting forth the findings of the Inspector General with respect to the audit conducted pursuant to paragraph (1). (b) Guidance to Reduce, Mitigate, or Eliminate Risk.-- (1) Guidance.--Based on the audit conducted under subsection (a), the Secretary shall issue new guidance to reduce, mitigate, or eliminate risk to Department data or cloud computing infrastructure from foreign countries of concern. (2) Requirements.--The guidance issued pursuant to paragraph (1) shall-- (A) restrict the use of personnel from foreign countries of concern to support Department information technology systems; and (B) require disclosure to the congressional defense committees if the Secretary finds a Department information technology system is maintained by personnel from a foreign country of concern. (3) Waiver.--The Secretary may waive any guidance issued under paragraph (1) in any case in which the Secretary certifies in writing that such waiver-- (A) does not pose a risk to national security; and (B) is necessary in the interest of national security. (c) Definition of Foreign Country of Concern.--ln this section, the term ``foreign country of concern'' has the meaning given that term in section 9901 of the William M. (Mac) Thornberry National Defense Authorization Act for Fiscal Year 2021 (15 U.S.C. 4651). ______