H.R. 4915House118th Congress (2023-2025)In Committee

The Project Spectrum Authorization Act

Introduced July 26, 2023

AI-Generated Summary

Updated January 20, 2026 at 10:31 AM UTC

The Project Spectrum Authorization Act adds a new section to Title 10 of the U.S. Code to formally establish the Department of Defense’s Project Spectrum program. The program creates an online platform that offers cybersecurity education, tools, and services to small and medium‑size defense suppliers. It sets up eligibility rules, an application process, and defines the types of resources that can be provided. The bill mainly affects DoD contractors that qualify as “covered entities.”

Key Provisions

  • Creates a new Section 398b in Title 10 that authorizes Project Spectrum, an online platform delivering cybersecurity resources to eligible small‑ and medium‑business defense suppliers.
  • Allows the Director of the Office of Small Business Programs to set eligibility criteria and require applications for access to specific resources or services.
  • Specifies the range of resources offered, including training, best‑practice guidance, security assessments, product reviews, monitoring, patching, readiness checks, and secure data‑collaboration tools.
  • Defines “covered entity” as a DoD supplier that is a small or medium business and registers on the Project Spectrum platform.
  • Mandates the Director to maintain and operate the platform and to provide any additional resources deemed necessary.

Legislative Activity

Stay on top of the latest movement without scrolling through every action

1 earlier action
HouseIntro Referral Latest Action

Referred to the House Committee on Armed Services.

July 26, 2023

View full timeline
HouseIntro Referral

Introduced in House

July 26, 2023

HouseIntro Referral

Referred to the House Committee on Armed Services.

July 26, 2023

Bill Text

Latest available legislative text

Reading Mode
Latest
Introduced in HouseIssued July 26, 2023

I

118th CONGRESS

1st Session

H. R. 4915

IN THE HOUSE OF REPRESENTATIVES

July 26, 2023

Mr. Joyce of Ohio (for himself, Ms. Ross, Mr. Fitzpatrick, and Ms. Escobar) introduced the following bill; which was referred to the Committee on Armed Services

A BILL

To amend title 10, United States Code, to codify the program of the Office of Small Business Programs of the Department of Defense known as Project Spectrum, and for other purposes.

1.

Short title

This Act may be cited as the The Project Spectrum Authorization Act.

2.

Project Spectrum

Chapter 19 of title 10, United States Code, is amended by inserting before section 399 the following new section:

398b.

Project Spectrum

(a)

Project Spectrum; purpose

There is within the Office of Small Business Programs of the Department of Defense a program known as Project Spectrum, the purpose of which is to provide to covered entities, through an online platform, digital resources and services that increase awareness about cybersecurity risks and help such covered entities to comply with the cybersecurity requirements of the defense acquisition system.

(b)

Eligibility

The Director of the Office of Small Business Programs may establish eligibility requirements for the receipt by a covered entity of a given resource or service made available through Project Spectrum.

(c)

Application

To receive through Project Spectrum a resource or service for which the Director has established an eligibility requirement under subsection (b), a covered entity shall submit to the Director an application at such time, in such form, and containing such information as the Director determines appropriate.

(d)

Functions

In carrying out Project Spectrum, the Director shall maintain an online platform through which the Director shall make available to each covered entity that the Director determines to be eligible under subsection (b) with respect to a given resource or service, the following:

(1)

Educational materials regarding cybersecurity, including cybersecurity training courses and workforce development training.

(2)

Guidance regarding best practices for cybersecurity matters, including guidance for developing internal cybersecurity policies and suggestions for procedures for reviewing any violation of such policies.

(3)

Assessments of the cybersecurity practices and cybersecurity systems used by a covered entity.

(4)

A review and feasibility assessment of products, software, and data security tools available in the commercial marketplace.

(5)

Cybersecurity services, including dashboard monitoring services, continuous threat monitoring services, software patching services, and patch testing services.

(6)

Cybersecurity readiness checks.

(7)

A platform for secure data collaboration between two or more employees of a covered entity and between multiple covered entities.

(8)

Any additional resources or services, as determined by the Director.

(e)

Definitions

In this section:

(1)

The term covered entity means a supplier of the Department of Defense that is a small or medium business and registers to access the online platform of Project Spectrum.

(2)

The term defense acquisition system has the meaning given to such term in section 3001 of this title.

.