Chip Security and Export Verification Act

Full Title:
Chip Security Act

Summary#

This bill, called the Chip Security Act, would make the Commerce Department require security features on certain advanced chips and computers before those items are exported, reexported, or transferred within a foreign country. The main change is a new requirement that covered integrated circuit products include location verification and possibly other security mechanisms. The broad goal is to reduce theft, diversion, tampering, and unauthorized use of advanced computing hardware and to support export control and national security objectives.

  • Who is covered: Integrated circuits and computers in specific export control categories (blocks of items currently controlled under U.S. export rules).
  • Primary rule: Within 180 days of enactment, covered products must have chip security mechanisms that provide location verification.
  • Reporting duty: Export license holders must promptly report credible information that a product is not where or with whom the license said it would be, or has been tampered with.
  • Further study and rules: Commerce must, with Defense, assess additional security measures within one year and can require those secondary measures within two years after the assessment.
  • Enforcement powers: Commerce may verify locations, keep records of products (including location and end-user), and require information from licensees to maintain records.
  • Ongoing review: Commerce must assess new chip security mechanisms annually for three years and report to Congress.

What it means for you#

  • Manufacturers of chips and covered devices

    • Must design and ship covered products with location-verification features within 180 days of the law starting.
    • Could face new technical requirements later if Commerce and Defense identify additional security measures.
  • Exporters and companies that apply for export licenses

    • Must report quickly if a licensed item is in a different location, has an unauthorized user, or shows tampering.
    • Must supply information Commerce asks for to support recordkeeping and verification.
  • Technology and security teams

    • May need to add or change firmware, software, or hardware to support location verification and later secondary mechanisms.
    • Must consider impacts on product performance, testing, and supply-chain procedures.
  • U.S. government agencies (Commerce and Defense)

    • Will do assessments, issue standards, verify exported items, and keep records of exported products and end-users.
    • Will produce reports to Congress, including possibly classified annexes.
  • Foreign buyers or end-users of covered products

    • Could receive devices that include embedded security and location-tracking features.
    • The bill does not specify how foreign privacy or sovereignty concerns will be handled.
  • General public and customers of affected products

    • If products include new security features, that could affect device performance, repairability, or resale — the bill does not detail these effects.

Expenses#

No publicly available information.

  • The bill requires assessments, reports, recordkeeping, and verification activities, which would likely increase administrative costs for the Commerce Department and possibly Defense.
  • Companies that make or export covered products would likely incur compliance costs to design, test, and deploy required security mechanisms.
  • There may be costs to validate and maintain a record of product locations and end-users, and potential costs from changes in device performance or timeframe to market.
  • The bill directs Commerce to analyze implementation costs as part of the required assessment, but it does not provide a budget or specific funding in the text.

Proponents' View#

  • The bill appears intended to reduce theft, diversion, tampering, and unauthorized use of advanced chips and computing hardware exported from the United States.
  • It could improve compliance with existing export control laws by giving exporters and regulators technical tools to verify location and end-use.
  • The law could make it easier to detect smuggling or misuse, potentially allowing Commerce to relax export restrictions for trusted partners where security mechanisms are present.
  • The bill supports using U.S. technology to advance U.S. foreign policy and national security goals and to help allies and partners use advanced computing in secure ways.

Opponents' View#

  • One concern is technical feasibility: the bill requires location verification within 180 days but does not define which methods are acceptable or how reliable they must be.
  • The bill does not fully explain who pays for design, testing, and deployment of security mechanisms; this may raise costs for manufacturers and exporters.
  • The requirement to record and verify locations and end-users may raise privacy or sovereignty questions for foreign users; the bill does not detail safeguards for those concerns.
  • The bill asks Commerce to keep records and verify ownership and location, but it is unclear how that will work in practice, how accurate records will be, or how enforcement will be handled abroad.
  • Adding security mechanisms could affect device performance, increase attack surface if poorly designed, or introduce new vulnerabilities; the bill requires Commerce to study such risks but does not set specific protections.