Information and Communications Technology and Services National Security Review Act
SB2041, the Information and Communications Technology and Services National Security Review Act, would create a new Office of Information and Communications Technology and Services within the Department of Commerce’s Bureau of Industry and Security. The office would be responsible for reviewing certain ICTS-related transactions that may pose national security risks, especially where they involve entities or jurisdictions of concern, and for mitigating or prohibiting transactions when risks cannot be adequately addressed. The bill defines covered transactions broadly to include ICTS supply-chain transactions and certain exports, reexports, and in-country transfers of items on the Commerce Control List.
The bill gives the Secretary of Commerce substantial authority to investigate covered transactions, require information and testimony, impose mitigation measures, exclude components, and prohibit transactions. It also directs the Director of National Intelligence to provide periodic risk assessments, establishes an ICTS technical advisory committee, preserves existing ICTS-related executive order authorities, and creates enforcement, judicial review, and penalty provisions. Conforming amendments would update the Export Control Reform Act of 2018 to integrate the new part IV framework, add reporting requirements, and authorize an additional Assistant Secretary to help carry out the new responsibilities.
The bill would amend the Export Control Reform Act of 2018 by adding a new Part IV that formalizes and expands Commerce’s authority over ICTS national security reviews. It would create a permanent statutory structure for reviewing, mitigating, and prohibiting certain technology and supply-chain transactions, while also adding reporting, enforcement, and judicial review provisions. The measure would affect U.S. persons, companies in the ICTS and export-control sectors, and parties connected to China, Russia, Iran, North Korea, and other entities or jurisdictions designated as concerns.
Based on the bill text and available context, the measure appears to be framed as a national security and supply-chain protection bill, with an emphasis on preventing foreign adversaries from exploiting U.S. technology and infrastructure. There are no recorded committee transcripts or votes in the provided material, so no formal bipartisan or partisan sentiment can be directly measured from debate or roll call history. The structure and findings suggest a generally security-focused, enforcement-oriented approach that would likely appeal to lawmakers concerned about technology transfer, cyber risk, and critical infrastructure resilience.
The main points of contention are likely to be the breadth of Commerce’s new authority and the scope of transactions that can be reviewed or prohibited. The bill allows the Secretary to act on suspected undue risk, impose broad mitigation conditions, require extensive disclosures, and prohibit transactions when risks cannot be mitigated, which could raise concerns from industry about uncertainty, compliance burdens, and potential overreach. Additional friction may come from the bill’s focus on jurisdictions of concern, its use of classified or ex parte information in judicial review, and the significant criminal and civil penalties attached to violations.