H. R. 2029—706 (A) shall accept from any non-Federal entity in real time cyber threat indicators and defensive measures, pursuant to this section; (B) shall, upon submittal of the certification under paragraph (2) that such capability and process fully and effectively operates as described in such paragraph, be the process by which the Federal Government receives cyber threat indicators and defensive measures under this title that are shared by a non-Federal entity with the Federal Government through electronic mail or media, an interactive form on an Internet website, or a real time, automated process between information systems except— (i) consistent with section 104, communications between a Federal entity and a non-Federal entity regarding a previously shared cyber threat indicator to describe the relevant cybersecurity threat or develop a defensive measure based on such cyber threat indicator; and (ii) communications by a regulated non-Federal entity with such entity’s Federal regulatory authority regarding a cybersecurity threat; (C) ensures that all of the appropriate Federal entities receive in an automated manner such cyber threat indicators and defensive measures shared through the real-time process within the Department of Homeland Security; (D) is in compliance with the policies, procedures, and guidelines required by this section; and (E) does not limit or prohibit otherwise lawful disclosures of communications, records, or other information, including— (i) reporting of known or suspected criminal activity, by a non-Federal entity to any other nonFederal entity or a Federal entity, including cyber threat indicators or defensive measures shared with a Federal entity in furtherance of opening a Federal law enforcement investigation; (ii) voluntary or legally compelled participation in a Federal investigation; and (iii) providing cyber threat indicators or defensive measures as part of a statutory or authorized contractual requirement. (2) CERTIFICATION AND DESIGNATION.— (A) CERTIFICATION OF CAPABILITY AND PROCESS.—Not later than 90 days after the date of the enactment of this Act, the Secretary of Homeland Security shall, in consultation with the heads of the appropriate Federal entities, submit to Congress a certification as to whether the capability and process required by paragraph (1) fully and effectively operates— (i) as the process by which the Federal Government receives from any non-Federal entity a cyber threat indicator or defensive measure under this title; and (ii) in accordance with the interim policies, procedures, and guidelines developed under this title. (B) DESIGNATION.— (i) IN GENERAL.—At any time after certification is submitted under subparagraph (A), the President

Select target paragraph3