 Enabling a Digital Economy that Empowers and Protects Consumers The American public must be able to participate in a digital economy that is safe, fair, and accessible, and produces hardware and software that are reliably secure against cyber threats. The Administration has pursued a range of market shaping tools to empower consumers, promote innovation, and incentivize cyber-secure competition. In March 2024, the FCC approved the U.S. Cyber Trust Mark, a voluntary cybersecurity certification and labeling program that will help Americans purchase smart devices that are safer and less vulnerable to cyberattacks. Under the program, IoT devices that meet certain cybersecurity criteria as determined by NIST, such as requiring unique and strong default passwords or securely implementing software updates, will be eligible for certification. Already, several leading consumer electronics manufacturers and retailers have committed to supporting implementation of the program. In July 2023, DOE announced a labeling research effort to address the feasibility and limitations of applying a labeling approach to OT like smart meters and solar inverters. The Administration has taken steps to ensure that Federal spending increases our collective cybersecurity and resilience. DoD, the General Services Administration (GSA), and NASA have proposed amendments to the Federal Acquisition Regulation (FAR) to standardize and improve cybersecurity requirements for unclassified Federal information systems, including prohibiting agencies from buying vulnerable IoT devices and requiring the use of SBOMs. Raising the cybersecurity standards of Federally-procured technology products will incentivize cybersecurity across the ecosystem. Under the False Claims Act, the DOJ’s Civil Cyber-Fraud Initiative holds government contractors accountable when they materially misrepresent the cybersecurity attributes of their products or services. In 2023, DOJ reached settlements with two vendors who had misrepresented that their products met cybersecurity controls tied to Federal contracts. At the end of 2023, the Treasury Department completed its initial assessment of the need for a Federal insurance response to catastrophic cyber events, finding that further exploration of the appropriate form of such a response is warranted and would be undertaken in the next phase of the assessment, in coordination with CISA and ONCD. CISA also announced the reconstitution of the Cybersecurity Insurance and Data Analysis Working Group to create a venue for government and industry stakeholders to exchange information and discuss the role of the insurance industry in driving down cyber risk. Investing in Resilient Next-Generation Technologies Embedding security and resilience into the technological foundations of our digital ecosystem is a cheaper and more efficient approach than attempting to bolt it on after the fact. In 2023, American innovation and public investment, powered by the President’s Invest in America Agenda, created opportunities for coordinated public-private efforts to optimize critical and emerging technologies for cybersecurity as they are developed and deployed. For example, in November 2023, DOE announced $70 million in funding through the Rural and Municipal 2024 REPORT 22 ON THE CYBERSECURITY OF THE UNITED STATES POSTURE

Select target paragraph3