H. R. 2029—736 SEC. 304. IDENTIFICATION OF CYBER-RELATED WORK ROLES OF CRITICAL NEED. (a) IN GENERAL.—Beginning not later than 1 year after the date on which the employment codes are assigned to employees pursuant to section 303(b)(2), and annually thereafter through 2022, the head of each Federal agency, in consultation with the Director, the Director of the National Institute of Standards and Technology, and the Secretary of Homeland Security, shall— (1) identify information technology, cybersecurity, or other cyber-related work roles of critical need in the agency’s workforce; and (2) submit a report to the Director that— (A) describes the information technology, cybersecurity, or other cyber-related roles identified under paragraph (1); and (B) substantiates the critical need designations. (b) GUIDANCE.—The Director shall provide Federal agencies with timely guidance for identifying information technology, cybersecurity, or other cyber-related roles of critical need, including— (1) current information technology, cybersecurity, and other cyber-related roles with acute skill shortages; and (2) information technology, cybersecurity, or other cyberrelated roles with emerging skill shortages. (c) CYBERSECURITY NEEDS REPORT.—Not later than 2 years after the date of the enactment of this Act, the Director, in consultation with the Secretary of Homeland Security, shall— (1) identify critical needs for information technology, cybersecurity, or other cyber-related workforce across all Federal agencies; and (2) submit a progress report on the implementation of this section to the appropriate congressional committees. SEC. 305. GOVERNMENT ACCOUNTABILITY OFFICE STATUS REPORTS. The Comptroller General of the United States shall— (1) analyze and monitor the implementation of sections 303 and 304; and (2) not later than 3 years after the date of the enactment of this Act, submit a report to the appropriate congressional committees that describes the status of such implementation. TITLE IV—OTHER CYBER MATTERS SEC. 401. STUDY ON MOBILE DEVICE SECURITY. (a) IN GENERAL.—Not later than 1 year after the date of the enactment of this Act, the Secretary of Homeland Security, in consultation with the Director of the National Institute of Standards and Technology, shall— (1) complete a study on threats relating to the security of the mobile devices of the Federal Government; and (2) submit an unclassified report to Congress, with a classified annex if necessary, that contains the findings of such study, the recommendations developed under paragraph (3) of subsection (b), the deficiencies, if any, identified under (4) of such subsection, and the plan developed under paragraph (5) of such subsection.

Select target paragraph3