<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<REGINFO_RIN_DATA xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" RUN_DATE="2026-05-25-04:00" xsi:noNamespaceSchemaLocation="https://www.reginfo.gov/public/xml/REGINFO_XML_Ver10262011.xsd">
    <RIN_INFO>
        <RIN>0694-AJ56</RIN>
        <PUBLICATION>
            <PUBLICATION_ID>202410</PUBLICATION_ID>
            <PUBLICATION_TITLE>The Regulatory Plan and the Unified Agenda of Federal Regulatory and Deregulatory Actions</PUBLICATION_TITLE>
        </PUBLICATION>
        <AGENCY>
            <CODE>0694</CODE>
            <NAME>Bureau of Industry and Security</NAME>
            <ACRONYM>BIS</ACRONYM>
        </AGENCY>
        <PARENT_AGENCY>
            <CODE>0600</CODE>
            <NAME>Department of Commerce</NAME>
            <ACRONYM>DOC</ACRONYM>
        </PARENT_AGENCY>
        <RULE_TITLE>Securing the Information and Communications Technology and Services Supply Chain: Connected Vehicles</RULE_TITLE>
        <ABSTRACT><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>The Department of Commerce&rsquo;s Bureau of Industry and Security (BIS) published an advance notice of proposed rulemaking (ANPRM) on March 1, 2024, to seek public comment on questions related to transactions involving information and communications technology and services integral to connected vehicles that are designed, developed, manufactured, or supplied by persons owned, controlled, or subject to the jurisdiction or direction of foreign governments or foreign non-government persons identified at 15 CFR 7.4, pursuant to Executive Order (E.O.) 13873.&nbsp;BIS is reviewing comments and working to implement a proposed rule to assist BIS in better determining the technologies and market participants most appropriate for regulation pursuant to E.O. 13873 regarding connected vehicles.</p>
</body>
</html>]]></ABSTRACT>
        <PRIORITY_CATEGORY>Other Significant</PRIORITY_CATEGORY>
        <RIN_STATUS>Previously Published in The Unified Agenda</RIN_STATUS>
        <RULE_STAGE>Proposed Rule Stage</RULE_STAGE>
        <MAJOR>Yes</MAJOR>
        <UNFUNDED_MANDATE_LIST>
            <UNFUNDED_MANDATE>No</UNFUNDED_MANDATE>
        </UNFUNDED_MANDATE_LIST>
        <CFR_LIST>
            <CFR>15 CFR 791</CFR>
        </CFR_LIST>
        <LEGAL_AUTHORITY_LIST>
            <LEGAL_AUTHORITY>50 U.S.C. 1701</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>50 U.S.C. 1601</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>3 U.S.C. 301</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>E.O. 13873</LEGAL_AUTHORITY>
        </LEGAL_AUTHORITY_LIST>
        <LEGAL_DLINE_LIST/>
        <RPLAN_ENTRY>Yes</RPLAN_ENTRY>
        <RPLAN_INFO>
            <STMT_OF_NEED><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>OICTS has identified an undue and unacceptable risk to U.S. national security or the security and safety of U.S. Persons from ICTS integral to connected vehicles that is designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction&nbsp;or direction&nbsp;of the People&rsquo;s Republic of China or Russia, which are each listed as foreign adversaries in 15 CFR Part 791.4(a). When such ICTS&nbsp;components are part of a Connected Vehicle, they may allow foreign adversaries to gain illicit access to the Connected Vehicle and this access could enable those foreign adversaries to exfiltrate sensitive data collected by Connected Vehicles and, potentially, allow remote access and manipulation of the vehicles. Pursuant to E.O. 13873, the Department&nbsp;proposes to identify&nbsp;the potential exfiltration of sensitive U.S. Person data and remote manipulation of Connected Vehicles as undue or unacceptable risks to U.S. national security and to the security and safety of U.S. Persons.&nbsp;</p>
</body>
</html>]]></STMT_OF_NEED>
            <LEGAL_BASIS><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>In E.O. 13873, the President delegated to the Secretary of Commerce, to the extent necessary to implement the order, the authority granted under the International Emergency Economic Powers Act&nbsp;(50 U.S.C. 1701, et seq.), to deal with any unusual and extraordinary foreign threat to the United States&rsquo; national security, foreign policy, or economy, if the President declares a national emergency with respect to such threat. In E.O. 13873, the President declared a national emergency with respect to the unusual and extraordinary foreign threat posed to the ICTS supply chain. This notice of proposed rulemaking aims to mitigate the risks to U.S. national security posed by ICTS integral to connected vehicles when those ICTS are designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction or direction of a foreign adversary.</p>
</body>
</html>]]></LEGAL_BASIS>
            <ALTERNATIVES><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>The Department has proposed what it believes to be the least restrictive means necessary [by] tailor[ing] the prohibition to address the undue or unacceptable risk while balancing the overall compliance costs&nbsp;of the rule and minimizing the impact on small entities. The Department also considered a no-action, and&nbsp;a&nbsp;more stringent alternative.&nbsp;The no-action alternative is not preferred because the risks presented by foreign adversary involvement in the U.S. CV market could lead to&nbsp;&nbsp;negative events for U.S. national security. The more stringent regulatory approaches, including regulating additional CV component systems under consideration that are not included in the proposed rule,&nbsp;were&nbsp;found to&nbsp;unacceptably increase the costs of the proposed rule due to the additional&nbsp;burden on industry&nbsp;while not substantially reducing national security risk.</p>
</body>
</html>]]></ALTERNATIVES>
            <COSTS_AND_BENEFITS><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>The Department concludes that the majority of costs will be borne&nbsp;by entities responsible for compliance with the proposed rule: namely connected vehicle manufacturers and VCS hardware importers. The two major costs associated with connected vehicle manufactures and VCS hardware importers are 1) costs related to rule compliance&nbsp;(range of $30,964 to $38,554,&nbsp;which does not apply to firms that handle less than 1,000 vehicles)&nbsp;and 2) costs associated with substitute parts and services.&nbsp;The Department estimates that increased prices for consumers may reduce the number of vehicles sold in the U.S. by an estimated 0.01 percent to 0.16 percent (1,700 to 26,000 fewer vehicles).&nbsp;The Department estimates 1,700 to 26,000 fewer vehicles would be purchased by U.S. consumers per year as a result of the proposed rule&nbsp;and&nbsp;also estimates increased prices for consumers may reduce the number of vehicles sold in the U.S. by an estimated 0.01 percent or 0.16 percent. The primary expected benefit of implementing the proposed rule would be a reduction in the chance of a catastrophic attack due to the exfiltration of data and remote manipulation of connected vehicles.</p>
</body>
</html>]]></COSTS_AND_BENEFITS>
            <RISKS><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>The request for comments via the NPRM and subsequent engagement with the public and industry on connected vehicle systems will inform BIS considerations to further the national security and foreign policy of the United States. To not undergo this NPRM process would be to the detriment of the national security and foreign policy of the United States.</p>
</body>
</html>]]></RISKS>
        </RPLAN_INFO>
        <TIMETABLE_LIST>
            <TIMETABLE>
                <TTBL_ACTION>ANPRM</TTBL_ACTION>
                <TTBL_DATE>03/01/2024</TTBL_DATE>
                <FR_CITATION>89 FR 15066</FR_CITATION>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>ANPRM Comment Period End</TTBL_ACTION>
                <TTBL_DATE>04/30/2024</TTBL_DATE>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>NPRM</TTBL_ACTION>
                <TTBL_DATE>12/00/2024</TTBL_DATE>
            </TIMETABLE>
        </TIMETABLE_LIST>
        <RFA_REQUIRED>No</RFA_REQUIRED>
        <GOVT_LEVEL_LIST>
            <GOVT_LEVEL>None</GOVT_LEVEL>
        </GOVT_LEVEL_LIST>
        <FEDERALISM>No</FEDERALISM>
        <PRINT_PAPER>No</PRINT_PAPER>
        <INTERNATIONAL_INTEREST>Yes</INTERNATIONAL_INTEREST>
        <AGENCY_CONTACT_LIST>
            <CONTACT>
                <FIRST_NAME>Marc</FIRST_NAME>
                <LAST_NAME>Coldiron</LAST_NAME>
                <AGENCY>
                    <CODE>0694</CODE>
                    <NAME>Bureau of Industry and Security</NAME>
                    <ACRONYM>BIS</ACRONYM>
                </AGENCY>
                <PHONE>202 482-3678</PHONE>
                <EMAIL>marc.coldiron@bis.doc.gov</EMAIL>
                <MAILING_ADDRESS>
                    <STREET_ADDRESS>1401 Constitution Avenue NW,</STREET_ADDRESS>
                    <CITY>Washington</CITY>
                    <STATE>DC</STATE>
                    <ZIP>20230</ZIP>
                </MAILING_ADDRESS>
            </CONTACT>
        </AGENCY_CONTACT_LIST>
    </RIN_INFO>
</REGINFO_RIN_DATA>
