critical infrastructure; foreign adversaries; prohibition
What changed between versions
Added specific definitions for 'Chinese company' (including ownership and control criteria) and 'critical infrastructure' (listing specific sectors like water, power, and data storage).
Added a definition for 'school bus infraction detection system' to clarify what equipment falls under the prohibited list.
Changed the enforcement mechanism from a requirement for the Corporation Commission to publish a prohibited list to a requirement for entities to submit sworn self-certification statements under penalty of perjury.
Added a new risk-based oversight program requiring randomized audits and targeted audits based on credible intelligence or complaints, rather than universal physical inspections.
Added explicit exceptions allowing the purchase or use of prohibited equipment if no other reasonable providers exist, if pre-approved by the Corporation Commission, or if banning it would pose a greater threat to the state.
Added a new subsection establishing a secure and dedicated communications channel between critical infrastructure providers and the Department of Emergency and Military Affairs for emergency situations.
Added a provision stating that the Corporation Commission does not need to inspect all infrastructure but must implement the risk-based oversight program.
Clarified that the ban applies to contracts providing direct or indirect access to critical infrastructure, rather than a blanket ban on all software produced by Chinese companies.