Strengthening Agency Management and Oversight of Software Assets Act
What changed between versions
The definition of 'agency' now explicitly excludes elements of the intelligence community, and a new definition for 'intelligence community' is added referencing the National Security Act of 1947.
The comprehensive assessment scope is broadened from covering 'software entitlements and software inventories' to all 'software paid for by, in use at, or deployed throughout the agency,' now explicitly including software developed or built by the agency or another agency, including shared services.
Restrictions on software deployment now include 'data ownership or access' in addition to desktop/server hardware and cloud service provider restrictions.
Section 4 is retitled from 'Enterprise Licensing Positioning at Agencies' to 'Software modernization planning at agencies,' reflecting a broader mandate beyond just enterprise licensing.
The vendor-neutral procurement criteria requirement now includes an exception: 'unless prohibited by law (including regulation).'
The entire Section 5 'Government-wide strategy' is removed, including its requirement for a comprehensive strategy document and its budget submission requirements (which required performance metrics and progress reporting in 6 consecutive presidential budgets).
A new subsection (f) in Section 3 requires intelligence community elements to conduct their comprehensive assessments separately, performed only by a designated entity, with national security protections, and submitted in summary form to the Director and intelligence committees within 30 days.
The Chief Procurement Officer is replaced with the Chief Acquisition Officer throughout, and the Chief Data Officer is added as a required consulting official for both the assessment and the plan.
The redundancy determination standard is expanded: software is flagged if it creates duplication OR is otherwise determined unnecessary by the CIO, giving the CIO broader discretion.
The submission process is restructured: the CIO now submits only to the agency head, and the agency head then has 30 days to submit to the Director, Administrator, Comptroller General, and Congress. Previously the CIO submitted directly to all recipients.
The consultation provision in Section 3 is changed from permissive ('may share') to mandatory ('shall share'), requiring the Director to share information and best practices with agencies.
A new plan requirement mandates that agencies restrict the ability of any bureau, program, component, or operational entity to acquire, use, develop, or leverage software entitlements without CIO approval in consultation with the Chief Acquisition Officer.
New training requirements are added: agency officers and employees must be trained before entering into any software agreement, covering contract negotiation options, differences between commercial and custom software, and cost determination for different license types.
A new plan requirement calls for automation of software license management processes and incorporation of discovery tools across the agency.
The minimum number of software categories to prioritize for conversion is removed (previously 'not fewer than 5'), giving agencies more flexibility in how many categories they select.
A new Section 4(e)(2) requires the Director to submit a report within 2 years detailing recommendations on leveraging procurement policies to increase interoperability, consolidate licenses, reduce costs, improve performance, and modernize software management.
The deadline for agencies to complete their comprehensive assessment is extended from 1 year to 18 months after enactment.
The plan submission deadline is changed from 120 days after the CIO submits the assessment to 1 year after the agency head submits the assessment.
The conflict of interest provision now specifically references 'organizational conflicts of interest' as defined in subpart 9.5 of the Federal Acquisition Regulation, rather than using the undefined term 'organization conflicts of interest.'
The GAO report (now Section 5) is expanded to specifically cover trends in software asset management practices, comparisons among agencies, the Director's establishment of harmonization processes, and agency compliance with contract support restrictions.
A new Section 6 states that no additional funds are authorized to be appropriated for carrying out the Act.