Remote Access Security Act
Click any stage to learn more about the legislative process.
Would amend the Export Control Reform Act of 2018 to extend U.S. export controls to 'remote access' — meaning a foreign person reaching a controlled item through the internet or a cloud service from outside the item's physical location — allowing the Commerce Department to license and penalize such access when it poses a serious national security or foreign policy risk.
The change would close a gap in the existing export control framework, addressing scenarios where foreign actors use digital connectivity to reach controlled U.S. technology without physically moving it across a border, and would require advance congressional notification before regulations take effect.
What this bill would do
What it would do
The bill would amend the Export Control Reform Act of 2018 (ECRA) to bring "remote access" within the scope of U.S. export controls. Remote access is defined as a foreign person accessing a controlled item via a network connection — including the internet or a cloud computing service — from a location other than where the item physically resides, provided the Secretary of Commerce determines that such use could pose a serious risk to national security or foreign policy. The bill would insert remote access alongside exports and in-country transfers throughout ECRA, enabling the Bureau of Industry and Security to issue licenses for permissible remote access and to impose civil and criminal penalties for violations.
The bill would also require the Secretary of Commerce to keep designated congressional committees fully and currently informed before promulgating any regulations under the new authority, including briefings — in classified settings if necessary — on the national security risk addressed, the regulatory approach chosen, and potential economic impacts on the United States. This consultation requirement would not, however, give Congress a veto over those regulations.
Key provisions
- 1Would add a statutory definition of 'remote access' to ECRA — covering a foreign person's network-based access to a controlled item from outside its physical location when the Secretary finds a serious national security or foreign policy risk.
- 2Would extend ECRA's core licensing, enforcement, and penalty authorities — currently covering exports and in-country transfers — to remote access of controlled items throughout the statute.
- 3Would require the Secretary of Commerce to brief designated congressional committees before promulgating remote-access regulations, covering the security risk addressed, regulatory approach, and economic impact.
- 4Would clarify that the congressional notification requirement does not give committees veto power over regulations issued under the amended ECRA authority.
Who would be affected
Cloud service providers, technology companies, and any domestic entity that hosts or provides access to items subject to U.S. export controls via network connections. Foreign persons who remotely operate or interact with controlled U.S. technology through the internet or cloud platforms would also be subject to the new rules. The Commerce Department's Bureau of Industry and Security would gain expanded regulatory and enforcement authority.
Why it matters
If enacted, firms providing cloud or internet access to controlled U.S. technology would need to assess whether foreign users' remote connections trigger export licensing obligations — even when no physical item crosses a border. Violations could expose providers and foreign users to the same civil and criminal penalties that currently apply to unauthorized exports, creating new compliance obligations across the cloud computing and technology sectors.
What would change
Changes to existing law
Amends Export Control Reform Act of 2018 (Sec. 2)
Adds a definition of remote access and extends all licensing, enforcement, and penalty provisions throughout the statute to cover remote access of controlled items by foreign persons.
Agencies directed to act
Funding and costs
Congressional Budget Office estimate
CBO estimates that enacting H.R. 2683 would cost approximately $9 million over the 2025–2030 period in discretionary spending, with negligible effects on direct spending, revenues, and the deficit over the 2025–2035 period.
CBO estimates that H.R. 2683 would require about $9 million in discretionary appropriations (spending that requires annual congressional approval) over the 2025–2030 period to fund seven new full-time employees at the Bureau of Industry and Security (BIS) to finalize regulations, process license applications, and enforce the new remote-access export controls. Effects on direct (mandatory) spending and revenues — from civil and criminal penalties on violators — would each be less than $500,000 over the 2025–2035 period, resulting in an insignificant net reduction in the deficit. CBO found no intergovernmental mandates, but identified a private-sector mandate exceeding the UMRA statutory threshold ($206 million in 2025), because exporters would be required to obtain BIS licenses before allowing foreign entities to remotely access controlled technologies such as semiconductor chips, imposing compliance costs and potential revenue losses on affected businesses.
How implementation would work
The Bureau of Industry and Security would promulgate regulations under the Export Administration Regulations framework to define which items and remote-access scenarios require a license, consistent with the Secretary of Commerce's national security determinations. Before issuing those regulations, the Secretary must brief the House Committee on Foreign Affairs and the Senate Committee on Banking, Housing, and Urban Affairs — in a classified setting if necessary — on the security risk, regulatory method, and economic impact. BIS would then enforce the rules using existing ECRA penalty mechanisms, including civil fines and criminal prosecution.
Legislative status & sources
Latest action
Received in the Senate and Read twice and referred to the Committee on Banking, Housing, and Urban Affairs.
Official CRS summary
Show the CRS summaryHide the CRS summary
This bill broadens the scope of the U.S. export control system to include remote access of items. Remote access means (1) access to an item subject to the jurisdiction of the United States by a foreign person through a network connection, including the internet or a cloud computing service, from a location other than where the item is physically located; or (2) any other form of access specified in regulations promulgated by the Department of Commerce.
The Export Control Reform Act of 2018 (ECRA), which is implemented through the Export Administration Regulations, provides a permanent statutory basis for controlling the export of dual-use goods (e.g., items with both civilian and military uses) and certain military parts and components. This bill applies export controls under ECRA to remote access of items, thereby allowing Commerce's Bureau of Industry and Security to issue licenses and impose penalties related to remote access of controlled items.
Legislative subjects
Computers and information technology; Foreign Trade and International Finance; Presidents and presidential powers, Vice Presidents; Trade restrictions