No CRS summary available for this bill.
This section directs the TSA Administrator, not later than 180 days after enactment, to establish (1) a system for conducting risk-informed, headquarters-based covert testing project scenarios for aviation security operations (including passenger and baggage screening) to identify vulnerabilities with statistically valid data; and (2) a long-term headquarters-based covert testing program using static, risk-informed threat vectors based on annual risk assessments to annually assess operations effectiveness. For the project scenarios, TSA must conduct at least three per year—ensuring each Category X airport (i.e., highest-risk large-hub airports) is tested at least once per fiscal year—while documenting methodology for statistical validity. This section further requires TSA to establish a mitigation process for identified vulnerabilities, including root cause analysis within 90 days, a mitigation determination within 150 days thereafter (with prioritization by risk reduction, documented milestones and timelines if mitigating, or justification if not), and retesting within 180 days after mitigation completion. Finally, this section requires TSA to submit annual unclassified reports (with classified annexes) by November 30—starting in the first full fiscal year after enactment—to specified congressional committees alongside its budget request, detailing vulnerabilities, mitigation status, retesting results, unmitigated justifications, and trends; and to publicly post summaries of Category X airport covert testing performance data (total tests and aggregate pass/failure rates).