Building a Trusted ICT Supply Chain (Supply Chain), 56 are intended to be taken up in legislation, and many others rely on administrative actions from agencies such as the Department of Homeland Security (DHS), the National Institute of Standards and Technology (NIST), the Department of Defense (DOD), the Department of Commerce, and the Federal Communications Commission (FCC). Importantly, while these recommendations are targeted at actions in the public policy and legislative space, they could have widescale impacts on the private sector to include companies doing business with the federal government and industry members supporting the nation’s critical infrastructure. While a handful of the Commission’s proposals have been included in the 2021 National Defense Authorization Act (NDAA), there are still a number of recommendations that have drawn the interest of legislators and policymakers. This, combined with a proposed two-year extension of the Commission’s sunset period, potentially positions the CSC’s work as driving much of the cyber agenda in the coming year.