usa — track Congress Laws

Improving Contractor Cybersecurity Act

HR 1258 · In committee · last action February 12, 2025

<p><strong>Improving Contractor Cybersecurity Act</strong></p><p>This bill prohibits an executive agency from entering into a contract for information technology unless the contractor maintains a vulnerability disclosure policy (VDP) and program.</p><p>The contractor must report to the Cybersecurity and Infrastructure Security Agency (CISA) of the Department of Homeland Security, within seven days after the VDP is published&nbsp;and on an ongoing basis as vulnerability reports are received, information regarding</p><ul><li>any valid or credible report of a not previously known public vulnerability on a system that uses commercial software or services that affect, or are likely to affect, other parties in government or industry once a patch or viable mitigation is available; and</li><li>any other situation where the contractor determines it would be helpful or necessary to involve CISA.</li></ul><p>CISA must submit vulnerabilities to the MITRE Common Vulnerabilities and Exposures database and the National Institute of Standards and Technology National Vulnerability Database.</p>

Sponsor

Ted Lieu (D-CA)

Associated votes

No votes recorded against this bill yet — vote coverage is a work in progress.

Official summary

<p><strong>Improving Contractor Cybersecurity Act</strong></p><p>This bill prohibits an executive agency from entering into a contract for information technology unless the contractor maintains a vulnerability disclosure policy (VDP) and program.</p><p>The contractor must report to the Cybersecurity and Infrastructure Security Agency (CISA) of the Department of Homeland Security, within seven days after the VDP is published&nbsp;and on an ongoing basis as vulnerability reports are received, information regarding</p><ul><li>any valid or credible report of a not previously known public vulnerability on a system that uses commercial software or services that affect, or are likely to affect, other parties in government or industry once a patch or viable mitigation is available; and</li><li>any other situation where the contractor determines it would be helpful or necessary to involve CISA.</li></ul><p>CISA must submit vulnerabilities to the MITRE Common Vulnerabilities and Exposures database and the National Institute of Standards and Technology National Vulnerability Database.</p>