“To amend title 41, United States Code, to require information technology contractors to maintain a vulnerability disclosure policy and program, and for other purposes.”
Government operations and politics
Introduced Feb 12, 2025
Last action Feb 12, 2025
Pipeline · Bill → Law
Step 1
Introduced
Feb 12, 2025
Step 2
Referred
Feb 12, 2025
Oversight
Step 3
Committee
Step 4
House floor
Step 5
Senate
Step 6
Resolve Changes
Step 7
Signed
SummaryCRS Summary
This bill prohibits an executive agency from entering into a contract for information technology unless the contractor maintains a vulnerability disclosure policy (VDP) and program.
The contractor must report to the Cybersecurity and Infrastructure Security Agency (CISA) of the Department of Homeland Security, within seven days after the VDP is published and on an ongoing basis as vulnerability reports are received, information regarding
any valid or credible report of a not previously known public vulnerability on a system that uses commercial software or services that affect, or are likely to affect, other parties in government or industry once a patch or viable mitigation is available;...
Provisions · 2 sectionsIntroduced in House
AI
AI
Timeline · 2 actions
Feb 12, 2025
Introduced in House
Feb 12, 2025
Referred to the House Committee on Oversight and Government Reform.