Skip to main content
HOUSE 3608117th CongressReferred to the House Committee on Oversight and Reform.

Improving Contractor Cybersecurity Act

Last Action
5/28/2021

Actions

  • 2021-05-28Referred to the House Committee on Oversight and Reform.
  • 2021-05-28Introduced in House
  • 2021-05-28Introduced in House

CRS Summary

As of 2021-05-28 (00)

Improving Contractor Cybersecurity Act

This bill prohibits an executive agency from entering into a contract for information technology unless the contractor maintains a vulnerability disclosure policy (VDP) and program.

The contractor must report to the Cybersecurity and Infrastructure Security Agency (CISA) of the Department of Homeland Security, within seven days after the VDP is published, information regarding

  • any valid or credible report of a not previously known public vulnerability on a system that uses commercial software or services that affect, or are likely to affect, other parties in government or industry once a patch or viable mitigation is available; and
  • any other situation where the contractor determines it would be helpful or necessary to involve CISA.

CISA must submit vulnerabilities to the MITRE Common Vulnerabilities and Exposures database and the National Institute of Standards and Technology National Vulnerability Database.

Subjects

  • Computers and information technology
  • Government information and archives
  • Public contracts and procurement
Read on Congress.gov

Sourced from Congress.gov (public domain).

This is legal information, not legal advice. Laws vary by jurisdiction and change frequently. Always verify current law with official sources and consult a licensed attorney in your jurisdiction for advice on your specific situation.