Nonpartisan civic infrastructure
AllCiv·Legis1
·

H.R. 3608

BillFederalHouseIn Committee
Improving Contractor Cybersecurity Act
About This Bill
Committee
Latest Action · May 28, 2021
Referred to the House Committee on Oversight and Reform.
Congress
117th (2021–2023)
Introduced
May 28, 2021
Cosponsors (0)
None
View PDF ↗

Summary

Highlight any text to annotate
Improving Contractor Cybersecurity Act This bill prohibits an executive agency from entering into a contract for information technology unless the contractor maintains a vulnerability disclosure policy (VDP) and program. The contractor must report to the Cybersecurity and Infrastructure Security Agency (CISA) of the Department of Homeland Security, within seven days after the VDP is published, information regarding any valid or credible report of a not previously known public vulnerability on a system that uses commercial software or services that affect, or are likely to affect, other parties in government or industry once a patch or viable mitigation is available; and any other situation where the contractor determines it would be helpful or necessary to involve CISA. CISA must submit vulnerabilities to the MITRE Common Vulnerabilities and Exposures database and the National Institute of Standards and Technology National Vulnerability Database.

Take Action

Your position
Add a comment
to comment on this bill.
Annotate the text
Highlight any passage on the Summary or Full Text tab to attach a note. Annotations appear on the Annotations tab.