Nonpartisan civic infrastructure
AllCiv·Legis1
·

S. 5028

BillFederalSenateFloor Consideration
Federal Contractor Cybersecurity Vulnerability Reduction Act of 2024
About This Bill
Introduced
Latest Action · December 19, 2024
Placed on Senate Legislative Calendar under General Orders. Calendar No. 740.
Congress
118th (2023–2025)
Introduced
September 11, 2024
Cosponsors (1)
0D 1R
View PDF ↗

Summary

Highlight any text to annotate
This bill requires federal contractors to establish vulnerability disclosure policies to help identify and address cybersecurity weaknesses in their information systems. It directs the Office of Management and Budget, working with cybersecurity and technology agencies, to review current contracting rules within 180 days and recommend updates aligning them with existing NIST guidelines and international cybersecurity standards. The Federal Acquisition Regulation Council would then have another 180 days to formally update contracting rules based on these recommendations, and the Department of Defense would follow a similar process for its own contracting supplement. The requirements apply to contractors with contracts above a certain dollar threshold or those managing federal information systems, though agencies can waive the requirement for national security or research reasons with proper notification to Congress. The bill explicitly authorizes no additional funding, meaning agencies must implement these changes using existing budgets.

Take Action

Your position
Add a comment
to comment on this bill.
Annotate the text
Highlight any passage on the Summary or Full Text tab to attach a note. Annotations appear on the Annotations tab.