Nonpartisan civic infrastructure
AllCiv·Legis1
·

H.R. 5255

BillFederalHouseReported
To require covered contractors implement a vulnerability disclosure policy consistent with NIST guidelines, and for other purposes.
About This Bill
Floor Vote
Latest Action · May 15, 2024
Ordered to be Reported in the Nature of a Substitute by the Yeas and Nays: 42 - 0.
Congress
118th (2023–2025)
Introduced
August 22, 2023
Cosponsors (0)
None
View PDF ↗

Summary

Highlight any text to annotate
The Federal Cybersecurity Vulnerability Reduction Act of 2023 requires federal contractors to adopt vulnerability disclosure policies aligned with National Institute of Standards and Technology guidelines. The bill applies to contractors with federal contracts valued at or above the simplified acquisition threshold and directs the Office of Management and Budget to review and update federal procurement rules within 180 days of enactment, with final updates to the Federal Acquisition Regulation due 60 days later. The Department of Defense must conduct a similar review and update its own procurement rules on the same timeline. Contractors can be exempted from these requirements only if a federal Chief Information Officer determines the waiver is necessary for national security or research purposes. The bill does not specify new funding but establishes timelines for implementing existing NIST cybersecurity standards across federal contracting.

Take Action

Your position
Add a comment
to comment on this bill.
Annotate the text
Highlight any passage on the Summary or Full Text tab to attach a note. Annotations appear on the Annotations tab.