The Federal Cybersecurity Vulnerability Reduction Act of 2023 requires federal contractors to adopt vulnerability disclosure policies aligned with National Institute of Standards and Technology guidelines. The bill applies to contractors with federal contracts valued at or above the simplified acquisition threshold and directs the Office of Management and Budget to review and update federal procurement rules within 180 days of enactment, with final updates to the Federal Acquisition Regulation due 60 days later. The Department of Defense must conduct a similar review and update its own procurement rules on the same timeline. Contractors can be exempted from these requirements only if a federal Chief Information Officer determines the waiver is necessary for national security or research purposes. The bill does not specify new funding but establishes timelines for implementing existing NIST cybersecurity standards across federal contracting.
Take Action
Your position
Add a comment
to comment on this bill.
Annotate the text
Highlight any passage on the Summary or Full Text tab to attach a note. Annotations appear on the Annotations tab.