This bill requires the federal government to establish new rules that mandate federal contractors implement formal policies for disclosing security vulnerabilities in their computer systems, following standards set by the National Institute of Standards and Technology (NIST). The Office of Management and Budget has 180 days from the bill's enactment to recommend updates to federal contracting rules, and the Federal Acquisition Regulation Council has an additional 180 days to incorporate these requirements into procurement contracts. The new rules will apply to contractors on federal contracts worth at least the simplified acquisition threshold (currently $250,000) and those managing federal information systems. Agencies can request waivers from these requirements if they determine it's necessary for national security or research purposes, but must notify Congress within 30 days if they do so. The bill requires no new federal funding to implement.
Take Action
Your position
Add a comment
to comment on this bill.
Annotate the text
Highlight any passage on the Summary or Full Text tab to attach a note. Annotations appear on the Annotations tab.