PoliticalRepoPoliticalRepo

United States · Bill · HR

H.R. 3608 (117th)

Improving Contractor Cybersecurity Act

referredUnited States· United States Congress· EN

Introduced

28 May 2021

Last action

28 May 2021 · Introduced

Status

Referred to the House Committee on Oversight and Reform.

Sponsors

Rep. Lieu, Ted [D-CA-36]

Subjects

Transport

Source updated

7 April 2025

Transport

Summary

Improving Contractor Cybersecurity Act This bill prohibits an executive agency from entering into a contract for information technology unless the contractor maintains a vulnerability disclosure policy (VDP) and program. The contractor must report to the Cybersecurity and Infrastructure Security Agency (CISA) of the Department of Homeland Security, within seven days after the VDP is published, information regarding any valid or credible report of a not previously known public vulnerability on a system that uses commercial software or services that affect, or are likely to affect, other parties in government or industry once a patch or viable mitigation is available; and any other situation where the contractor determines it would be helpful or necessary to involve CISA. CISA must submit vulnerabilities to the MITRE Common Vulnerabilities and Exposures database and the National Institute of Standards and Technology National Vulnerability Database.

This text is taken from the official record. PoliticalRepo does not editorialize.

Timeline

  1. 28 May 2021

    Introduced

    Referred to the House Committee on Oversight and Reform.

    Source: IntroReferral

  2. 28 May 2021

    Introduced

    Introduced in House

    Source: IntroReferral

  3. 28 May 2021

    Introduced

    Introduced in House

    Source: IntroReferral

Votes

No vote records are attached yet.

Versions

Documents

3 official files

Introduced in House (text)

View fileDownload file

Sponsors

Related records

Sources

PoliticalRepo is an index and interpretation layer, not the authoritative legal source.