United States · Bill · S
S. 917 (118th)
Securing Open Source Software Act of 2023
Introduced
22 March 2023
Last action
16 May 2023 · Reported
Status
Placed on Senate Legislative Calendar under General Orders. Calendar No. 76.
Sponsors
Gary Peters, Josh Hawley
Subjects
Transport, Budget
Source updated
27 May 2025
Summary
Securing Open Source Software Act of 2023 This bill sets forth the duties of the Cybersecurity and Infrastructure Security Agency (CISA) regarding open source software security. Open source software means software for which the human-readable source code is made available to the public for use, study, reuse, modification, enhancement, and redistribution. Specifically, CISA must perform outreach and engagement to bolster the security of open source software; support federal efforts to strengthen open source software security; coordinate with nonfederal entities on efforts to ensure long-term open source software security; serve as a public point of contact regarding open source software security for nonfederal entities; and support federal and nonfederal supply chain security efforts by encouraging efforts to bolster open source software security. CISA must (1) publish a framework, incorporating government, industry, and open source software community frameworks and best practices, for assessing the risk of open source software components; (2) update the framework at least annually; and (3) ensure, to the greatest extent practicable, that the framework is usable by the open source software community. The bill requires CISA to assess open source software components used by federal agencies based on the framework and provides for a pilot assessment of critical infrastructure. CISA's Cybersecurity Advisory Committee may establish a software security subcommittee. The Office of Management and Budget, in coordination with CISA, the Office of the National Cyber Director, and the General Services Administration, shall issue guidance on the responsibilities of the chief information officers at specified agencies regarding open source software.
This text is taken from the official record. PoliticalRepo does not editorialize.
Timeline
22 March 2023
Introduced
Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
Source: IntroReferral
22 March 2023
Introduced
Introduced in Senate
Source: IntroReferral
29 March 2023
Reported
Committee on Homeland Security and Governmental Affairs. Ordered to be reported without amendment favorably.
Source: Committee
16 May 2023
Calendars
Placed on Senate Legislative Calendar under General Orders. Calendar No. 76.
Source: Calendars
16 May 2023
Reported
Committee on Homeland Security and Governmental Affairs. Reported by Senator Peters with amendments. With written report No. 118-32.
Source: Committee
16 May 2023
Reported
Committee on Homeland Security and Governmental Affairs. Reported by Senator Peters with amendments. With written report No. 118-32.
Source: Committee
Votes
No vote records are attached yet.
Versions
- Reported to Senate · 16 May 2023 · Official file
- Introduced in Senate · 22 March 2023 · Official file
Documents
6 official files
Reported to Senate (text)
Reported to Senate · EN · 16 May 2023
Reported to Senate (PDF)
Reported to Senate · EN · 16 May 2023
Reported to Senate
summary · EN · 16 May 2023
Introduced in Senate (text)
Introduced in Senate · EN · 22 March 2023
Introduced in Senate (PDF)
Introduced in Senate · EN · 22 March 2023
Introduced in Senate
summary · EN · 22 March 2023
Sponsors
- Gary Peters · D · Sponsor
- Josh Hawley · R · Sponsor
- · ssga00 · Standing
Related records
No cross-record relationships stored yet.
Sources
PoliticalRepo is an index and interpretation layer, not the authoritative legal source.
- Official source: https://www.congress.gov/bill/118th-congress/senate-bill/917
- Open data entity: https://api.congress.gov/v3/bill/118/s/917
- us · 118-s-917 · source updated 27 May 2025