Loading
Loading
Your feedback directly shapes Sporos.
Sign in to track your feedback history
Improving Contractor Cybersecurity Act This bill prohibits an executive agency from entering into a contract for information technology unless the contractor maintains a vulnerability disclosure policy (VDP) and program. The contractor must report to the Cybersecurity and Infrastructure Security Agency (CISA) of the Department of Homeland Security, within seven days after the VDP is published and on an ongoing basis as vulnerability reports are received, information regarding any valid or credible report of a not previously known public vulnerability on a system that uses commercial software or services that affect, or are likely to affect, other parties in government or industry once a patch or viable mitigation is available; andany other situation where the contractor determines it would be helpful or necessary to involve CISA.CISA must submit vulnerabilities to the MITRE Common Vulnerabilities and Exposures database and the National Institute of Standards and Technology National Vulnerability Database.
Introduced
Feb 12, 2025
Last Action
Feb 12, 2025
Session
119th Congress
Sponsors
1 primary · 0 co
Passage Probability
2% — Very Low
Introduced in House
Referred to the House Committee on Oversight and Government Reform.
Get a plain-English explanation of what this bill does, who it affects, and why it matters.
2%
Estimate based on legislative signals
See what factors are driving this score — cosponsor support, bipartisan backing, committee progress, and more.
Upgrade to ProReferred to the House Committee on Oversight and Government Reform.