arrow_back Civic Audit
Share share

Enhanced Cybersecurity: Mandatory Vulnerability Disclosure for Federal Contractors

This Act mandates that companies working with the federal government implement a digital vulnerability disclosure policy. This aims to strengthen the security of information systems used by the government, indirectly protecting citizen data and critical infrastructure. These companies must actively solicit and address potential threats according to NIST guidelines.
Key points
Mandate for Federal Contractors: Companies with contracts at or above the simplified acquisition threshold must implement a security vulnerability disclosure policy.
Increased Data Security: This requirement aims to quickly identify and fix weaknesses in systems used for government contracts, enhancing overall digital security.
Standards and Guidelines: Vulnerability disclosure policies must align with NIST guidelines and industry best practices, including ISO standards.
Waivers: Agency heads can waive this requirement for national security or research purposes, provided they justify and report the decision to Congress.
article Official text account_balance Process page notifications_active Track this Bill
gavel
Status:
Expired
Record your position for audit.
Why does your vote on bills matter?
It creates raw, undeniable proof. Civic Will provides the permanent data to verify the Government's loyalty towards its citizens (explained here). Start recording it now.
Additional Information
Print number: 118_S_5028
Sponsor: Sen. Warner, Mark R. [D-VA]
Process start date: 2024-09-11