arrow_back Civic Audit
Share share

Mandatory Vulnerability Disclosure Programs for Government IT Contractors.

This law mandates that IT companies contracting with the federal government establish clear policies for reporting security vulnerabilities. The goal is to significantly enhance the security of government systems and protect public data from cyber threats. Crucially, individuals who report flaws in good faith (ethical hackers) are protected from civil lawsuits by the contractor.
Key points
All U.S. government IT contractors must implement public programs allowing anyone to report security flaws found in their systems.
Researchers reporting vulnerabilities are protected from civil liability if they act in good faith and follow the contractor's established policy.
Contractors must quickly acknowledge reports, communicate progress to researchers, and report critical vulnerabilities to CISA (Cybersecurity and Infrastructure Security Agency).
article Official text account_balance Process page notifications_active Track this Bill
gavel
Status:
Introduced
Record your position for audit.
Why does your vote on bills matter?
It creates raw, undeniable proof. Civic Will provides the permanent data to verify the Government's loyalty towards its citizens (explained here). Start recording it now.
Additional Information
Print number: 119_HR_1258
Sponsor: Rep. Lieu, Ted [D-CA-36]
Process start date: 2025-02-12