This bill aims to boost cybersecurity for government work by requiring federal contractors to set up a clear way for security researchers and the public to report software flaws—and for contractors to fix them. The rules must follow federal and industry guidelines, including NIST and ISO standards, and will be built into federal contracts through updates to the Federal Acquisition Regulation (FAR) .
The Office of Management and Budget will review current contract language and recommend updates, and then the FAR Council will add the new requirements. Agencies can grant limited waivers for national security or research reasons, with notice to Congress. No new funding is provided for this effort .
Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
Last progress May 22, 2025 (7 months ago)
Introduced on May 22, 2025 by Mark R. Warner