Improving Contractor Cybersecurity Act
Summary
Improving Contractor Cybersecurity Act This bill prohibits an executive agency from entering into a contract for information technology unless the contractor maintains a vulnerability disclosure policy (VDP) and program. The contractor must report to the Cybersecurity and Infrastructure Security Agency (CISA) of the Department of Homeland Security, within seven days after the VDP is published, information regarding any valid or credible report of a not previously known public vulnerability on a system that uses commercial software or services that affect, or are likely to affect, other parties in government or industry once a patch or viable mitigation is available; and any other situation where the contractor determines it would be helpful or necessary to involve CISA. CISA must submit vulnerabilities to the MITRE Common Vulnerabilities and Exposures database and the National Institute of Standards and Technology National Vulnerability Database.
Bill status
in committee
1 of 4 stages cleared
Introduction
May 2021
Committee Review
Floor Vote
President
Introduced May 28, 2021
Last action May 28, 2021
Floor votes
How they voted
No floor votes recorded yet.
Full legislative history
Actions timeline
Total actions
2
Key actions
0
Committee
1
May 28, 2021
Committee
Referred to the House Committee on Oversight and Reform.
lower
May 28, 2021
Introduced
Introduced in House
lower
1 primary · 0 co-sponsors
Sponsors
Role
Legislator
Party
State
District
P
Ted Lieu
DDemocratic
Ask Maddy
·
AI policy assistant
Ask Maddy about HR 3608
Scope: US
Hi! I can help you understand HR 3608. What would you like to know?
Try one of these
i
Maddy answers using official bill text and legislative records. Always verify before sharing.
Sources cited inline