Federal Cybersecurity Vulnerability Reduction Act of 2023
HR 5255 requires federal contractors with large contracts (over $250,000) to implement vulnerability disclosure policies aligned with NIST cybersecurity guidelines. It directs the Office of Management and Budget to update the Federal Acquisition Regulation (FAR) and Defense Department rules (DFARS) within 180 days to mandate that contractors report security flaws in their systems. The policy excludes small contractors below the simplified acquisition threshold and allows national security waivers for specific cases. This law aims to standardize how contractors handle and disclose cybersecurity risks across federal systems.
Bill status
in committee
1 of 4 stages cleared
Introduction
Aug 2023
Committee Review
Floor Vote
President
Introduced Aug 22, 2023
Last action May 15, 2024
Floor votes
How they voted
No floor votes recorded yet.
Full legislative history
Actions timeline
Total actions
4
Key actions
1
Committee
2
May 15, 2024
Lower · Passed
Committee Consideration and Mark-up Session Held
lower
Aug 22, 2023
Committee
Referred to the Committee on Oversight and Accountability, and in addition to the Committee on Armed Services, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.
lower
Aug 22, 2023
Introduced
Introduced in House
lower
1 primary · 0 co-sponsors
Sponsors
Role
Legislator
Party
State
District
P
Nancy Mace
RRepublican
Ask Maddy
·
AI policy assistant
Ask Maddy about HR 5255
Scope: US
Hi! I can help you understand HR 5255. What would you like to know?
Try one of these
i
Maddy answers using official bill text and legislative records. Always verify before sharing.
Sources cited inline