HR 5255 United States House · 118th Congress

Federal Cybersecurity Vulnerability Reduction Act of 2023

HR 5255 requires federal contractors with large contracts (over $250,000) to implement vulnerability disclosure policies aligned with NIST cybersecurity guidelines. It directs the Office of Management and Budget to update the Federal Acquisition Regulation (FAR) and Defense Department rules (DFARS) within 180 days to mandate that contractors report security flaws in their systems. The policy excludes small contractors below the simplified acquisition threshold and allows national security waivers for specific cases. This law aims to standardize how contractors handle and disclose cybersecurity risks across federal systems.
Sub-Topics: Cybersecurity
Bill status in committee 1 of 4 stages cleared
Introduction
Aug 2023
Committee Review
Floor Vote
President
Introduced Aug 22, 2023 Last action May 15, 2024
Floor votes

How they voted

No floor votes recorded yet.
Full legislative history

Actions timeline

Total actions
4
Key actions
1
Committee
2
May 15, 2024
Lower · Passed
Committee Consideration and Mark-up Session Held
lower
Aug 22, 2023
Committee
Referred to the Committee on Oversight and Accountability, and in addition to the Committee on Armed Services, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.
lower
Aug 22, 2023
Introduced
Introduced in House
lower
1 primary · 0 co-sponsors

Sponsors

Role
Legislator
Party
State
District
P
Photo of Nancy Mace
Nancy Mace
RRepublican
SC
1