<?xml version="1.0" encoding="UTF-8"?><BillSummaries>
    <item congress="119" measure-type="hr" measure-number="1258" measure-id="id119hr1258" originChamber="HOUSE" orig-publish-date="2025-02-12" update-date="2025-05-06">
        <title>Improving Contractor Cybersecurity Act</title>
        <summary summary-id="id119hr1258v00" currentChamber="HOUSE" update-date="2025-05-06">
            <action-date>2025-02-12</action-date>
            <action-desc>Introduced in House</action-desc>
            <summary-text><![CDATA[<p><strong>Improving Contractor Cybersecurity Act</strong></p><p>This bill prohibits an executive agency from entering into a contract for information technology unless the contractor maintains a vulnerability disclosure policy (VDP) and program.</p><p>The contractor must report to the Cybersecurity and Infrastructure Security Agency (CISA) of the Department of Homeland Security, within seven days after the VDP is published&nbsp;and on an ongoing basis as vulnerability reports are received, information regarding</p><ul><li>any valid or credible report of a not previously known public vulnerability on a system that uses commercial software or services that affect, or are likely to affect, other parties in government or industry once a patch or viable mitigation is available; and</li><li>any other situation where the contractor determines it would be helpful or necessary to involve CISA.</li></ul><p>CISA must submit vulnerabilities to the MITRE Common Vulnerabilities and Exposures database and the National Institute of Standards and Technology National Vulnerability Database.</p>]]></summary-text>
        </summary>
    </item>
    <dublinCore xmlns:dc="http://purl.org/dc/elements/1.1/">
        <dc:format>text/xml</dc:format>
        <dc:language>EN</dc:language>
        <dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
        <dc:contributor>Congressional Research Service, Library of Congress</dc:contributor>
        <dc:description>This file contains bill summaries for federal legislation. A bill summary describes the most significant provisions of a piece of legislation and details the effects the legislative text may have on current law and federal programs. Bill summaries are authored by the Congressional Research Service (CRS) of the Library of Congress. As stated in Public Law 91-510 (2 USC 166 (d)(6)), one of the duties of CRS is "to prepare summaries and digests of bills and resolutions of a public general nature introduced in the Senate or House of Representatives". For more information, refer to the User Guide that accompanies this file.</dc:description>
    </dublinCore>
</BillSummaries>
