<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Reported-in-Senate" dms-id="A1" public-private="public" slc-id="S1-DAV24J65-LVS-WK-FGW"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>118 S5028 RS: Federal Contractor Cybersecurity Vulnerability Reduction Act of 2024</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2024-12-19</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><calendar>Calendar No. 740</calendar><congress>118th CONGRESS</congress><session>2d Session</session><legis-num>S. 5028</legis-num><associated-doc role="report">[Report No. 118–320]</associated-doc><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20240911">September 11, 2024</action-date><action-desc><sponsor name-id="S327">Mr. Warner</sponsor> (for himself and <cosponsor name-id="S378">Mr. Lankford</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSGA00" added-display-style="italic" deleted-display-style="strikethrough">Committee on Homeland Security and Governmental Affairs</committee-name></action-desc></action><action stage="Reported-in-Senate"><action-date date="20241219" legis-day="20241216">December 19 (legislative day, December 16), 2024</action-date><action-desc>Reported by <sponsor name-id="S380">Mr. Peters</sponsor>, with an amendment</action-desc><action-instruction>Strike out all after the enacting clause and insert the part printed in italic</action-instruction></action><legis-type>A BILL</legis-type><official-title>To require Federal contractors to implement a vulnerability disclosure policy consistent with NIST guidelines, and for other purposes.</official-title></form><legis-body><section id="H0F487BCFA7D8433FBB3FBA81A10836DE" section-type="section-one" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Federal Contractor Cybersecurity Vulnerability Reduction Act of 2024</short-title></quote>.</text></section><section id="H042E59A0AFE34B3B8656339D49089EC9" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><enum>2.</enum><header>Federal contractor vulnerability disclosure policy</header><subsection id="HF1DAE0C1CE5C4F609999A1BB3D6BDFF7"><enum>(a)</enum><header>Recommendations</header><paragraph id="HF448B2923EFD48F7A7875816BB6A559D"><enum>(1)</enum><header>In general</header><text>Not later than 180 days after the date of the enactment of this Act, the Director of the Office of Management and Budget, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, the National Cyber Director, the Director of the National Institute of Standards and Technology, and any other appropriate head of an Executive department, shall—</text><subparagraph id="H9A5487B006324F729C0D841D7B9077D4"><enum>(A)</enum><text>review the Federal Acquisition Regulation (FAR) contract requirements and language for contractor vulnerability disclosure programs; and</text></subparagraph><subparagraph id="H45FEE15111CE403C9B719F7DDACDCBF2"><enum>(B)</enum><text>recommend updates to such requirements and language to the Federal Acquisition Regulation Council.</text></subparagraph></paragraph><paragraph id="H6240B456755F430595A0A5D5B74DCC4A"><enum>(2)</enum><header>Contents</header><text>The recommendations required by paragraph (1) shall include updates to such requirements designed to ensure that covered contractors implement a vulnerability disclosure policy consistent with National Institute of Standards and Technology (NIST) guidelines for contractors as required under section 5 of the IoT Cybersecurity Improvement Act of 2020 (<external-xref legal-doc="usc" parsable-cite="usc/15/278g-3c">15 U.S.C. 278g–3c</external-xref>).</text></paragraph></subsection><subsection id="H1DC7A1D5AFE249708DDFBFF5DCD68792"><enum>(b)</enum><header>Procurement requirements</header><text display-inline="yes-display-inline">Not later than 180 days after the date on which the recommended contract language developed pursuant to subsection (a) is received, the Federal Acquisition Regulation Council shall review the recommended contract language and amend the FAR as necessary to incorporate requirements for covered contractors to solicit and address information about potential security vulnerabilities relating to an information system owned or controlled by the contractor that is used in performance of a Federal contract. </text></subsection><subsection id="HCAD12AE38C874B5780FCB8128BD21F39"><enum>(c)</enum><header>Elements</header><text>The update to the FAR pursuant to subsection (b) shall—</text><paragraph id="HF73EC498F55E431A8F2EDF900F2E690B"><enum>(1)</enum><text display-inline="yes-display-inline">to the maximum extent practicable, align with the security vulnerability disclosure process and coordinated disclosure requirements relating to Federal information systems under sections 5 and 6 of the IoT Cybersecurity Improvement Act of 2020 (15 U.S.C. 278g–3c, 278g–3d); and</text></paragraph><paragraph id="HC33A10BCCC2A40A0B7C74E2642485821"><enum>(2)</enum><text>to the maximum extent practicable, be aligned with industry best practices and Standards 29147 and 30111 of the International Standards Organization (or any successor standard) or any other appropriate, relevant, and widely used standard.</text></paragraph></subsection><subsection id="H9BF14E11034D48EEB3D2FFB0A76F2593" display-inline="no-display-inline"><enum>(d)</enum><header>Waiver</header><text>The head of an agency may waive the security vulnerability disclosure policy requirement under subsection (b) if the agency Chief Information Officer—</text><paragraph display-inline="no-display-inline" commented="no" id="ida2c0e518c7504f1086606cc483ef8f0b"><enum>(1)</enum><text display-inline="yes-display-inline">determines that the waiver is necessary in the interest of national security or research purposes; and</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id9d471d9ab26c4e9d9950272c5e1083c4"><enum>(2)</enum><text> not later than 30 days after granting the waiver, submits a notification and justification, including information about the duration of the waiver, to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Oversight and Accountability of the House of Representatives. </text></paragraph></subsection><subsection id="HCE4D241CE8614453AB66CA33DD9197AF" commented="no"><enum>(e)</enum><header>Department of Defense Supplement to the Federal Acquisition Regulation</header><paragraph id="HDB518AC45C644D548C6CA4B8F2291A6D" commented="no"><enum>(1)</enum><header>Review</header><text display-inline="yes-display-inline">Not later than 180 days after the date of the enactment of this Act, the Secretary of Defense shall review the Department of Defense Supplement to the Federal Acquisition Regulation (DFARS) contract requirements and language for contractor vulnerability disclosure programs and develop updates to such requirements designed to ensure that covered contractors, to the maximum extent practicable, align with the security vulnerability disclosure process and coordinated disclosure requirements relating to Federal information systems under sections 5 and 6 of the IoT Cybersecurity Improvement Act of 2020 (15 U.S.C. 278g–3c, 278g–3d).</text></paragraph><paragraph id="HB56731DA40EF4CCB9458027386F3066C" commented="no"><enum>(2)</enum><header>Revisions</header><text display-inline="yes-display-inline">Not later than 180 days after the date on which the review required under subsection (a) is completed, the Secretary shall revise the DFARS as necessary to incorporate requirements for covered contractors to receive information about a potential security vulnerability relating to an information system owned or controlled by a contractor, in performance of the contract.</text></paragraph><paragraph id="H945B3C7DBC01491FA62ED44ACA3C759E" commented="no"><enum>(3)</enum><header>Elements</header><text>The Secretary shall ensure that the revision to the DFARS described in this subsection is carried out in accordance with the requirements of paragraphs (1) and (2) of subsection (c).</text></paragraph><paragraph id="H336485A692214BC4B800F91543B0EA11" commented="no"><enum>(4)</enum><header>Waiver</header><text display-inline="yes-display-inline">The Chief Information Officer of the Department of Defense may waive the security vulnerability disclosure policy requirements under paragraph (2) if the Chief Information Officer—</text><subparagraph commented="no" display-inline="no-display-inline" id="id71050a3eb88841cf91874eb1874295f5"><enum>(A)</enum><text display-inline="yes-display-inline">determines that the waiver is necessary in the interest of national security or research purposes; and</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id7fceaa5f4f954341bc9072d8fcc984fc"><enum>(B)</enum><text>not later than 30 days after granting the waiver, submits a notification and justification, including information about the duration of the waiver, to the Committee on Armed Services of the Senate and the Committee on Armed Services of the House of Representatives.</text></subparagraph></paragraph></subsection><subsection id="H7BE377484A9545DCA0D56B7C1AE78F19"><enum>(f)</enum><header>Definitions</header><text>In this section: </text><paragraph id="HFAF299DC5A624BBA92608E192A330A50"><enum>(1)</enum><header>Agency</header><text>The term <term>agency</term> has the meaning given the term in section 3502 of title 44, United States Code.</text></paragraph><paragraph id="H0379D093DBEA4E71953EC25B8B837A83"><enum>(2)</enum><header>Covered contractor</header><text display-inline="yes-display-inline">The term <term>covered contractor</term> means a contractor (as defined in section 7101 of title 41, United States Code)—</text><subparagraph id="HE5051BA79634400E94B7E547D0E81488"><enum>(A)</enum><text>whose contract is in an amount the same as or greater than the simplified acquisition threshold; or</text></subparagraph><subparagraph id="H2F2BCBB3BE204155A49111B7EDD4B689"><enum>(B)</enum><text>that uses, operates, manages, or maintains a Federal information system (as defined by section 11331 of title 40, United Stated Code) on behalf of an agency.</text></subparagraph></paragraph><paragraph id="H10630335C2554791903E1A2297B74338" commented="no"><enum>(3)</enum><header>Executive department</header><text>The term <term>Executive department</term> has the meaning given that term in section 101 of title 5, United States Code. </text></paragraph><paragraph id="H8904F6A201CF413C95B5D96B389A0FD8"><enum>(4)</enum><header>Security vulnerability</header><text>The term <term>security vulnerability</term> has the meaning given that term in section 2200 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/650">6 U.S.C. 650</external-xref>).</text></paragraph><paragraph id="HC168C37240984081B03DF886AB5246DA" commented="no"><enum>(5)</enum><header>Simplified acquisition threshold</header><text>The term <term>simplified acquisition threshold</term> has the meaning given that term in section 134 of title 41, United States Code. </text></paragraph></subsection></section></legis-body><legis-body display-enacting-clause="no-display-enacting-clause"><section id="id9467ed2d-4c33-412e-a729-a840401ed95a" section-type="section-one" changed="added" reported-display-style="italic" committee-id="SSGA00"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Federal Contractor Cybersecurity Vulnerability Reduction Act of 2024</short-title></quote>.</text></section><section id="id879e8937-a8d7-49b1-891d-d8c4d84fd3bb" changed="added" reported-display-style="italic" committee-id="SSGA00"><enum>2.</enum><header>Federal contractor vulnerability disclosure policy</header><subsection id="ida466d5c7-883f-4e43-b29e-bce1a23e2a25"><enum>(a)</enum><header>Recommendations</header><paragraph id="id81d3cedc-8f9c-4da3-b3b1-7e5072bc7be6"><enum>(1)</enum><header>In general</header><text>Not later than 180 days after the date of the enactment of this Act, the Director of the Office of Management and Budget, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, the National Cyber Director, the Director of the National Institute of Standards and Technology, and any other appropriate head of an Executive department, shall—</text><subparagraph id="id3d7dd30a-136e-468e-aa00-d719b61e2013"><enum>(A)</enum><text>review the Federal Acquisition Regulation (FAR) contract requirements and language for contractor vulnerability disclosure programs; and</text></subparagraph><subparagraph id="id5ac91e12-b420-4e4d-a91c-1fd61cf68feb"><enum>(B)</enum><text>recommend updates to such requirements and language to the Federal Acquisition Regulation Council.</text></subparagraph></paragraph><paragraph id="idbb2ec3cb-66af-4c66-8912-f4625550108f"><enum>(2)</enum><header>Contents</header><text>The recommendations required by paragraph (1) shall include updates to such requirements designed to ensure that covered contractors implement a vulnerability disclosure policy consistent with National Institute of Standards and Technology (NIST) guidelines for contractors as required under section 5 of the IoT Cybersecurity Improvement Act of 2020 (<external-xref legal-doc="usc" parsable-cite="usc/15/278g-3c">15 U.S.C. 278g–3c</external-xref>).</text></paragraph></subsection><subsection id="id49dbfd41-9ac2-4a4d-9fc7-d292dcb63134"><enum>(b)</enum><header>Procurement requirements</header><text display-inline="yes-display-inline">Not later than 180 days after the date on which the recommended contract language developed pursuant to subsection (a) is received, the Federal Acquisition Regulation Council shall review the recommended contract language and amend the FAR as necessary to incorporate requirements for covered contractors to solicit and address information about potential security vulnerabilities relating to an information system owned or controlled by the contractor that is used in performance of a Federal contract. </text></subsection><subsection id="id4ae141b4-715c-4830-8441-fc28f0fa0b4a"><enum>(c)</enum><header>Elements</header><text>The update to the FAR pursuant to subsection (b) shall—</text><paragraph id="id543461c2-caf7-48a5-82cb-f1659b0a5c37"><enum>(1)</enum><text display-inline="yes-display-inline">to the maximum extent practicable, align with the security vulnerability disclosure process and coordinated disclosure requirements relating to Federal information systems under sections 5 and 6 of the IoT Cybersecurity Improvement Act of 2020 (15 U.S.C. 278g–3c, 278g–3d); and</text></paragraph><paragraph id="idca8da3d0-4105-40c6-adbf-34fc02126456"><enum>(2)</enum><text>to the maximum extent practicable, be aligned with industry best practices and Standards 29147 and 30111 of the International Standards Organization (or any successor standard) or any other appropriate, relevant, and widely used standard.</text></paragraph></subsection><subsection id="id77be1805-79db-4982-b3dc-4cf0460cddf7" display-inline="no-display-inline"><enum>(d)</enum><header>Waiver</header><text>The head of an agency may waive the security vulnerability disclosure policy requirement under subsection (b) if the agency Chief Information Officer—</text><paragraph display-inline="no-display-inline" commented="no" id="id9246a4b5-b481-4130-be6f-0d72ba309c32"><enum>(1)</enum><text display-inline="yes-display-inline">determines that the waiver is necessary in the interest of national security or research purposes; and</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id167981fd-d7d0-43d3-805b-fb7548cd5549"><enum>(2)</enum><text> not later than 30 days after granting the waiver, submits a notification and justification, including information about the duration of the waiver, to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Oversight and Accountability of the House of Representatives. </text></paragraph></subsection><subsection id="id2bceaca6-44a3-45a0-beb2-a44c76aeeb91"><enum>(e)</enum><header>Definitions</header><text>In this section: </text><paragraph id="id57543895-2561-47c2-8553-1e7f83a58e84"><enum>(1)</enum><header>Agency</header><text>The term <term>agency</term> has the meaning given the term in section 3502 of title 44, United States Code.</text></paragraph><paragraph id="id1f905957-25f8-4d89-8e2c-c957255896f5"><enum>(2)</enum><header>Covered contractor</header><text display-inline="yes-display-inline">The term <term>covered contractor</term> means a contractor (as defined in section 7101 of title 41, United States Code)—</text><subparagraph id="id68165fc4-3bed-4e52-b962-fbf434a191fb"><enum>(A)</enum><text>whose contract is in an amount the same as or greater than the simplified acquisition threshold; or</text></subparagraph><subparagraph id="id3a3bd910-058b-4958-8239-e0330709cce1"><enum>(B)</enum><text>that uses, operates, manages, or maintains a Federal information system (as defined by section 11331 of title 40, United Stated Code) on behalf of an agency.</text></subparagraph></paragraph><paragraph id="idb86cb6e7-df09-4d0c-8b77-9af64c60ad1f" commented="no"><enum>(3)</enum><header>Executive department</header><text>The term <term>Executive department</term> has the meaning given that term in section 101 of title 5, United States Code. </text></paragraph><paragraph id="id5a47202e-b397-43e4-a2d5-8837f3635927"><enum>(4)</enum><header>Security vulnerability</header><text>The term <term>security vulnerability</term> has the meaning given that term in section 2200 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/650">6 U.S.C. 650</external-xref>).</text></paragraph><paragraph id="id521a3ed9-3444-4d7d-af7c-6c37aeea4637" commented="no" display-inline="no-display-inline"><enum>(5)</enum><header>Simplified acquisition threshold</header><text>The term <term>simplified acquisition threshold</term> has the meaning given that term in section 134 of title 41, United States Code. </text></paragraph></subsection></section><section id="id93ff01e1af72486b89441d09c4788783" changed="added" reported-display-style="italic" committee-id="SSGA00"><enum>3.</enum><header>No additional funding</header><text display-inline="no-display-inline">No additional funds are authorized to be appropriated for the purpose of carrying out this Act. </text></section></legis-body><endorsement><action-date date="20241219" legis-day="20241216">December 19 (legislative day, December 16), 2024</action-date><action-desc>Reported with an amendment</action-desc></endorsement></bill> 

