- H.R. 10171August 27, 2026
- H.R. 10156August 27, 2026
- H.R. 10172August 27, 2026
- H.R. 10160August 27, 2026
- H.R. 10181August 27, 2026
- H.R. 10176August 27, 2026
- H.Res. 1496August 27, 2026
- H.R. 10164August 27, 2026
- H.R. 10170August 27, 2026
- H.Res. 1494August 27, 2026
- H.R. 10163August 27, 2026
- H.R. 10157August 27, 2026
- Administration
- Agriculture
- Agriculture, Nutrition, And Forestry
- Appropriations
- Armed Services
- Banking, Housing, And Urban Affairs
- Budget
- Commerce, Science, And Transportation
- Education and Workforce
- Energy And Commerce
- Energy And Natural Resources
- Environment And Public Works
- Ethics
- Finance
- Financial Services
- Foreign Affairs
- Foreign Relations
- Health, Education, Labor, And Pensions
- Homeland Security
- Homeland Security And Governmental Affa…
- Indian Affairs
- Indian and Insular Affairs
- Intelligence
- Judiciary
- Natural Resources
- Oversight And Government Reform
- Permanent Select Intelligence
- Rules
- Rules And Administration
- Science, Space, And Technology
- Select Intelligence
- Small Business
- Small Business And Entrepreneurship
- Subcommittee on Aviation
- Subcommittee on Border Security and Enf…
- Subcommittee on Coast Guard and Maritim…
- Subcommittee on Commodity Markets, Digi…
- Subcommittee on Conservation, Research,…
- Subcommittee on Counterterrorism and In…
- Subcommittee on Cybersecurity and Infra…
- Subcommittee on Disability Assistance a…
- Subcommittee on Economic Development, P…
- Subcommittee on Economic Opportunity
- Subcommittee on Emergency Management an…
- Subcommittee on Energy and Mineral Reso…
- Subcommittee on Federal Lands
- Subcommittee on Forestry and Horticultu…
- Subcommittee on General Farm Commoditie…
- Subcommittee on Health
- Subcommittee on Highways and Transit
- Subcommittee on Livestock, Dairy, and P…
- Subcommittee on Nutrition and Foreign A…
- Subcommittee on Oversight and Investiga…
- Subcommittee on Oversight, Investigatio…
- Subcommittee on Railroads, Pipelines, a…
- Subcommittee on Transportation and Mari…
- Subcommittee on Water Resources and Env…
- Subcommittee on Water, Wildlife and Fis…
- Transportation And Infrastructure
- Veterans' Affairs
- Ways And Means

H.R. 1258
U.S. House•In House Committee
Summary
H.R. 1258, the Improving Contractor Cybersecurity Act, was introduced in the House on Feb 12, 2025 by Rep. Ted Lieu (D). It was referred to Oversight And Government Reform, and last saw action on Feb 12, 2025: Referred to the House Committee on Oversight and Government Reform.
Record
Text
H.R. 1258 has no co-sponsors and has not gone to a roll call.
hb1258/introduced-in-house.txt119 HR 1258 IH: Improving Contractor Cybersecurity ActU.S. House of Representatives2025-02-12text/xmlENPursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.I 119th CONGRESS 1st Session H. R. 1258 IN THE HOUSE OF REPRESENTATIVES February 12, 2025 Mr. Lieu introduced the following bill; which was referred to the Committee on Oversight and Government Reform A BILLTo amend title 41, United States Code, to require information technology contractors to maintain a vulnerability disclosure policy and program, and for other purposes.1.Short titleThis Act may be cited as the Improving Contractor Cybersecurity Act .2.Vulnerability disclosure policy and program required for information technology contractors(a)AmendmentChapter 47 of division C of subtitle I of title 41, United States Code, is amended by adding at the end the following new section:4715.Vulnerability disclosure policy and program required(a)Requirements for information technology contractorsThe head of an executive agency may not enter into a contract for information technology unless the contractor maintains or does the following:(1)A vulnerability disclosure policy for information technology that—(A)includes—(i)a description of which systems are in scope;(ii)the type of information technology testing for each system that is allowed (or specifically not authorized);(iii)if a contractor includes systems that host sensitive information in the vulnerability disclosure policy, the contractor shall determine whether to impose restrictions on accessing, copying, transferring, storing, using, and retaining such information, including by—(I)prohibiting sensitive information from being saved, stored, transferred, or otherwise accessed after initial discovery;(II)directing that sensitive information be viewed only to the extent required to identify a vulnerability and that the information not be retained; or(III)limiting use of information obtained from interacting with the systems or services to be explored by the researcher to activities directly related to reporting security vulnerabilities;(iv)a description of how an individual may submit a vulnerability report that includes—(I)the location of where to send the report, such as a web form or email address;(II)a description of the type of information necessary to find and analyze the vulnerability (such as a description, the location, and potential impact of the vulnerability, the technical information needed to reproduce the vulnerability, and any proof of concept); and(III)a clear statement—(aa)that any individual that submits a vulnerability report may do so anonymously; and(bb)on how and whether any incomplete submission is evaluated;(v)a commitment from the contractor that the contractor will not pursue civil action for any accidental, good faith violation of the vulnerability disclosure policy;(vi)a commitment from the contractor that if an individual acting in accordance with the vulnerability disclosure policy of the contractor is sued by a third party, the contractor will inform the public or the court that the individual was acting in compliance with the vulnerability disclosure policy;(vii)a statement that describes the time frame in which the individual that submits a report, if known, will receive a notification of receipt of the report and a description of what steps will be taken by the contractor during the remediation process; and(viii)a set of guidelines that establishes what type of activity by a researcher are acceptable and unacceptable; and(B)does not—(i)require the submission of personally identifiable information of a researcher; and(ii)limit testing solely to entities approved by the contractor but rather authorizes the public to search for and report any vulnerability.(2)A description of additional procedures that describe how the contractor will communicate with the researcher, and how and when any communication occurs.(3)A description of the target timelines for and tracking of the following:(A)Notification of receipt to the individual that submits the report, if known.(B)An initial assessment, such as determining whether any disclosed vulnerability is valid.(C)Resolution of a vulnerability, including notification of the outcome to the researcher.(4)A page on the website of the contractor that—(A)allows for the submission of vulnerabilities by anyone relating to the information technology;(B)lists the contact information, such as a phone number or email address for an individual or team responsible for reviewing any such submission under subparagraph (A); and(C)describes the process by which a review is conducted, including how long it will take for the contractor to respond to the researcher and whether or not monetary rewards will be paid to the reporter for identifying a vulnerability.(5)In the case of a discovered vulnerability that the contractor is not responsible for patching, the contractor shall submit the vulnerability to the responsible party or direct the researcher to the appropriate party.(b)Reporting requirements and metricsNot later than 7 days after the date on which the vulnerability disclosure policy described in subsection (a) is published, and on an ongoing basis as vulnerability reports are received, an information technology contractor shall report to the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security the following information:(1)Any valid or credible report of a not previously known public vulnerability (including any misconfiguration) on a system that uses commercial software or services that affect or are likely to affect other parties in government or industry once a patch or viable mitigation is available.(2)Any other situation where the contractor determines it would be helpful or necessary to involve the Cybersecurity and Infrastructure Security Agency.(c)CISA submission of vulnerabilitiesThe Cybersecurity and Infrastructure Security Agency shall communicate with and submit, as necessary, vulnerabilities to the MITRE Common Vulnerabilities and Exposures database and the National Institute of Standards and Technology National Vulnerability Database.(d)DefinitionsIn this section:(1)Executive agencyThe term executive agency has the meaning given that term in section 133.(2)ResearcherThe term researcher means the individual who submits a vulnerability report.(3)Information technologyThe term information technology has the meaning given that term in section 11101 of title 40..(b)Technical and conforming amendmentThe table of sections for chapter 47 of division C of subtitle I of title 41, United States Code, is amended by adding at the end the following new item:4715. Vulnerability disclosure policy and program required..(c)ApplicabilityThe amendments made by this section shall take effect on the date of the enactment of this section and shall apply to any contract entered into on or after such effective date.
Tracker
The tracker indicates the progress of this legislation as it moves through the legislative process.
- Introduced2025-02-12
- Passed House
- Passed Senate
- Conference
- To President
- Became Law
CRS Summary
The summaries are the Congressional Research Service’s, one per stage. Read them in full.
Introduced in House Feb 12, 2025
hb1258/introduced-in-house.mdShown Here:
Introduced in House (02/12/2025)
Sponsors
Rep. Ted Lieu (D) sponsors H.R. 1258 alone.
Committees
H.R. 1258 went before 1 committee: Oversight and Government Reform.

Actions
H.R. 1258 has taken 2 actions since Feb 12, 2025.
| Chamber | Action | |||
|---|---|---|---|---|
Feb 12, 2025 | House | Introduced in House | ||
Feb 12, 2025 | House | Referred to the House Committee on Oversight and Government Reform.Oversight and Government Reform Committee |
Votes
H.R. 1258 has not gone to a roll call.
Titles
H.R. 1258 goes by 3 titles, 1 of them short titles.
- Improving Contractor Cybersecurity Act — Display Title
- Improving Contractor Cybersecurity Act — Short Title(s) as Introduced
- To amend title 41, United States Code, to require information technology contractors to maintain a vulnerability disclosure policy and program, and for other purposes. — Official Title as Introduced
Classification
The Congressional Research Service files H.R. 1258 under Government Operations and Politics, one of its 31 policy areas, and gives it 3 legislative subjects.
CRS Subjects
CRS assigns every bill one policy area from its 31; H.R. 1258’s is Government Operations and Politics.
hr1258/policy-areas.txtLegislative Subjects
H.R. 1258 carries 3 of CRS’s legislative subjects, from Computers and information technology to Public contracts and procurement.
hr1258/subjects.txtSource: congress.gov · legiscan.com