S 5028 United States Senate · 118th Congress

Federal Contractor Cybersecurity Vulnerability Reduction Act of 2024

This bill requires federal contractors with significant contracts (over $250,000) or those managing government systems to implement standardized processes for reporting security vulnerabilities in their systems. It mandates updates to federal procurement rules (FAR and DFARS) to align with NIST cybersecurity guidelines, ensuring contractors systematically address security flaws in systems used for government contracts. The changes must follow industry best practices and existing federal standards for vulnerability disclosure. Contractors may be exempt only if a federal agency head justifies a national security waiver, requiring congressional notification.
Sub-Topics: Cybersecurity
Bill status in committee 1 of 4 stages cleared
Introduction
Sep 2024
Committee Review
Floor Vote
President
Introduced Sep 11, 2024 Last action Dec 19, 2024
Floor votes

How they voted

No floor votes recorded yet.
Full legislative history

Actions timeline

Total actions
5
Key actions
2
Committee
3
Dec 19, 2024
Upper · Passed
Committee on Homeland Security and Governmental Affairs. Reported by Senator Peters with an amendment in the nature of a substitute. With written report No. 118-320.
upper
Nov 20, 2024
Upper · Passed
Committee on Homeland Security and Governmental Affairs. Ordered to be reported with an amendment in the nature of a substitute favorably.
upper
Sep 11, 2024
Committee
Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
upper
Sep 11, 2024
Introduced
Introduced in Senate
upper
1 primary · 1 co-sponsor

Sponsors