Federal Contractor Cybersecurity Vulnerability Reduction Act of 2024
This bill requires federal contractors with significant contracts (over $250,000) or those managing government systems to implement standardized processes for reporting security vulnerabilities in their systems. It mandates updates to federal procurement rules (FAR and DFARS) to align with NIST cybersecurity guidelines, ensuring contractors systematically address security flaws in systems used for government contracts. The changes must follow industry best practices and existing federal standards for vulnerability disclosure. Contractors may be exempt only if a federal agency head justifies a national security waiver, requiring congressional notification.
Bill status
in committee
1 of 4 stages cleared
Introduction
Sep 2024
Committee Review
Floor Vote
President
Introduced Sep 11, 2024
Last action Dec 19, 2024
Floor votes
How they voted
No floor votes recorded yet.
Full legislative history
Actions timeline
Total actions
5
Key actions
2
Committee
3
Dec 19, 2024
Upper · Passed
Committee on Homeland Security and Governmental Affairs. Reported by Senator Peters with an amendment in the nature of a substitute. With written report No. 118-320.
upper
Nov 20, 2024
Upper · Passed
Committee on Homeland Security and Governmental Affairs. Ordered to be reported with an amendment in the nature of a substitute favorably.
upper
Sep 11, 2024
Committee
Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
upper
Sep 11, 2024
Introduced
Introduced in Senate
upper
1 primary · 1 co-sponsor
Sponsors
Ask Maddy
·
AI policy assistant
Ask Maddy about S 5028
Scope: US
Hi! I can help you understand S 5028. What would you like to know?
Try one of these
i
Maddy answers using official bill text and legislative records. Always verify before sharing.
Sources cited inline