Improving Contractor Cybersecurity Act
HR 1258, the Improving Contractor Cybersecurity Act, requires federal information technology contractors to implement standardized vulnerability disclosure policies. These policies must allow anonymous reporting of security flaws, prohibit lawsuits against researchers acting in good faith, and provide clear timelines for responding to reports and fixing issues. Contractors must also report significant new vulnerabilities to the Cybersecurity and Infrastructure Security Agency (CISA) within 7 days, and CISA will submit verified vulnerabilities to national databases like the National Vulnerability Database. The law directly affects companies bidding on federal IT contracts, mandating transparent security reporting processes to protect government and public systems.
Bill status
in committee
1 of 4 stages cleared
Introduction
Feb 2025
Committee Review
Floor Vote
President
Introduced Feb 12, 2025
Last action Feb 12, 2025
Floor votes
How they voted
No floor votes recorded yet.
Full legislative history
Actions timeline
Total actions
2
Key actions
0
Committee
1
Feb 12, 2025
Committee
Referred to the House Committee on Oversight and Government Reform.
lower
Feb 12, 2025
Introduced
Introduced in House
lower
1 primary · 0 co-sponsors
Sponsors
Role
Legislator
Party
State
District
P
Ted Lieu
DDemocratic
Ask Maddy
·
AI policy assistant
Ask Maddy about HR 1258
Scope: US
Hi! I can help you understand HR 1258. What would you like to know?
Try one of these
i
Maddy answers using official bill text and legislative records. Always verify before sharing.
Sources cited inline