[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"current-user-roles":3,"user-subscription":3,"bill:119-hr-1258":4},null,{"bill":5,"indexable":180,"summaries":181,"cosponsors":187,"cosponsorSlugs":188,"actions":189,"amendments":208,"amendmentSponsorSlugs":209,"linkages":210,"sponsorSlug":211},{"statusDate":6,"sponsor":7,"updateDate":15,"cboCostEstimates":16,"originChamber":17,"congress":18,"isByRequest":19,"title":20,"createdAt":21,"committeeReports":22,"cosponsorCount":23,"onBehalfOfSponsor":3,"adminOverride":3,"amendmentCount":23,"actionCount":24,"popularTitle":3,"laws":3,"billType":25,"introducedDate":6,"committees":26,"congressGovUrl":27,"constitutionalAuthority":28,"policyArea":29,"deletedAt":3,"latestAction":30,"billNumber":32,"cosponsorCountIncludingWithdrawn":23,"status":33,"shortTitle":20,"officialTitle":34,"keyMilestoneCount":35,"subjects":36,"updatedAt":40,"policyAreaLower":41,"searchTokens":42,"committeeCodes":179},"2025-02-12",{"firstName":8,"lastName":9,"district":10,"fullName":11,"state":12,"party":13,"bioguideId":14},"Ted","Lieu","36","Rep. Lieu, Ted [D-CA-36]","CA","D","L000582","2025-05-06T13:51:06Z",[],"House",119,false,"Improving Contractor Cybersecurity Act","2026-05-11T15:31:07.120Z",[],0,3,"hr",[],"https:\u002F\u002Fwww.congress.gov\u002Fbill\u002F119th-congress\u002Fhouse-bill\u002F1258","\u003Cpre>\n[Congressional Record Volume 171, Number 29 (Wednesday, February 12, 2025)]\n[House]\nFrom the Congressional Record Online through the Government Publishing Office [\u003Ca href=\"https:\u002F\u002Fwww.gpo.gov\">www.gpo.gov\u003C\u002Fa>]\nBy Mr. LIEU:\nH.R. 1258.\nCongress has the power to enact this legislation pursuant\nto the following:\nU.S. Const., Art. 1, Sec. 8\n[Page H677]\n\u003C\u002Fpre>","Government Operations and Politics",{"date":6,"text":31},"Referred to the House Committee on Oversight and Government Reform.",1258,"in_committee","To amend title 41, United States Code, to require information technology contractors to maintain a vulnerability disclosure policy and program, and for other purposes.",2,[37,38,39],"Computers and information technology","Government information and archives","Public contracts and procurement","2026-05-22T16:49:28.768Z","government operations and politics",[43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95,96,97,98,99,100,101,102,103,104,105,106,107,108,109,110,111,112,113,114,115,116,117,118,119,120,121,122,123,124,125,126,127,128,129,130,131,132,133,134,135,136,137,138,139,140,141,142,143,144,145,146,147,148,149,150,151,152,153,154,155,156,157,158,159,160,161,162,163,164,165,166,167,168,169,170,171,172,173,174,175,176,177,178,10],"improving","im","imp","impr","impro","improv","improvi","improvin","contractor","co","con","cont","contr","contra","contrac","contract","contracto","cybersecurity","cy","cyb","cybe","cyber","cybers","cyberse","cybersec","cybersecu","cybersecur","cybersecuri","cybersecurit","act","to","amend","am","ame","amen","title","ti","tit","titl","41","united","un","uni","unit","unite","states","st","sta","stat","state","code","cod","require","re","req","requ","requi","requir","information","in","inf","info","infor","inform","informa","informat","informati","informatio","technology","te","tec","tech","techn","techno","technol","technolo","technolog","contractors","maintain","ma","mai","main","maint","mainta","maintai","vulnerability","vu","vul","vuln","vulne","vulner","vulnera","vulnerab","vulnerabi","vulnerabil","vulnerabili","vulnerabilit","disclosure","di","dis","disc","discl","disclo","disclos","disclosu","disclosur","policy","po","pol","poli","polic","and","program","pr","pro","prog","progr","progra","for","other","ot","oth","othe","purposes","pu","pur","purp","purpo","purpos","purpose","rep","lieu","li","lie","ted","ca",[],true,[182],{"versionCode":183,"actionDate":6,"actionDesc":184,"text":185,"updateDate":186},"00","Introduced in House","\u003Cp>\u003Cstrong>Improving Contractor Cybersecurity Act\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This bill prohibits an executive agency from entering into a contract for information technology unless the contractor maintains a vulnerability disclosure policy (VDP) and program.\u003C\u002Fp>\u003Cp>The contractor must report to the Cybersecurity and Infrastructure Security Agency (CISA) of the Department of Homeland Security, within seven days after the VDP is published&nbsp;and on an ongoing basis as vulnerability reports are received, information regarding\u003C\u002Fp>\u003Cul>\u003Cli>any valid or credible report of a not previously known public vulnerability on a system that uses commercial software or services that affect, or are likely to affect, other parties in government or industry once a patch or viable mitigation is available; and\u003C\u002Fli>\u003Cli>any other situation where the contractor determines it would be helpful or necessary to involve CISA.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>CISA must submit vulnerabilities to the MITRE Common Vulnerabilities and Exposures database and the National Institute of Standards and Technology National Vulnerability Database.\u003C\u002Fp>","2025-05-06T13:44:02Z",[],{},[190,199,205],{"actionDate":6,"actionDateTime":3,"text":31,"type":191,"actionCode":192,"sourceSystem":193,"committees":195,"recordedVotes":3,"calendarNumber":3,"sequenceIndex":23,"isKeyMilestone":19},"IntroReferral","H11100",{"code":35,"name":194},"House floor actions",[196],{"name":197,"systemCode":198},"Oversight and Government Reform Committee","hsgo00",{"actionDate":6,"actionDateTime":3,"text":184,"type":191,"actionCode":200,"sourceSystem":201,"committees":3,"recordedVotes":3,"calendarNumber":3,"sequenceIndex":204,"isKeyMilestone":180},"Intro-H",{"code":202,"name":203},9,"Library of Congress",1,{"actionDate":6,"actionDateTime":3,"text":184,"type":191,"actionCode":206,"sourceSystem":207,"committees":3,"recordedVotes":3,"calendarNumber":3,"sequenceIndex":35,"isKeyMilestone":180},"1000",{"code":202,"name":203},[],{},[],"ted-lieu"]