QuorumCivic. Hidden in plain sight Get the app
Bill intelligence

Federal contractors must open their code to security researchers

H.R. 1258 — Improving Contractor Cybersecurity Act · Filed by Ted Lieu (D-CA) · Introduced Feb 12, 2025 · Referred to committee

75%
Transparency
Typical bill: 82%
15/100
Hidden-provision risk
Typical bill: 15/100
Cybersecurity Accountability Mandate

Your members of Congress

Enter a ZIP to see where your representative and both senators stood on this bill.

Looked up on this device — your ZIP is never stored on our servers.

What it does

This bill requires federal contractors who provide information technology to the government to establish and maintain a public vulnerability disclosure policy—a formal process that allows security researchers to safely report software bugs and security flaws without legal risk. The policy must include clear instructions on how to report vulnerabilities, timelines for fixes, and a commitment not to sue researchers acting in good faith. Contractors must also report serious vulnerabilities to the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency (CISA) within 7 days of discovery.

Why we flagged it

The bill is a regulatory requirement imposed on federal IT contractors to establish transparent vulnerability disclosure processes and report security flaws to government agencies. It is fundamentally a governance and accountability measure, not a subsidy, tax provision, or commemorative act.

What the text implies

  • Contractors may face increased operational costs to establish and maintain vulnerability disclosure programs, including staffing, legal review, and communication infrastructure—costs that may be passed to the government or absorbed as reduced profit margins.
  • The requirement to report vulnerabilities to CISA within 7 days may create competitive disadvantage for contractors if vulnerability information is shared with competitors or if disclosure timelines are too aggressive for complex remediation.

The full analysis lists 5 implications of this text.

Who stands to gain

cybersecurity consulting firms; vulnerability management software vendors; IT compliance and audit service providers

Correlative observation from public records — not evidence of coordination or wrongdoing, and not financial advice.
This page is the record as of today. The app tells you when it changes.
Quorum analysis of the full bill text · 119th Congress · public record