Federal contractors must open their code to security researchers
H.R. 1258 — Improving Contractor Cybersecurity Act · Filed by Ted Lieu (D-CA) · Introduced Feb 12, 2025 · Referred to committee
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This bill requires federal contractors who provide information technology to the government to establish and maintain a public vulnerability disclosure policy—a formal process that allows security researchers to safely report software bugs and security flaws without legal risk. The policy must include clear instructions on how to report vulnerabilities, timelines for fixes, and a commitment not to sue researchers acting in good faith. Contractors must also report serious vulnerabilities to the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency (CISA) within 7 days of discovery.
Why we flagged it
The bill is a regulatory requirement imposed on federal IT contractors to establish transparent vulnerability disclosure processes and report security flaws to government agencies. It is fundamentally a governance and accountability measure, not a subsidy, tax provision, or commemorative act.
What the text implies
- Contractors may face increased operational costs to establish and maintain vulnerability disclosure programs, including staffing, legal review, and communication infrastructure—costs that may be passed to the government or absorbed as reduced profit margins.
- The requirement to report vulnerabilities to CISA within 7 days may create competitive disadvantage for contractors if vulnerability information is shared with competitors or if disclosure timelines are too aggressive for complex remediation.
The full analysis lists 5 implications of this text.
Who stands to gain
cybersecurity consulting firms; vulnerability management software vendors; IT compliance and audit service providers