Congress mandates independent hacking of voting machines to find flaws
H.R. 6315 — SECURE IT Act · Filed by David Valadao (R-CA) · 1 cosponsor · Introduced Nov 25, 2025 · Referred to committee
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This bill creates a 5-year pilot program requiring voting machine manufacturers to allow independent cybersecurity researchers to test their systems for vulnerabilities, with a coordinated process for reporting and fixing security flaws. Researchers get legal protection from lawsuits and copyright claims when conducting authorized testing, and critical vulnerabilities must be patched and sent to election officials within defined timelines.
Why we flagged it
The bill's core function is to mandate independent penetration testing and vulnerability disclosure for voting systems as a condition of certification. It is a regulatory requirement, not a subsidy or carve-out, and directly addresses election infrastructure security.
What the text implies
- Vendors may face increased compliance costs and operational burden to support researcher access and expedited patch review, potentially raising barriers to entry for smaller vendors.
- The 180-day confidentiality window before public disclosure to CISA may delay awareness of critical vulnerabilities in deployed systems, creating a window where flaws remain unfixed in live elections.
The full analysis lists 4 implications of this text.
Who stands to gain
cybersecurity testing firms and laboratories; election system vendors (through expedited certification pathways); IT security consultancies