United States 119th Congress Status: In Committee 1 D cosponsors
Similar bills in 1 other state →

HR 1258 — Improving Contractor Cybersecurity Act

Last action — Referred to the House Committee on Oversight and Government Reform.

  1. ✓
    Introduced
  2. 2
    In Committee
  3. 3
    Passed House
  4. 4
    Passed Senate
  5. 5
    To Executive
  6. 6
    Enacted

This bill is in committee in the House. Introduced February 12, 2025. It must pass committee before a floor vote.

Next likely step: a committee vote, then a floor vote in the House.

Odds of enactment

Low chance

Based on the sponsor, cosponsors, and committee posture, this bill has a low chance of becoming law.

Upgrade to see the exact probability and what's driving it.

A statistical estimate from our own model of past outcomes — an insight, not a guarantee. Policymaking is volatile.

Prognosis

Stalled 18% · moderate confidence
  • In Committee

    Current position in the legislative process.

  • 1 sponsor

    1 primary, 0 co-sponsors signed on.

  • Single-party support

    Sponsorship is currently within one party (1 D).

  • Spreading across states

    Near-identical bills in 1 other state — cross-state momentum.

Based on stage, sponsorship breadth, committee status, recorded votes, and cross-state momentum — a description of the observable signals, not a prediction.

In plain language

HR 1258 aims to improve government oversight and reform processes.

This bill focuses on strengthening government oversight and promoting effective reform. By enhancing accountability, it seeks to improve public trust and governance.

Summary

Improving Contractor Cybersecurity ActThis bill prohibits an executive agency from entering into a contract for information technology unless the contractor maintains a vulnerability disclosure policy (VDP) and program.The contractor must report to the Cybersecurity and Infrastructure Security Agency (CISA) of the Department of Homeland Security, within seven days after the VDP is published and on an ongoing basis as vulnerability reports are received, information regardingany valid or credible report of a not previously known public vulnerability on a system that uses commercial software or services that affect, or are likely to affect, other parties in government or industry once a patch or viable mitigation is available; andany other situation where the contractor determines it would be helpful or necessary to involve CISA.CISA must submit vulnerabilities to the MITRE Common Vulnerabilities and Exposures database and the National Institute of Standards and Technology National Vulnerability Database.

Bill Text

Action History

  1. Introduced in House

  2. Introduced in House

  3. Referred to the House Committee on Oversight and Government Reform.

Sponsors

Sponsorship breakdown

Export CSV (upgrade) →

1 sponsors · 0 co-sponsors · 546 not signed on

Sponsors (1)

Co-sponsors (0)

None.

Not signed on (546)

546 members have not signed on to this bill.

Show all 546 →

"Not signed on" means a member has not sponsored or co-sponsored this bill — it does not imply opposition. Members flagged Voted No have a recorded No vote on this bill.

Whip count is in markup. Polling the chamber and every recorded vote this session. Only the first open is slow. It’s instant for you after this. Calling the roll · Tallying · Engrossing

Subjects

Similar bills in other states

Bills in other jurisdictions that match this one by MEANING — title, summary and subject, compared across every state we track. A strong signal the same policy is moving elsewhere.

Pick a bill from “Similar bills” above and click Compare text to see how its language differs from HR 1258.

Cross-referencing the record. Reading this bill against every other bill in the corpus by meaning, not keywords. Only the first open is slow. It’s instant for you after this. Matching · Ranking · Engrossing

Frequently asked questions

What does HR 1258 do?
Improving Contractor Cybersecurity ActThis bill prohibits an executive agency from entering into a contract for information technology unless the contractor maintains a vulnerability disclosure policy (VDP) and program.The contractor must report to the Cybersecurity and Infrastructure Security Agency (CISA) of the Department of Homeland Security, within seven days after the VDP is published and on an ongoing basis as vulnerability reports are received, information regardingany valid or credible report of a not previously known public vulnerability on a system that uses commercial software or services that affect, or are likely to affect, other parties in government or industry once a patch or viable mitigation is available; andany other situation where the contractor determines it would be helpful or necessary to involve CISA.CISA must submit vulnerabilities to the MITRE Common Vulnerabilities and Exposures database and the National Institute of Standards and Technology National Vulnerability Database.
Who sponsors HR 1258?
HR 1258 is sponsored by Lieu, Ted (Democratic).
What is the current status of HR 1258?
This bill is in committee in the House. Introduced February 12, 2025. It must pass committee before a floor vote.
Where can I track HR 1258?
Track HR 1258 free on One Click Politics — get push/email alerts when it moves.

Make your voice heard on HR 1258

Find the representatives who decide this bill and tell them where you stand — for yourself, or mobilize your whole list in one click with One Click Politics advocacy software.

Stay ahead of HR 1258

Last checked for changes 3 months ago · updated continuously

One Click Politics tracks every bill in Congress and all 50 states.

Track this bill →