HR 1258 — Improving Contractor Cybersecurity Act
Last action — Referred to the House Committee on Oversight and Government Reform.
-
✓Introduced
-
2In Committee
-
3Passed House
-
4Passed Senate
-
5To Executive
-
6Enacted
This bill is in committee in the House. Introduced February 12, 2025. It must pass committee before a floor vote.
Next likely step: a committee vote, then a floor vote in the House.
Odds of enactment
Low chanceBased on the sponsor, cosponsors, and committee posture, this bill has a low chance of becoming law.
Upgrade to see the exact probability and what's driving it.
A statistical estimate from our own model of past outcomes — an insight, not a guarantee. Policymaking is volatile.
Prognosis
-
In Committee
Current position in the legislative process.
-
1 sponsor
1 primary, 0 co-sponsors signed on.
-
Single-party support
Sponsorship is currently within one party (1 D).
-
Spreading across states
Near-identical bills in 1 other state — cross-state momentum.
Based on stage, sponsorship breadth, committee status, recorded votes, and cross-state momentum — a description of the observable signals, not a prediction.
In plain language
HR 1258 aims to improve government oversight and reform processes.
This bill focuses on strengthening government oversight and promoting effective reform. By enhancing accountability, it seeks to improve public trust and governance.
Summary
Improving Contractor Cybersecurity ActThis bill prohibits an executive agency from entering into a contract for information technology unless the contractor maintains a vulnerability disclosure policy (VDP) and program.The contractor must report to the Cybersecurity and Infrastructure Security Agency (CISA) of the Department of Homeland Security, within seven days after the VDP is published and on an ongoing basis as vulnerability reports are received, information regardingany valid or credible report of a not previously known public vulnerability on a system that uses commercial software or services that affect, or are likely to affect, other parties in government or industry once a patch or viable mitigation is available; andany other situation where the contractor determines it would be helpful or necessary to involve CISA.CISA must submit vulnerabilities to the MITRE Common Vulnerabilities and Exposures database and the National Institute of Standards and Technology National Vulnerability Database.
Bill Text
- Introduced Introduced in House Current html February 12, 2025
Action History
-
Introduced in House
-
Introduced in House
-
Referred to the House Committee on Oversight and Government Reform.
Sponsors
- Ted Lieu · Primary
Sponsorship breakdown
Export CSV (upgrade) →1 sponsors · 0 co-sponsors · 546 not signed on
Sponsors (1)
- Lieu, Ted Democratic
Co-sponsors (0)
None.
Not signed on (546)
546 members have not signed on to this bill.
Show all 546 →"Not signed on" means a member has not sponsored or co-sponsored this bill — it does not imply opposition. Members flagged Voted No have a recorded No vote on this bill.
Subjects
Similar bills in other states
Bills in other jurisdictions that match this one by MEANING — title, summary and subject, compared across every state we track. A strong signal the same policy is moving elsewhere.
- HR1255 Texas 85% Compare text
Pick a bill from “Similar bills” above and click Compare text to see how its language differs from HR 1258.
Frequently asked questions
- What does HR 1258 do?
- Improving Contractor Cybersecurity ActThis bill prohibits an executive agency from entering into a contract for information technology unless the contractor maintains a vulnerability disclosure policy (VDP) and program.The contractor must report to the Cybersecurity and Infrastructure Security Agency (CISA) of the Department of Homeland Security, within seven days after the VDP is published and on an ongoing basis as vulnerability reports are received, information regardingany valid or credible report of a not previously known public vulnerability on a system that uses commercial software or services that affect, or are likely to affect, other parties in government or industry once a patch or viable mitigation is available; andany other situation where the contractor determines it would be helpful or necessary to involve CISA.CISA must submit vulnerabilities to the MITRE Common Vulnerabilities and Exposures database and the National Institute of Standards and Technology National Vulnerability Database.
- Who sponsors HR 1258?
- HR 1258 is sponsored by Lieu, Ted (Democratic).
- What is the current status of HR 1258?
- This bill is in committee in the House. Introduced February 12, 2025. It must pass committee before a floor vote.
- Where can I track HR 1258?
- Track HR 1258 free on One Click Politics — get push/email alerts when it moves.
Make your voice heard on HR 1258
Find the representatives who decide this bill and tell them where you stand — for yourself, or mobilize your whole list in one click with One Click Politics advocacy software.
Stay ahead of HR 1258
Last checked for changes 3 months ago · updated continuously
One Click Politics tracks every bill in Congress and all 50 states.
Track this bill →