yourstate.us
15 U.S.C. § 278g–3e

Contractor compliance with coordinated disclosure of security vulnerabilities relating to agency Internet of Things devices

United States · Title 15 — COMMERCE AND TRADE · Status: effective

Get this as JSONEmbed this
Cite this
Citation
15 U.S.C. § 278g–3e, Contractor compliance with coordinated disclosure of security vulnerabilities relating to agency Internet of Things devices, United States, version 1 as recorded 2026-07-09, yourstate.us, https://yourstate.us/provision/440345
Permanent ID
ys:prov:440345@1
SHA-256
8dd714a823a714b399addb2d86873759e798f1095a7edc791745d86b05d03d7b

The hash is SHA-256 of this version's text, with every run of whitespace collapsed to a single space and the ends trimmed. The ID always leads back here, and checking it says whether the text you cited is still the current version.

Full text

The head of an agency is prohibited from procuring or obtaining, renewing a contract to procure or obtain, or using an Internet of Things device, if the Chief Information Officer of that agency determines during a review required by section 11319(b)(1)(C) of title 40 of a contract for such device that the use of such device prevents compliance with the standards and guidelines developed under section 278g–3b of this title or the guidelines published under section 278g–3c of this title with respect to such device. Notwithstanding section 1905 of title 41, the requirements under paragraph (1) shall apply to a contract or subcontract in amounts not greater than the simplified acquisition threshold. The head of an agency may waive the prohibition under subsection (a)(1) with respect to an Internet of Things device if the Chief Information Officer of that agency determines that— The Director of OMB shall establish a standardized process for the Chief Information Officer of each agency to follow in determining whether the waiver under paragraph (1) may be granted. Every 2 years during the 6-year period beginning on December 4, 2020, the Comptroller General of the United States shall submit to the Committee on Oversight and Reform of the House of Representatives, the Committee on Homeland Security of the House of Representatives, and the Committee on Homeland Security and Governmental Affairs of the Senate a report— that lists— Each report submitted under this subsection shall be submitted in unclassified form, but may include a classified annex that contains the information described under paragraph (1)(C). The prohibition under subsection (a)(1) shall take effect 2 years after December 4, 2020.

Legislative history

The public laws that enacted or amended this section. Tallies are for the whole bill as it passed each chamber — often an omnibus covering far more than this provision — not a vote on this section alone.

  • Enacted byPub. L. 116-207(H.R. 1668)2020-12-04
    IoT Cybersecurity Improvement Act of 2020
    House: no recorded tallySenate: no recorded tally