22 U.S.C. § 10306
Vulnerability disclosure policy and bug bounty program report
United States · Title 22 — FOREIGN RELATIONS AND INTERCOURSE · Status: effective
Cite this
- Citation
- 22 U.S.C. § 10306, Vulnerability disclosure policy and bug bounty program report, United States, version 1 as recorded 2026-07-09, yourstate.us, https://yourstate.us/provision/458945
- Permanent ID
ys:prov:458945@1- SHA-256
7e2c3b2299fd1991bf8c0985df28d3d3bbf04cb859b9bce37582233a60c7df85
The hash is SHA-256 of this version's text, with every run of whitespace collapsed to a single space and the ends trimmed. The ID always leads back here, and checking it says whether the text you cited is still the current version.
Full text
In this section:
The term “bug bounty program” means a program under which an approved individual, organization, or company is temporarily authorized to identify and report vulnerabilities of internet-facing information technology of the Department in exchange for compensation.
The term “information technology” has the meaning given such term in section 11101 of title 40.
Not later than 180 days after December 23, 2022, the Secretary shall design, establish, and make publicly known a Vulnerability Disclosure Policy (referred to in this section as the “VDP”) to improve Department cybersecurity by—
Not later than 180 days after the establishment of the VDP pursuant to paragraph (1), and annually thereafter for the following 5 years, the Secretary shall submit a report on the VDP to the Committee on Foreign Relations of the Senate, the Committee on Homeland Security and Governmental Affairs of the Senate, the Select Committee on Intelligence of the Senate, the Committee on Foreign Affairs of the House of Representatives, the Committee on Homeland Security of the House of Representatives, and the Permanent Select Committee on Intelligence of the House of Representatives that includes information relating to—
Not later than 180 days after December 23, 2022, the Secretary shall submit a report to Congress that describes any ongoing efforts by the Department or a third-party vendor under contract with the Department to establish or carry out a bug bounty program that identifies security vulnerabilities of internet-facing information technology of the Department.
Not later than 180 days after the date on which any bug bounty program is established, the Secretary shall submit a report to the Committee on Foreign Relations of the Senate, the Committee on Homeland Security and Governmental Affairs of the Senate, the Committee on Foreign Affairs of the House of Representatives, and the Committee on Homeland Security of the House of Representatives regarding such program, including information relating to—
the number of approved individuals, organizations, or companies involved in such program, disaggregated by the number of approved individuals, organizations, or companies that—
Legislative history
The public laws that enacted or amended this section. Tallies are for the whole bill as it passed each chamber — often an omnibus covering far more than this provision — not a vote on this section alone.
- James M. Inhofe National Defense Authorization Act for Fiscal Year 2023