Title 15 › Chapter 7— NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY › § 278g–3c
Create and publish guidelines within 180 days after December 4, 2020. The Director of the Institute must work with cybersecurity researchers, private industry experts, and the Secretary to write rules about how to report, share, publish, and receive information about security vulnerabilities in systems the government owns or controls, including Internet of Things devices, and how to report when those problems are fixed. The rules must also tell contractors and their subcontractors what to do when they get reports of possible vulnerabilities and how to share information about fixes. The guidance should follow industry best practices and align with ISO Standards 29147 and 30111 (or their successors) or other common standards, and be consistent with related federal policies. The guidelines must include example content showing what information contractors should report. The Director of OMB will oversee putting the guidelines into practice, and the Secretary, with OMB, will run the implementation and give technical and operational help.
Full Legal Text
Commerce and Trade, Source: USLM XML via OLRC
Legislative History
Reference
Citation
15 U.S.C. § 278g–3c
Title 15, Commerce and Trade
Last Updated
Apr 3, 2026
Release point: 119-73not60