Open Eye

A plain-language record of the U.S. government

117th Congress · House

DHS Software Supply Chain Risk Management Act of 2021

Subjects: Administrative law and regulatory procedures · Computer security and identity theft · Computers and information technology · Congressional oversight · Department of Homeland Security · Government information and archives · Government studies and investigations · Public contracts and procurement

In plain language

  • House bill in the 117th Congress.
  • Requires the Management Directorate of DHS (DHS) to issue guidance regarding new and existing contracts relating.
  • House passed it on Oct 20, 2021 (substantive).
Official summary (Congressional Research Service)

DHS Software Supply Chain Risk Management Act of 2021 This bill requires the Management Directorate of the Department of Homeland Security (DHS) to issue guidance regarding new and existing contracts relating to the procurement of information and communications technology or services. The bill requires contractors to submit to DHS a bill of materials, a certification that each item in the bill of materials is free from certain security vulnerabilities or defects affecting the security of the end product or service, a notification of any identified vulnerability or defect, and a plan to mitigate, repair, or resolve any identified vulnerability or defect. The Government Accountability Office must report to specified congressional committees with (1) a review of this bill's implementation; (2) information regarding DHS engagement with industry; (3) an assessment of how guidance issued pursuant to this bill complies with Executive Order 14208, relating to improving the nation's cybersecurity; and (4) any recommendations related to improving the supply chain for covered contracts.

View this measure on congress.gov

Roll-call votes on this measure