H.R. 2980House117th Congress (2021-2023)In Committee

Cybersecurity Vulnerability Remediation Act

Introduced May 4, 2021

AI-Generated Summary

Updated February 8, 2026 at 2:37 AM UTC

The Cybersecurity Vulnerability Remediation Act amends the Homeland Security Act of 2002 to define “cybersecurity vulnerability,” require the Department of Homeland Security to develop and share actionable protocols for fixing such vulnerabilities, and establish reporting and incentive programs. It impacts DHS (including CISA), industry, academia, and other stakeholders that operate information and industrial control systems.

Key Provisions

  • Adds a definition of “cybersecurity vulnerability” by referencing the Cybersecurity Information Sharing Act of 2015.
  • Directs the DHS Director to identify, develop, and disseminate protocols to mitigate vulnerabilities, especially for unsupported software or hardware.
  • Requires the DHS Director to submit a detailed report within one year on how vulnerability disclosures and mitigation protocols are coordinated and shared.
  • Authorizes the Under Secretary for Science and Technology, in consultation with CISA, to create an incentive‑based competition for identifying remediation solutions for vulnerabilities.
  • Makes technical and clerical updates to section headings and numbering in the Homeland Security Act (e.g., renaming sections related to .gov domain, joint cyber planning office, and cybersecurity programs).

Legislative Activity

Stay on top of the latest movement without scrolling through every action

13 earlier actions
SenateIntro Referral Latest Action

Received in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs.

July 21, 2021

View full timeline
HouseIntro Referral

Introduced in House

May 4, 2021

HouseIntro Referral

Referred to the House Committee on Homeland Security.

May 4, 2021

HouseCommittee

Referred to the Subcommittee on Cybersecurity, Infrastructure Protection, and Innovation.

May 5, 2021

HouseCommittee

Subcommittee on Cybersecurity, Infrastructure Protection, and Innovation Discharged.

May 18, 2021

HouseCommittee

Committee Consideration and Mark-up Session Held.

May 18, 2021

HouseCommittee

Ordered to be Reported (Amended).

May 18, 2021

HouseFloor

Ms. Clarke (NY) moved to suspend the rules and pass the bill, as amended.

July 20, 2021 • 1:22 PM

HouseFloor

Considered under suspension of the rules. (consideration: CR H3696-3701; text: CR H3696-3697)

July 20, 2021 • 1:22 PM

HouseFloor

DEBATE - The House proceeded with forty minutes of debate on H.R. 2980.

July 20, 2021 • 1:22 PM

HouseFloor

At the conclusion of debate, the Yeas and Nays were demanded and ordered. Pursuant to the provisions of clause 8, rule XX, the Chair announced that further proceedings on the motion would be postponed.

July 20, 2021 • 1:34 PM

HouseFloor

Pursuant to the provisions of H. Res. 535, proceedings on H.R. 2980 are considered vacated.

July 20, 2021 • 4:45 PM

HouseFloor

Passed/agreed to in House: Pursuant to section 7 of H. Res. 535, and the motion offered by Mr. Hoyer, the following bills passed under suspension of the rules: H.R. 678; H.R. 1036; H.R. 1079, as amended; H.R. 1158; H.R. 1250; H.R. 1754; H.R. 1833, as amended; H.R. 1850; H.R. 1871; H.R. 1877, as amended; H.R. 1893; H.R. 1895; H.R. 2118; H.R. 2795, as amended; H.R. 2928; H.R. 2980, as amended; H.R. 3003; H.R. 3138, as amended; H.R. 3223; H.R. 3263; and H.R. 3264; and the following resolutions were agreed to under suspension of the rules: H. Res. 277; and H. Res. 294.(consideration: CR H3715-3730; text: CR H3722)

July 20, 2021 • 4:45 PM

HouseFloor

Pursuant to section 7 of H. Res. 535, and the motion offered by Mr. Hoyer, the following bills passed under suspension of the rules: H.R. 678; H.R. 1036; H.R. 1079, as amended; H.R. 1158; H.R. 1250; H.R. 1754; H.R. 1833, as amended; H.R. 1850; H.R. 1871; H.R. 1877, as amended; H.R. 1893; H.R. 1895; H.R. 2118; H.R. 2795, as amended; H.R. 2928; H.R. 2980, as amended; H.R. 3003; H.R. 3138, as amended; H.R. 3223; H.R. 3263; and H.R. 3264; and the following resolutions were agreed to under suspension of the rules: H. Res. 277; and H. Res. 294. (consideration: CR H3715-3730; text: CR H3722)

July 20, 2021 • 4:45 PM

SenateIntro Referral

Received in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs.

July 21, 2021

Floor Debate

8 members

What members said about H.R. 2980 on the floor

5 Republicans3 Democrats
Sheila Jackson Lee
Rep. Sheila Jackson LeeD-TX-18 · Jul 20, 2021

Madam Speaker, I thank the gentlewoman from New York for her leadership, and I thank the ranking member of the full committee and the chair of the full committee for bringing these matters to the…

Yvette D. Clarke
Rep. Yvette D. ClarkeD-NY-9 · Jul 20, 2021

Madam Speaker, I move to suspend the rules and pass the bill (H.R. 2980) to amend the Homeland Security Act of 2002 to provide for the remediation of cybersecurity vulnerabilities, and for other…

John Katko
Rep. John KatkoR-NY-24 · Jul 20, 2021

Madam Speaker, I yield myself such time as I may consume. Madam Speaker, I rise today in support of H.R. 2980, the Cybersecurity Vulnerability Remediation Act. I would like to thank the gentlewoman…

Rick W. Allen
Rep. Rick W. AllenR-GA-12 · Jul 20, 2021

Mr. Speaker, had I been present, I would have voted ``nay'' on rollcall No. 212. members recorded pursuant to house resolution 8, 117th congress Aderholt (Moolenaar) Buchanan (LaHood) DeSaulnier…

Steny H. Hoyer
Rep. Steny H. HoyerD-MD-5 · Jul 20, 2021

Mr. Speaker, pursuant to section 7 of House Resolution 535, I move to suspend the rules and pass the bills: H.R. 678; H.R. 1036; H.R. 1079; H.R. 1158; H.R. 1250; H.R. 1754; H.R. 1833; H.R. 1850;

Show 3 more
Pete Stauber
Rep. Pete StauberR-MN-8 · Jul 20, 2021

Mr. Speaker, had I been present, I would have voted ``nay'' on rollcall No. 212.

Dan Bishop
Rep. Dan BishopR-NC-9 · Jul 20, 2021

Madam Speaker, on that I demand the yeas and nays.

Matthew M. Rosendale, Sr.
Rep. Matthew M. Rosendale, Sr.R-MT · Jul 20, 2021

Mr. Speaker, on that I demand the yeas and nays.

Bill Text

3 versions available

Reading Mode
Latest
Referred in SenateIssued July 21, 2021

IIB

117th CONGRESS

1st Session

H. R. 2980

IN THE SENATE OF THE UNITED STATES

July 21, 2021

Received; read twice and referred to the Committee on Homeland Security and Governmental Affairs

AN ACT

To amend the Homeland Security Act of 2002 to provide for the remediation of cybersecurity vulnerabilities, and for other purposes.

1.

Short title

This Act may be cited as the Cybersecurity Vulnerability Remediation Act.

2.

Cybersecurity vulnerabilities

Section 2209 of the Homeland Security Act of 2002 (6 U.S.C. 659) is amended—

(1)

in subsection (a)—

(A)

in paragraph (5), by striking and after the semicolon at the end;

(B)

by redesignating paragraph (6) as paragraph (7); and

(C)

by inserting after paragraph (5) the following new paragraph:

(6)

the term cybersecurity vulnerability has the meaning given the term security vulnerability in section 102 of the Cybersecurity Information Sharing Act of 2015 (6 U.S.C. 1501); and

.

(2)

in subsection (c)—

(A)

in paragraph (5)—

(i)

in subparagraph (A), by striking and after the semicolon at the end;

(ii)

by redesignating subparagraph (B) as subparagraph (C);

(iii)

by inserting after subparagraph (A) the following new subparagraph:

(B)

sharing mitigation protocols to counter cybersecurity vulnerabilities pursuant to subsection (n); and

; and

(iv)

in subparagraph (C), as so redesignated, by inserting and mitigation protocols to counter cybersecurity vulnerabilities in accordance with subparagraph (B) before with Federal;

(B)

in paragraph (7)(C), by striking sharing and inserting share; and

(C)

in paragraph (9), by inserting mitigation protocols to counter cybersecurity vulnerabilities, after measures,;

(3)

in subsection (e)(1)(G), by striking the semicolon after and at the end;

(4)

by redesignating subsection (o) as subsection (p); and

(5)

by inserting after subsection (n) following new subsection:

(o)

Protocols to counter certain cybersecurity vulnerabilities

The Director may, as appropriate, identify, develop, and disseminate actionable protocols to mitigate cybersecurity vulnerabilities to information systems and industrial control systems, including in circumstances in which such vulnerabilities exist because software or hardware is no longer supported by a vendor.

.

3.

Report on cybersecurity vulnerabilities

(a)

Report

Not later than 1 year after the date of the enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security shall submit to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate a report on how the Agency carries out subsection (n) of section 2209 of the Homeland Security Act of 2002 to coordinate vulnerability disclosures, including disclosures of cybersecurity vulnerabilities (as such term is defined in such section), and subsection (o) of such section (as added by section 2) to disseminate actionable protocols to mitigate cybersecurity vulnerabilities to information systems and industrial control systems, that includes the following:

(1)

A description of the policies and procedures relating to the coordination of vulnerability disclosures.

(2)

A description of the levels of activity in furtherance of such subsections (n) and (o) of such section 2209.

(3)

Any plans to make further improvements to how information provided pursuant to such subsections can be shared (as such term is defined in such section 2209) between the Department and industry and other stakeholders.

(4)

Any available information on the degree to which such information was acted upon by industry and other stakeholders.

(5)

A description of how privacy and civil liberties are preserved in the collection, retention, use, and sharing of vulnerability disclosures.

(b)

Form

The report required under subsection (b) shall be submitted in unclassified form but may contain a classified annex.

4.

Competition relating to cybersecurity vulnerabilities

The Under Secretary for Science and Technology of the Department of Homeland Security, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency of the Department, may establish an incentive-based program that allows industry, individuals, academia, and others to compete in identifying remediation solutions for cybersecurity vulnerabilities (as such term is defined in section 2209 of the Homeland Security Act of 2002, as amended by section 2) to information systems (as such term is defined in such section 2209) and industrial control systems, including supervisory control and data acquisition systems.

5.

Title XXII technical and clerical amendments

(a)

Technical amendments

(1)

Homeland Security Act of 2002

Subtitle A of title XXII of the Homeland Security Act of 2002 (6 U.S.C. 651 et seq.) is amended—

(A)

in the first section 2215 (6 U.S.C. 665; relating to the duties and authorities relating to .gov internet domain), by amending the section enumerator and heading to read as follows:

2215.

Duties and authorities relating to .gov internet domain

;

(B)

in the second section 2215 (6 U.S.C. 665b; relating to the joint cyber planning office), by amending the section enumerator and heading to read as follows:

2216.

Joint cyber planning office

;

(C)

in the third section 2215 (6 U.S.C. 665c; relating to the Cybersecurity State Coordinator), by amending the section enumerator and heading to read as follows:

2217.

Cybersecurity State Coordinator

;

(D)

in the fourth section 2215 (6 U.S.C. 665d; relating to Sector Risk Management Agencies), by amending the section enumerator and heading to read as follows:

2218.

Sector Risk Management Agencies

;

(E)

in section 2216 (6 U.S.C. 665e; relating to the Cybersecurity Advisory Committee), by amending the section enumerator and heading to read as follows:

2219.

Cybersecurity Advisory Committee

; and

(F)

in section 2217 (6 U.S.C. 665f; relating to Cybersecurity Education and Training Programs), by amending the section enumerator and heading to read as follows:

2220.

Cybersecurity Education and Training Programs

.

(2)

Consolidated Appropriations Act, 2021

Paragraph (1) of section 904(b) of division U of the Consolidated Appropriations Act, 2021 (Public Law 116–260) is amended, in the matter preceding subparagraph (A), by inserting of 2002 after Homeland Security Act.

(b)

Clerical amendment

The table of contents in section 1(b) of the Homeland Security Act of 2002 is amended by striking the items relating to sections 2214 through 2217 and inserting the following new items:

Sec. 2214. National Asset Database.

Sec. 2215. Duties and authorities relating to .gov internet domain.

Sec. 2216. Joint cyber planning office.

Sec. 2217. Cybersecurity State Coordinator.

Sec. 2218. Sector Risk Management Agencies.

Sec. 2219. Cybersecurity Advisory Committee.

Sec. 2220. Cybersecurity Education and Training Programs.

.

Passed the House of Representatives July 20, 2021.

Cheryl L. Johnson,

Clerk