H.R. 4611House117th Congress (2021-2023)Passed House

DHS Software Supply Chain Risk Management Act of 2021

Introduced July 21, 2021

AI-Generated Summary

Updated February 8, 2026 at 5:34 AM UTC

The DHS Software Supply Chain Risk Management Act of 2021 directs the Department of Homeland Security to issue guidance for contracts involving information and communications technology or services. The guidance requires contractors to submit a bill of materials and certify that the software components are free of known security vulnerabilities, and to notify DHS of any identified issues and mitigation plans. It applies to both new and existing DHS contracts for covered ICT products and services.

Key Provisions

  • The Secretary, through the Under Secretary, must issue guidance for new and existing covered contracts within 180 days of enactment.
  • For new contracts, bidders must provide a planned bill of materials and certify that listed items have no known vulnerabilities per the NIST Vulnerability Database and any DHS‑designated databases.
  • For existing contracts, contractors must supply the bill of materials upon request and provide the same certification and notifications.
  • Contractors must promptly update the bill of materials whenever changes occur.
  • Certifications must confirm no known vulnerabilities and include notifications of any discovered issues and plans to mitigate them.
  • The guidance must outline enforcement processes for contracting officers and other designated officials.
  • The Government Accountability Office must report within one year on implementation, industry engagement, compliance with relevant executive orders, and recommendations for supply‑chain improvement.

Legislative Activity

Stay on top of the latest movement without scrolling through every action

16 earlier actions
SenateIntro Referral Latest Action

Received in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs.

October 21, 2021

View full timeline
HouseIntro Referral

Introduced in House

July 21, 2021

HouseIntro Referral

Referred to the House Committee on Homeland Security.

July 21, 2021

HouseCommittee

Referred to the Subcommittee on Oversight, Management, and Accountability.

July 22, 2021

HouseCommittee

Subcommittee on Oversight, Management, and Accountability Discharged.

July 28, 2021

HouseCommittee

Committee Consideration and Mark-up Session Held.

July 28, 2021

HouseCommittee

Ordered to be Reported (Amended) by Voice Vote.

July 28, 2021

HouseCommittee

Reported (Amended) by the Committee on Homeland Security. H. Rept. 117-120.

September 14, 2021

HouseCalendars

Placed on the Union Calendar, Calendar No. 85.

September 14, 2021

HouseFloor

Mr. Thompson (MS) moved to suspend the rules and pass the bill, as amended.

September 29, 2021 • 3:41 PM

HouseFloor

Considered under suspension of the rules. (consideration: CR H5535-5536)

September 29, 2021 • 3:41 PM

HouseFloor

DEBATE - The House proceeded with forty minutes of debate on H.R. 4611.

September 29, 2021 • 3:41 PM

HouseFloor

At the conclusion of debate, the Yeas and Nays were demanded and ordered. Pursuant to the provisions of clause 8, rule XX, the Chair announced that further proceedings on the motion would be postponed.

September 29, 2021 • 3:51 PM

HouseFloor

Considered as unfinished business. (consideration: CR H5698-5699)

October 20, 2021 • 1:30 PM

HouseFloor

Passed/agreed to in House: On motion to suspend the rules and pass the bill, as amended Agreed to by the Yeas and Nays: (2/3 required): 412 - 2 (Roll no. 319).(text: CR 9/29/2021 H5535)

October 20, 2021 • 2:02 PM

HouseFloor

On motion to suspend the rules and pass the bill, as amended Agreed to by the Yeas and Nays: (2/3 required): 412 - 2 (Roll no. 319). (text: CR 9/29/2021 H5535)

October 20, 2021 • 2:02 PM

HouseFloor

Motion to reconsider laid on the table Agreed to without objection.

October 20, 2021 • 2:02 PM

SenateIntro Referral

Received in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs.

October 21, 2021

Floor Debate

5 members

What members said about H.R. 4611 on the floor

2 Republicans3 Democrats
Bennie G. Thompson
Rep. Bennie G. ThompsonD-MS-2 · Sep 29, 2021

Madam Speaker, I move to suspend the rules and pass the bill (H.R. 4611) to direct the Secretary of Homeland Security to issue guidance with respect to certain information and communications…

Ritchie Torres
Rep. Ritchie TorresD-NY-15 · Sep 29, 2021

Madam Speaker, a cyberattack on a software supply chain is like an infectious disease outbreak, spreading widely and rapidly, and causing untold damage far and wide. The SolarWinds espionage campaign…

Michael Guest
Rep. Michael GuestR-MS-3 · Sep 29, 2021

Madam Speaker, I yield myself such time as I may consume. Madam Speaker, I rise today in support of H.R. 4611, the DHS Software Supply Chain Risk Management Act of 2021. As we have seen over the past…

Brenda L. Lawrence
Rep. Brenda L. LawrenceD-MI-14 · Oct 21, 2021

Madam Speaker, unfortunately, on October 20, 2021. my vote was not recorded on the first vote of the series (Roll Call No. 319 on H.R. 4611). Had my vote been recorded. I would have voted: YES on DHS…

Bill Posey
Rep. Bill PoseyR-FL-8 · Sep 29, 2021

Madam Speaker, on that I demand the yeas and nays.

Bill Text

4 versions available

Reading Mode
Latest
Referred in SenateIssued October 21, 2021

IIB

117th CONGRESS

1st Session

H. R. 4611

IN THE SENATE OF THE UNITED STATES

October 21, 2021

Received; read twice and referred to the Committee on Homeland Security and Governmental Affairs

AN ACT

To direct the Secretary of Homeland Security to issue guidance with respect to certain information and communications technology or services contracts, and for other purposes.

1.

Short title

This Act may be cited as the DHS Software Supply Chain Risk Management Act of 2021.

2.

Department of Homeland Security guidance with respect to certain information and communications technology or services contracts

(a)

Guidance

The Secretary of Homeland Security, acting through the Under Secretary, shall issue guidance with respect to new and existing covered contracts.

(b)

New covered contracts

In developing guidance under subsection (a), with respect to each new covered contract, as a condition on the award of such a contract, each contractor responding to a solicitation for such a contract shall submit to the covered officer—

(1)

a planned bill of materials when submitting a bid proposal; and

(2)

the certification and notifications described in subsection (e).

(c)

Existing covered contracts

In developing guidance under subsection (a), with respect to each existing covered contract, each contractor with an existing covered contract shall submit to the covered officer—

(1)

the bill of materials used for such contract, upon the request of such officer; and

(2)

the certification and notifications described in subsection (e).

(d)

Updating bill of materials

With respect to a covered contract, in the case of a change to the information included in a bill of materials submitted pursuant to subsections (b)(1) and (c)(1), each contractor shall submit to the covered officer the update to such bill of materials, in a timely manner.

(e)

Certification and notifications

The certification and notifications referred to in subsections (b)(2) and (c)(2), with respect to a covered contract, are the following:

(1)

A certification that each item listed on the submitted bill of materials is free from all known vulnerabilities or defects affecting the security of the end product or service identified in—

(A)

the National Institute of Standards and Technology National Vulnerability Database; and

(B)

any database designated by the Under Secretary, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency, that tracks security vulnerabilities and defects in open source or third-party developed software.

(2)

A notification of each vulnerability or defect affecting the security of the end product or service, if identified, through—

(A)

the certification of such submitted bill of materials required under paragraph (1); or

(B)

any other manner of identification.

(3)

A notification relating to the plan to mitigate, repair, or resolve each security vulnerability or defect listed in the notification required under paragraph (2).

(f)

Enforcement

In developing guidance under subsection (a), the Secretary shall instruct covered officers with respect to—

(1)

the processes available to such officers enforcing subsections (b) and (c); and

(2)

when such processes should be used.

(g)

Effective date

The guidance required under subsection (a) shall take effect on the date that is 180 days after the date of the enactment of this section.

(h)

GAO report

Not later than 1 year after the date of the enactment of this Act, the Comptroller General of the United States shall submit to the Secretary, the Committee on Homeland Security of the House of Representatives, and the Committee on Homeland Security and Governmental Affairs of the Senate a report that includes—

(1)

a review of the implementation of this section;

(2)

information relating to the engagement of the Department of Homeland Security with industry;

(3)

an assessment of how the guidance issued pursuant to subsection (a) complies with Executive Order 14208 (86 Fed. Reg. 26633; relating to improving the nation’s cybersecurity); and

(4)

any recommendations relating to improving the supply chain with respect to covered contracts.

(i)

Definitions

In this section:

(1)

Bill of materials

The term bill of materials means a list of the parts and components (whether new or reused) of an end product or service, including, with respect to each part and component, information relating to the origin, composition, integrity, and any other information as determined appropriate by the Under Secretary.

(2)

Covered contract

The term covered contract means a contract relating to the procurement of covered information and communications technology or services for the Department of Homeland Security.

(3)

Covered information and communications technology or services

The term covered information and communications technology or services means the terms—

(A)

information technology (as such term is defined in section 11101(6) of title 40, United States Code);

(B)

information system (as such term is defined in section 3502(8) of title 44, United States Code);

(C)

telecommunications equipment (as such term is defined in section 3(52) of the Communications Act of 1934 (47 U.S.C. 153(52))); and

(D)

telecommunications service (as such term is defined in section 3(53) of the Communications Act of 1934 (47 U.S.C. 153(53))).

(4)

Covered officer

The term covered officer means—

(A)

a contracting officer of the Department; and

(B)

any other official of the Department as determined appropriate by the Under Secretary.

(5)

Software

The term software means computer programs and associated data that may be dynamically written or modified during execution.

(6)

Under Secretary

The term Under Secretary means the Under Secretary for Management of the Department of Homeland Security.

3.

Determination of budgetary effects

The budgetary effects of this Act, for the purpose of complying with the Statutory Pay-As-You-Go Act of 2010, shall be determined by reference to the latest statement titled Budgetary Effects of PAYGO Legislation for this Act, submitted for printing in the Congressional Record by the Chairman of the House Budget Committee, provided that such statement has been submitted prior to the vote on passage.

Passed the House of Representatives October 20, 2021.

Cheryl L. Johnson,

Clerk.