H.R. 7299House117th Congress (2021-2023)Enacted

SVAC Act of 2022

Introduced March 30, 2022

AI-Generated Summary

Updated February 8, 2026 at 1:11 PM UTC

The Strengthening VA Cybersecurity Act of 2022 requires the Department of Veterans Affairs to obtain an independent review of its most critical information systems and overall security program, then develop and implement a plan to fix identified weaknesses. The law sets tight deadlines for the assessment, the remediation plan, and a follow‑up review by the Comptroller General, aiming to improve the VA’s protection against cyber threats for veterans’ data and services.

Key Provisions

  • Within 60 days of the law’s enactment, the VA Secretary must contract with a federally funded research and development center to conduct an independent cybersecurity assessment of five high‑impact VA information systems and the department’s overall security program.
  • The assessment must analyze the VA’s ability to protect confidentiality, integrity, and availability against a wide range of threats—including ransomware, insider threats, foreign actors, phishing, supply‑chain attacks, and remote‑work risks—and must cover on‑premises, cloud, mobile, and any “shadow” IT used without official approval.
  • Within 120 days after receiving the assessment, the Secretary must submit a remediation plan to the House and Senate Veterans’ Affairs Committees outlining security improvements, cost estimates, timelines, and any other necessary actions.
  • Within 180 days of the plan’s submission, the Comptroller General must review both the independent assessment and the VA’s response, then brief the same committees on findings and recommendations.

Legislative Activity

Stay on top of the latest movement without scrolling through every action

19 earlier actions
Became Law Latest Action

Became Public Law No: 117-302.

December 27, 2022

View full timeline
HouseIntro Referral

Introduced in House

March 30, 2022

HouseIntro Referral

Referred to the House Committee on Veterans' Affairs.

March 30, 2022

HouseCommittee

Referred to the Subcommittee on Technology Modernization.

July 14, 2022

HouseCommittee

Subcommittee on Technology Modernization Discharged.

July 18, 2022

HouseCommittee

Committee Consideration and Mark-up Session Held.

July 19, 2022

HouseCommittee

Ordered to be Reported (Amended) by Voice Vote.

July 19, 2022

HouseFloor

Mr. Takano moved to suspend the rules and pass the bill, as amended.

November 14, 2022 • 3:37 PM

HouseFloor

Considered under suspension of the rules. (consideration: CR H8464-8465; text: CR H8464-8465)

November 14, 2022 • 3:37 PM

HouseFloor

DEBATE - The House proceeded with forty minutes of debate on H.R. 7299.

November 14, 2022 • 3:37 PM

HouseFloor

At the conclusion of debate, the Yeas and Nays were demanded and ordered. Pursuant to the provisions of clause 8, rule XX, the Chair announced that further proceedings on the motion would be postponed.

November 14, 2022 • 3:41 PM

HouseFloor

Passed/agreed to in House: Pursuant to section 2 of H. Res. 1464, and the motion offered by Mr. Carter (LA), the following bills passed under suspension of the rules: H.R. 4275, as amended; H.R. 5502, as amended; H.R. 5721, as amended; H.R. 6290, as amended; H.R. 7277, as amended; H.R. 7299, as amended; and H.R. 8416, as amended.

November 17, 2022 • 2:10 PM

HouseFloor

Pursuant to section 2 of H. Res. 1464, and the motion offered by Mr. Carter (LA), the following bills passed under suspension of the rules: H.R. 4275, as amended; H.R. 5502, as amended; H.R. 5721, as amended; H.R. 6290, as amended; H.R. 7277, as amended; H.R. 7299, as amended; and H.R. 8416, as amended. (consideration: CR H8566-8574; text: CR H8569-8570)

November 17, 2022 • 2:10 PM

HouseFloor

Pursuant to the provisions of H. Res. 1464, proceedings on H.R. 7299 are considered vacated.

November 17, 2022 • 2:10 PM

SenateIntro Referral

Received in the Senate and Read twice and referred to the Committee on Veterans' Affairs.

November 17, 2022

SenateCommittee

Senate Committee on Veterans' Affairs discharged by Unanimous Consent.

December 19, 2022

SenateFloor

Passed Senate without amendment by Unanimous Consent. (consideration: CR S7302-7303)

December 19, 2022

SenateFloor

Message on Senate action sent to the House.

December 21, 2022

President

Presented to President.

December 23, 2022

Became Law

Signed by President.

December 27, 2022

Became Law

Became Public Law No: 117-302.

December 27, 2022

Floor Debate

7 members

What members said about H.R. 7299 on the floor

3 Republicans4 Democrats
Sheila Jackson Lee
Rep. Sheila Jackson LeeD-TX-18 · Nov 17, 2022

Mr. Speaker, I rise in support of H.R. 7299, the Strengthening VA Cybersecurity Act of 2022, to require the Secretary of Veterans Affairs to obtain an independent cybersecurity assessment of…

Mark Takano
Rep. Mark TakanoD-CA-41 · Nov 14, 2022

Mr. Speaker, I move to suspend the rules and pass the bill (H.R. 7299) to require the Secretary of Veterans Affairs to obtain an independent cybersecurity assessment of information systems of the…

Jake Ellzey
Rep. Jake EllzeyR-TX-6 · Nov 14, 2022

Mr. Speaker, I yield myself such time as I may consume. Mr. Speaker, I rise today in support of H.R. 7299, as amended, the Strengthening VA Cybersecurity Act of 2022. VA is the second largest Federal…

Mark Kelly
Sen. Mark KellyD-AZ · Dec 19, 2022

Mr. President, I ask unanimous consent that the Committee on Veterans' Affairs be discharged and that the Senate proceed to the immediate consideration of the following bills en bloc: H.R. 6064, H.R.…

Greg Pence
Rep. Greg PenceR-IN-6 · Nov 17, 2022

Madam Speaker, I am not recorded for Roll Call votes No. 481, No. 482, No. 483, No. 484, and No. 485. Had I been present, I would have voted Yes on Roll Call No. 481 En Bloc Suspensions (H.R. 5721,…

Show 3 more
Troy A. Carter
Rep. Troy A. CarterD-LA-2 · Nov 17, 2022

Madam Speaker, pursuant to section 2 of House Resolution 1464, I move to suspend the rules and pass the bills: H.R. 4275, H.R. 5502, H.R. 5721, H.R. 6290, H.R. 7277, H.R. 7299, and

Matthew M. Rosendale, Sr.
Rep. Matthew M. Rosendale, Sr.R-MT · Nov 17, 2022

Madam Speaker, on that I demand the yeas and nays.

Matthew M. Rosendale, Sr.
Rep. Matthew M. Rosendale, Sr.R-MT · Nov 14, 2022

Mr. Speaker, on that I demand the yeas and nays.

Bill Text

5 versions available

Reading Mode
Latest
Enrolled BillPublication date not provided

One Hundred Seventeenth Congress of the United States of America

At the Second Session

Begun and held at the City of Washington on Monday, the third day of January, two thousand and twenty-two

H. R. 7299

AN ACT

To require the Secretary of Veterans Affairs to obtain an independent cybersecurity assessment of information systems of the Department of Veterans Affairs, and for other purposes.

1.

Short title

This Act may be cited as the Strengthening VA Cybersecurity Act of 2022 or the SVAC Act of 2022.

2.

Independent cybersecurity assessment of information systems of Department of Veterans Affairs

(a)

Independent assessment required

(1)

In general

Not later than 60 days after the date of the enactment of this Act, the Secretary of Veterans Affairs shall seek to enter into an agreement with a federally funded research and development center to provide to the Secretary an independent cybersecurity assessment of—

(A)

five high-impact information systems of the Department of Veterans Affairs; and

(B)

the effectiveness of the information security program and information security management system of the Department.

(2)

Detailed analysis

The independent cybersecurity assessment provided under paragraph (1) shall include a detailed analysis of the ability of the Department—

(A)

to ensure the confidentiality, integrity, and availability of the information, information systems, and devices of the Department; and

(B)

to protect against—

(i)

advanced persistent cybersecurity threats;

(ii)

ransomware;

(iii)

denial of service attacks;

(iv)

insider threats;

(v)

threats from foreign actors, including state sponsored criminals and other foreign based criminals;

(vi)

phishing;

(vii)

credential theft;

(viii)

cybersecurity attacks that target the supply chain of the Department;

(ix)

threats due to remote access and telework activity; and

(x)

other cyber threats.

(3)

Types of systems

The independent cybersecurity assessment provided under paragraph (1) shall cover on-premises, remote, cloud-based, and mobile information systems and devices used by, or in support of, Department activities.

(4)

Shadow information technology

The independent cybersecurity assessment provided under paragraph (1) shall include an evaluation of the use of information technology systems, devices, and services by employees and contractors of the Department who do so without the heads of the elements of the Department that are responsible for information technology at the Department knowing or approving of such use.

(5)

Methodology

In conducting the cybersecurity assessment to be provided under paragraph (1), the federally funded research and development center shall take into account industry best practices and the current state-of-the-art in cybersecurity evaluation and review.

(b)

Plan

(1)

In general

Not later than 120 days after the date on which an independent assessment is provided to the Secretary by a federally funded research and development center pursuant to an agreement entered into under subsection (a), the Secretary shall submit to the Committees on Veterans’ Affairs of the House of Representatives and the Senate a plan to address the findings of the federally funded research and development center set forth in such assessment.

(2)

Elements

The plan submitted under paragraph (1) shall include the following:

(A)

Improvements to the security controls of the information systems of the Department assessed under subsection (a) to—

(i)

achieve the goals specified in subparagraph (A) of paragraph (2) of such subsection; and

(ii)

protect against the threats specified in subparagraph (B) of such paragraph.

(B)

Improvements to the information security program and information security management system of the Department to achieve such goals and protect against such threats.

(C)

A cost estimate for implementing the plan.

(D)

A timeline for implementing the plan.

(E)

Such other elements as the Secretary considers appropriate.

(c)

Comptroller General of the United States evaluation and review

Not later than 180 days after the date of the submission of the plan under subsection (b)(1), the Comptroller General of the United States shall—

(1)

commence an evaluation and review of—

(A)

the independent cybersecurity assessment provided under subsection (a); and

(B)

the response of the Department to such assessment; and

(2)

provide to the Committees on Veterans’ Affairs of the House of Representatives and the Senate a briefing on the results of the evaluation and review, including any recommendations made to the Secretary regarding the matters covered by the briefing.

Speaker of the House of Representatives.

Vice President of the United States and President of the Senate.