BSA backs CISA reauthorization in House NDAA, flags three amendments
The software trade group's letter supports NIST-aligned vulnerability disclosure rules and a FedRAMP reciprocity pilot, while opposing provisions it says could sweep in routine commercial practices.
TL;DR
BSA (The Business Software Alliance) released an August 27 letter to Armed Services and party leaders backing CISA 2015's nine-year reauthorization through fiscal 2035, along with House NDAA provisions on FedRAMP reciprocity, vulnerability disclosure aligned to NIST guidelines, and post-quantum cryptography mandates. The letter also flags three House amendments it opposes or finds problematic: one on software-based cryptographic protections that BSA says conflicts with commercial cloud key-management architectures, one barring DoD contracts with providers that give advance vulnerability disclosure to countries-of-concern entities, and a third adding a 72-hour reporting deadline for discovering Chinese-linked hardware in contractor networks.

BSA CEO Victoria Espinel's letter, publicly shared September 10, backs several cybersecurity provisions in the House-passed FY2027 NDAA while flagging three amendments the trade group wants conferees to drop or revise. The letter is addressed to House and Senate leadership and the chairs and ranking members of both Armed Services committees.
The group's support for CISA 2015 reauthorization comes as the information-sharing law faces a known expiration timeline, it was extended only through December 11 via a stopgap continuing resolution. The House NDAA includes language extending it through fiscal 2035; the Senate has yet to pass its version, and negotiations between the chambers are expected to stretch into a lame-duck session.
Among the provisions BSA supports: House Section 1507, which would require covered DoD contractors to implement vulnerability disclosure policies consistent with NIST guidelines, with the FAR Council to follow through and CIO waiver authority available. The letter frames this as alignment with NIST and international standards. BSA also backs a FedRAMP high reciprocity pilot for DoD cloud security requirements and Senate language mandating that DoD adopt NIST-approved post-quantum algorithms for key establishment by December 31, 2030 and for digital signatures by December 31, 2031.
Three amendments drawing opposition
The letter raises concerns about an amendment from Rep. Troy Nehls (R-TX) that would require DoD to implement software-based cryptographic protections in place of hardware-based approaches. BSA says the provision "as drafted uses non-standard cryptographic parameters that conflict with commercial cloud key-management architectures, raises IP disclosure risks for vendors, and embeds procurement terms within what is framed as a security mandate."
BSA outright opposes two other House amendments. One, from Rep. Andy Ogles (R-TN), would bar DoD contracts with providers that give advance vulnerability disclosure to countries-of-concern entities. The letter warns it "could be read broadly enough to capture routine practices rather than only adversary-facing ones." The other, from Rep. Nick Begich (R-AK), would layer a 72-hour reporting deadline for discovering Chinese-linked hardware, software, or firmware in covered contractor networks onto existing cyber incident reporting requirements. BSA asks conferees not to include either in the final bill.
The letter also supports provisions on AI deployment frameworks, consumption-based acquisition authority, and the National Quantum Initiative reauthorization through 2034. But the cybersecurity provisions (and the three contested amendments) are where the operational impact on defense contractors is most concrete. House Section 1507 in particular would create a NIST-aligned vulnerability disclosure baseline for covered contractors, with the FAR Council charged with implementation. The contours of "covered contractor" remain undefined in the House language, leaving open whether the obligation stops at primes or cascades to subcontractors.
Published ·Deep Fathom