executive-ordertrade-pressNewsThe Broadside2 min read

House NDAA mandates vulnerability disclosure, extends CISA 2015

The vulnerability disclosure requirement marks the first time Congress has imposed the practice on contractors as a condition of federal work, rather than encouraging it as a best practice.


TL;DR

The House passed its fiscal 2027 NDAA 216-212 on July 22, packing in a nine-year CISA 2015 extension through 2035 and a first-of-its-kind mandate requiring federal contractors to adopt vulnerability disclosure policies. The bill also directs the Pentagon to brief Congress on CMMC's impact on small businesses. CISA 2015's current authorization expires September 30, leaving the Senate and reconciliation between now and then. The vulnerability disclosure mandate, carried by Rep. Nancy Mace's Federal Contractor Vulnerability Disclosure Act, shifts the practice from encouraged best practice to a condition of doing business with the federal government.

House NDAA mandates vulnerability disclosure, extends CISA 2015
Editorial illustration · drawn by The Broadside

The House passed its fiscal 2027 National Defense Authorization Act in a narrow 216-212 vote on July 22, advancing three cybersecurity provisions that reshape the compliance landscape for defense contractors: a nine-year extension of CISA 2015's information-sharing safe harbor, a mandate requiring federal contractors to adopt vulnerability disclosure policies, and a directive for the Pentagon to brief Congress on CMMC's small-business impact.

The CISA 2015 extension, carried by Rep. Morgan Luttrell's WIMWIG Act, would reauthorize the law through fiscal 2035. The current authorization expires September 30, the product of a short-term patch enacted in January 2026 after lawmakers failed to include the extension in the fiscal 2026 NDAA. WIMWIG cleared the Homeland Security Committee in September 2025 but stalled. The House NDAA vote revives it with a nine-year runway instead of another stopgap. Whether the Senate agrees before the September cliff is the open question.

The vulnerability disclosure mandate, drawn from House Oversight cyber subcommittee Chair Nancy Mace's Federal Contractor Vulnerability Disclosure Act, is the bill's most consequential shift. Until now, vulnerability disclosure policies have been encouraged as a best practice. CISA has published guidance, NIST has framework language, and individual agencies have nudged contractors toward adoption. Embedding the requirement in the NDAA makes it a condition of federal contracting. A contractor without a vulnerability disclosure policy on file would be out of compliance, not merely out of step with industry norms. The House approved over 300 of the 1,400 amendments filed, and this one made the cut alongside a separate measure directing the Pentagon to produce a memory-safe software roadmap.

The CMMC provision is narrower (a briefing, not a rule) but signals continued congressional attention to how the Pentagon's certification program lands on small and mid-sized suppliers. The briefing requirement gives the committees a lever to press for carve-outs, phased timelines, or cost offsets before the rule's teeth sink in.

For compliance directors, nothing changes Monday. The Senate hasn't acted, reconciliation hasn't started, and the CISA 2015 clock still reads September 30. But the House bill tees up a procurement landscape where vulnerability disclosure isn't optional and CISA 2015's safe harbor isn't perpetually on the brink of expiration. Watch the Senate markup for whether either provision gets softened or stripped.


Published ·Deep Fathom