Loading chat...
US HB6315
Bill
Status
11/25/2025
Primary Sponsor
David Valadao
Click for details
AI Summary
-
Requires the Election Assistance Commission to incorporate penetration testing into the testing, certification, decertification, and recertification of voting system hardware and software within 180 days of enactment, with NIST recommending accredited entities to conduct the testing.
-
Establishes a 5-year Independent Security Testing and Coordinated Vulnerability Disclosure Pilot Program (VDP-E) allowing cybersecurity researchers to test election systems, including voting machines and source code, for security vulnerabilities.
-
Requires researchers to keep discovered vulnerabilities confidential for 180 days after notifying vendors, the Commission, and the Secretary of Homeland Security, with critical vulnerabilities requiring vendors to send patches to state and local election officials.
-
Provides legal safe harbor for participating researchers under the Computer Fraud and Abuse Act and Digital Millennium Copyright Act, exempting good-faith security research from prosecution and circumvention claims.
-
Mandates expedited 90-day review of security patches for certified systems, with automatic certification if review is not completed, and requires vulnerabilities to be reported to CISA's Common Vulnerabilities and Exposures database after 180 days.
Legislative Description
SECURE IT Act Strengthening Election Cybersecurity to Uphold Respect for Elections through Independent Testing Act
Government operations and politics
Last Action
Referred to the Committee on House Administration, and in addition to the Committee on Science, Space, and Technology, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.
11/25/2025