logo

US Government Mandates Vulnerability Disclosure for IoT

ID: 8285f364-a86c-5ec6-9cc2-33cbf8c00866

STIX ID: report--8285f364-a86c-5ec6-9cc2-33cbf8c00866

Feed Name: HackerOne Blog

Date Published: 2024-11-20

Date Updated: 2026-06-12

...
...

This briefing explains how the IoT Cybersecurity Improvement Act, informed by NIST SP 800-53 Revision 5 and related guidance, requires IoT vendors and contractors selling to the U.S. government to adopt formal vulnerability disclosure policies (VDPs) and follow ISO/NIST standards within defined timelines — with OMB oversight — and highlights vendor compliance implications and available vendor assistance (e.g., HackerOne).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.