(a)
Agency guidelines required— Not later than 180 days after the date on which the guidance required under section 4 is published, the Director of the Office of Management and Budget shall, in consultation with the Administrator of the General Services Administration, issue guidelines for each agency on reporting, coordinating, publishing, and receiving information about—
(1)
a security vulnerability relating to a covered device used by the agency; and
(2)
the resolution of such security vulnerability.
(b)
Contractor and vendor compliance with National Institute of Standards and Technology guidance— The guidelines required by subsection (a) shall include a limitation that prohibits an agency from acquiring or using any covered device from a contractor or vendor if the contractor or vendor fails to comply with the guidance published under section 5(a).
(c)
Consistency with guidance from National Institute of Standards and Technology— The Director shall ensure that the guidelines issued under subsection (a) are consistent with the guidance published under section 5(a).