---
kind: "section"
citation: "15 U.S.C. § 278g–3c"
title: "15"
title_heading: "Commerce and Trade"
number: "278g–3c"
heading: "Guidelines on the disclosure process for security vulnerabilities relating to information systems, including Internet of Things devices"
release: "119-102"
date: "2026-07-12"
url: "https://uscodex.org/usc/15/278g-3c"
units:
  - "Chapter 7 — National Institute of Standards and Technology"
---

# §278g–3c. Guidelines on the disclosure process for security vulnerabilities relating to information systems, including Internet of Things devices

- (a) **In general—** Not later than 180 days after December 4, 2020, the [Director of the Institute](/usc/15/278g–3a.md?p=3), in consultation with such cybersecurity researchers and private sector industry experts as the Director considers appropriate, and in consultation with the [Secretary](/usc/15/278g–3a.md?p=7), shall develop and publish under [section 278g–3 of this title](/usc/15/278g–3.md) guidelines—
  - (1) for the reporting, coordinating, publishing, and receiving of information about—
    - (A) a [security vulnerability](/usc/15/278g–3a.md?p=8) relating to [information systems](/usc/15/278g–3a.md?p=4) owned or controlled by an [agency](/usc/15/278g–3a.md?p=1) (including Internet of Things [devices](/usc/15/55.md?p=d) owned or controlled by an [agency](/usc/15/278g–3a.md?p=1)); and
    - (B) the resolution of such [security vulnerability](/usc/15/278g–3a.md?p=8); and
  - (2) for a contractor providing to an [agency](/usc/15/278g–3a.md?p=1) an [information system](/usc/15/278g–3a.md?p=4) (including an Internet of Things [device](/usc/15/55.md?p=d)) and any subcontractor thereof at any tier providing such [information system](/usc/15/278g–3a.md?p=4) to such contractor, on—
    - (A) receiving information about a potential [security vulnerability](/usc/15/278g–3a.md?p=8) relating to the [information system](/usc/15/278g–3a.md?p=4); and
    - (B) disseminating information about the resolution of a [security vulnerability](/usc/15/278g–3a.md?p=8) relating to the [information system](/usc/15/278g–3a.md?p=4).
- (b) **Elements—** The guidelines published under [subsection (a)](#a) shall—
  - (1) to the maximum extent practicable, be aligned with industry best practices and Standards 29147 and 30111 of the International Standards Organization (or any successor standard) or any other appropriate, relevant, and widely-used standard;
  - (2) incorporate guidelines on—
    - (A) receiving information about a potential [security vulnerability](/usc/15/278g–3a.md?p=8) relating to an [information system](/usc/15/278g–3a.md?p=4) owned or controlled by an [agency](/usc/15/278g–3a.md?p=1) (including an Internet of Things [device](/usc/15/55.md?p=d)); and
    - (B) disseminating information about the resolution of a [security vulnerability](/usc/15/278g–3a.md?p=8) relating to an [information system](/usc/15/278g–3a.md?p=4) owned or controlled by an [agency](/usc/15/278g–3a.md?p=1) (including an Internet of Things [device](/usc/15/55.md?p=d)); and
  - (3) be consistent with the policies and procedures produced under [section 659(m) of title 6](/usc/6/659.md?p=m).
- (c) **Information items—** The guidelines published under [subsection (a)](#a) shall include example content, on the information items that should be reported, coordinated, published, or received pursuant to this section by a contractor, or any subcontractor thereof at any tier, providing an [information system](/usc/15/278g–3a.md?p=4) (including Internet of Things [device](/usc/15/55.md?p=d)) to the Federal Government.
- (d) **Oversight—** The [Director of OMB](/usc/15/278g–3a.md?p=2) shall oversee the implementation of the guidelines published under [subsection (a)](#a).
- (e) **Operational and technical assistance—** The [Secretary](/usc/15/278g–3a.md?p=7), in consultation with the [Director of OMB](/usc/15/278g–3a.md?p=2), shall administer the implementation of the guidelines published under [subsection (a)](#a) and provide operational and technical assistance in implementing such guidelines.

## Source credit

(Pub. L. 116–207, § 5, Dec. 4, 2020, 134 Stat. 1004.)

## Notes

### Editorial Notes

### Codification

Section was enacted as part of the Internet of Things Cybersecurity Improvement Act of 2020, also known as the IoT Cybersecurity Improvement Act of 2020, and not as part of the National Institute of Standards and Technology Act which comprises this chapter.

### Statutory Notes and Related Subsidiaries

### Definitions

For definitions of terms used in this section, see section 278g–3a of this title.
