---
kind: "section"
citation: "15 U.S.C. § 278g–3d"
title: "15"
title_heading: "Commerce and Trade"
number: "278g–3d"
heading: "Implementation of coordinated disclosure of security vulnerabilities relating to agency information systems, including Internet of Things devices"
release: "119-102"
date: "2026-07-12"
url: "https://uscodex.org/usc/15/278g-3d"
units:
  - "Chapter 7 — National Institute of Standards and Technology"
---

# §278g–3d. Implementation of coordinated disclosure of security vulnerabilities relating to agency information systems, including Internet of Things devices

- (a) **Agency guidelines required—** Not later than 2 years after December 4, 2020, the [Director of OMB](/usc/15/278g–3a.md?p=2), in consultation with the [Secretary](/usc/15/278g–3a.md?p=7), shall develop and oversee the implementation of policies, principles, standards, or guidelines as may be necessary to address [security vulnerabilities](/usc/15/278g–3a.md?p=8) of [information systems](/usc/15/278g–3a.md?p=4) (including Internet of Things [devices](/usc/15/55.md?p=d)).
- (b) **Operational and technical assistance—** Consistent with [section 3553(b) of title 44](/usc/44/3553.md?p=b), the [Secretary](/usc/15/278g–3a.md?p=7), in consultation with the [Director of OMB](/usc/15/278g–3a.md?p=2), shall provide operational and technical assistance to [agencies](/usc/15/278g–3a.md?p=1) on reporting, coordinating, publishing, and receiving information about [security vulnerabilities](/usc/15/278g–3a.md?p=8) of [information systems](/usc/15/278g–3a.md?p=4) (including Internet of Things [devices](/usc/15/55.md?p=d)).
- (c) **Consistency with guidelines from National Institute of Standards and Technology—** The [Secretary](/usc/15/278g–3a.md?p=7) shall ensure that the assistance provided under [subsection (b)](#b) is consistent with applicable standards and publications developed by the [Director of the Institute](/usc/15/278g–3a.md?p=3).
- (d) **Revision of Federal Acquisition Regulation—** The Federal Acquisition Regulation shall be revised as necessary to implement the provisions under this section.

## Source credit

(Pub. L. 116–207, § 6, Dec. 4, 2020, 134 Stat. 1005.)

## Notes

### Editorial Notes

### Codification

Section was enacted as part of the Internet of Things Cybersecurity Improvement Act of 2020, also known as the IoT Cybersecurity Improvement Act of 2020, and not as part of the National Institute of Standards and Technology Act which comprises this chapter.

### Statutory Notes and Related Subsidiaries

### Definitions

For definitions of terms used in this section, see section 278g–3a of this title.
