---
kind: "section"
citation: "15 U.S.C. § 278g–3e"
title: "15"
title_heading: "Commerce and Trade"
number: "278g–3e"
heading: "Contractor compliance with coordinated disclosure of security vulnerabilities relating to agency Internet of Things devices"
release: "119-102"
date: "2026-07-12"
url: "https://uscodex.org/usc/15/278g-3e"
units:
  - "Chapter 7 — National Institute of Standards and Technology"
---

# §278g–3e. Contractor compliance with coordinated disclosure of security vulnerabilities relating to agency Internet of Things devices

- (a) **Prohibition on procurement and use—**
  - (1) **In general—** The head of an [agency](/usc/15/278g–3a.md?p=1) is prohibited from procuring or obtaining, renewing a contract to procure or obtain, or using an Internet of Things [device](/usc/15/55.md?p=d), if the Chief Information Officer of that [agency](/usc/15/278g–3a.md?p=1) determines during a review required by [section 11319(b)(1)(C) of title 40](/usc/40/11319.md?p=b-1-C) of a contract for such [device](/usc/15/55.md?p=d) that the use of such [device](/usc/15/55.md?p=d) prevents compliance with the standards and guidelines developed under [section 278g–3b of this title](/usc/15/278g–3b.md) or the guidelines published under [section 278g–3c of this title](/usc/15/278g–3c.md) with respect to such [device](/usc/15/55.md?p=d).
  - (2) **Simplified acquisition threshold—** Notwithstanding [section 1905 of title 41](/usc/41/1905.md), the requirements under [paragraph (1)](#a-1) shall apply to a contract or subcontract in amounts not greater than the simplified acquisition threshold.
- (b) **Waiver—**
  - (1) **Authority—** The head of an [agency](/usc/15/278g–3a.md?p=1) may waive the prohibition under [subsection (a)(1)](#a-1) with respect to an Internet of Things [device](/usc/15/55.md?p=d) if the Chief Information Officer of that [agency](/usc/15/278g–3a.md?p=1) determines that—
    - (A) the waiver is necessary in the interest of national security;
    - (B) procuring, obtaining, or using such [device](/usc/15/55.md?p=d) is necessary for research purposes; or
    - (C) such [device](/usc/15/55.md?p=d) is secured using alternative and effective methods appropriate to the function of such [device](/usc/15/55.md?p=d).
  - (2) **Agency process—** The [Director of OMB](/usc/15/278g–3a.md?p=2) shall establish a standardized process for the Chief Information Officer of each [agency](/usc/15/278g–3a.md?p=1) to follow in determining whether the waiver under [paragraph (1)](#b-1) may be granted.
- (c) **Reports to Congress—**
  - (1) **Report—** Every 2 years during the 6-year period beginning on December 4, 2020, the Comptroller General of the United States shall submit to the Committee on Oversight and Reform of the House of Representatives, the Committee on Homeland Security of the House of Representatives, and the Committee on Homeland Security and Governmental Affairs of the Senate a report—
    - (A) on the effectiveness of the process established under [subsection (b)(2)](#b-2);
    - (B) that contains recommended best practices for the procurement of Internet of Things [devices](/usc/15/55.md?p=d); and
    - (C) that lists—
      - (i) the number and type of each Internet of Things [device](/usc/15/55.md?p=d) for which a waiver under [subsection (b)(1)](#b-1) was granted during the 2-year period prior to the submission of the report; and
      - (ii) the legal authority under which each such waiver was granted, such as whether the waiver was granted pursuant to subparagraph [(A)](#c-1-A), [(B)](#c-1-B), or [(C)](#c-1-C) of such subsection.
  - (2) **Classification of report—** Each report submitted under this subsection shall be submitted in unclassified form, but may include a classified annex that contains the information described under [paragraph (1)(C)](#c-1-C).
- (d) **Effective date—** The prohibition under [subsection (a)(1)](#a-1) shall take effect 2 years after December 4, 2020.

## Source credit

(Pub. L. 116–207, § 7, Dec. 4, 2020, 134 Stat. 1005.)

## Notes

### Editorial Notes

### Codification

Section was enacted as part of the Internet of Things Cybersecurity Improvement Act of 2020, also known as the IoT Cybersecurity Improvement Act of 2020, and not as part of the National Institute of Standards and Technology Act which comprises this chapter.

### Statutory Notes and Related Subsidiaries

### Change of Name

Committee on Oversight and Reform of House of Representatives changed to Committee on Oversight and Accountability of House of Representatives by House Resolution No. 5, One Hundred Eighteenth Congress, Jan. 9, 2023.

### Definitions

For definitions of terms used in this section, see section 278g–3a of this title.
