HR6315-119

Introduced

To amend the Help America Vote Act of 2002 to require the Election Assistance Commission to provide for the conduct of penetration testing as part of the testing and certification of voting systems and to provide for the establishment of an Independent Security Testing and Coordinated Vulnerability Disclosure Pilot Program for Election Systems.

119th Congress Introduced Nov 25, 2025

Summary

What This Bill Does

The bill requires the Election Assistance Commission to mandate penetration testing as part of voting system hardware and software certification, decertification, and recertification within 180 days. NIST recommends entities, amends the Help America Vote Act to establish a 5-year Independent Security Testing and Coordinated Vulnerability Disclosure Pilot Program (VDP-E) for election systems, and creates new Section 297 of HAVA establishing the VDP-E program with detailed requirements: vendor source code access for researchers, background checks, 180-day confidentiality, mandatory patching of critical/high. It relies on compliance mandates, liability protections, exemptions, and product standards. The main policy areas are Technology.

Who Benefits and How

Cybersecurity researchers receiving CFAA and DMCA safe harbor could face reduced risk, Cybersecurity researchers participating in VDP-E could face reduced risk, and Cybersecurity firms and penetration testing companies could gain revenue opportunities.

Who Bears the Burden and How

Election system vendors required to share source code and patch critical vulnerabilities would take on compliance duties, Election system vendors seeking EAC certification would take on compliance duties, and Election system vendors required to provide systems and patch vulnerabilities would take on compliance duties.

Key Provisions

  • Requires the Election Assistance Commission to mandate penetration testing as part of voting system hardware and software certification, decertification, and recertification within 180 days. NIST recommends entities...
  • Amends the Help America Vote Act to establish a 5-year Independent Security Testing and Coordinated Vulnerability Disclosure Pilot Program (VDP-E) for election systems.
  • Creates new Section 297 of HAVA establishing the VDP-E program with detailed requirements: vendor source code access for researchers, background checks, 180-day confidentiality, mandatory patching of critical/high...

Evidence Chain:

This summary is generated from the full bill text using AI analysis. Expand "Detailed Analysis" below for identified beneficiaries/burden bearers with clause-level evidence links.

At a Glance

What This Bill Does

The bill requires the Election Assistance Commission to mandate penetration testing as part of voting system hardware and software certification, decertification, and recertification within 180 days. NIST recommends entities, amends the Help America Vote Act to establish a 5-year Independent Security Testing and Coordinated Vulnerability Disclosure Pilot Program (VDP-E) for election systems, and creates new Section 297 of HAVA establishing the VDP-E program with detailed requirements: vendor source code access for researchers, background checks, 180-day confidentiality, mandatory patching of critical/high.

Key Policy Areas

Technology

Primary Purpose

The bill requires the Election Assistance Commission to mandate penetration testing as part of voting system hardware and software certification, decertification, and recertification within 180 days. NIST recommends entities, amends the Help America Vote Act to establish a 5-year Independent Security Testing and Coordinated Vulnerability Disclosure Pilot Program (VDP-E) for election systems, and creates new Section 297 of HAVA establishing the VDP-E program with detailed requirements: vendor source code access for researchers, background checks, 180-day confidentiality, mandatory patching of critical/high.

Policy Domains

Technology

Section 2 - Penetration Testing for Voting System Certification

Identified Gains
  • Cybersecurity researchers receiving CFAA and DMCA safe harbor
  • Cybersecurity researchers participating in VDP-E
  • Cybersecurity firms and penetration testing companies
  • State and local election officials receiving security patches
Model: codex-gpt-5:bulk-repair | Version: bill_summary_v2 | Source: ih
Cybersecurity researchers participating in VDP-E:
Cybersecurity firms and penetration testing companies:
Cybersecurity researchers receiving CFAA and DMCA safe harbor:
State and local election officials receiving security patches:
Identified Costs
  • Election system vendors required to share source code and patch critical vulnerabilities
  • Election system vendors seeking EAC certification
  • Election system vendors required to provide systems and patch vulnerabilities
  • Election Assistance Commission administering the program
  • Election Assistance Commission
Model: codex-gpt-5:bulk-repair | Version: bill_summary_v2 | Source: ih
Election Assistance Commission:
Election system vendors seeking EAC certification:
Election Assistance Commission administering the program:
Election system vendors required to provide systems and patch vulnerabilities:
Election system vendors required to share source code and patch critical vulnerabilities:

Legislative Progress

Introduced
Introduced Committee Passed
Nov 25, 2025

Mr. Valadao (for himself and Mr. Deluzio) introduced the following …

Stakeholder Effects

cui bono?

How this legislation distributes effects. Mention counts reflect frequency, not effect magnitude.

Technology
6 mentions across 3 clauses
+3 positive -3 negative

Cybersecurity firms and penetration testing companies, Cybersecurity researchers participating in VDP-E, Cybersecurity researchers receiving CFAA and DMCA safe harbor

Positive-direction: Cybersecurity firms and penetration testing companies, Cybersecurity researchers participating in VDP-E, Cybersecurity researchers receiving CFAA and DMCA safe harbor

Negative-direction: Election system vendors required to provide systems and patch vulnerabilities, Election system vendors required to share source code and patch critical vulnerabilities, Election system vendors seeking EAC certification

Government
3 mentions across 3 clauses
+1 positive -2 negative

Election Assistance Commission, Election Assistance Commission administering the program, State and local election officials receiving security patches

Positive-direction: State and local election officials receiving security patches

Negative-direction: Election Assistance Commission, Election Assistance Commission administering the program

3/4
sections analyzed
Full impact breakdown

Bill Structure & Actor Mappings

Who is "The Secretary" in each section?

Domains
Technology
Actor Mappings
"the_commission"
→ Election Assistance Commission
"the_director_nist"
→ Director of NIST
Domains
Cybersecurity Elections
Actor Mappings
"the_secretary"
→ Secretary of Homeland Security
"the_commission"
→ Election Assistance Commission
"the_director_cisa"
→ Director of CISA

Key Definitions

Terms defined in this bill

5 terms
"cybersecurity vulnerability" §297(e)(1)

Any security vulnerability that affects an election system

"election infrastructure" §297(e)(2)

Storage facilities, polling places, centralized vote tabulation locations, and related ICT including voter registration databases, election management systems, voting machines, and communications systems

"election system" §297(e)(3)

Any information system that is part of election infrastructure

"election system vendor" §297(e)(4)

Any person providing, supporting, or maintaining an election system on behalf of State or local election officials

"Secretary" §297(e)(6)

Secretary of Homeland Security

We use a combination of our own taxonomy and classification in addition to large language models to assess meaning and potential beneficiaries. High confidence means strong textual evidence. Always verify with the original bill text.

Learn more about our methodology