To amend the Help America Vote Act of 2002 to require the Election Assistance Commission to provide for the conduct of penetration testing as part of the testing and certification of voting systems and to provide for the establishment of an Independent Security Testing and Coordinated Vulnerability Disclosure Pilot Program for Election Systems.
Summary
What This Bill Does
The bill requires the Election Assistance Commission to mandate penetration testing as part of voting system hardware and software certification, decertification, and recertification within 180 days. NIST recommends entities, amends the Help America Vote Act to establish a 5-year Independent Security Testing and Coordinated Vulnerability Disclosure Pilot Program (VDP-E) for election systems, and creates new Section 297 of HAVA establishing the VDP-E program with detailed requirements: vendor source code access for researchers, background checks, 180-day confidentiality, mandatory patching of critical/high. It relies on compliance mandates, liability protections, exemptions, and product standards. The main policy areas are Technology.
Who Benefits and How
Cybersecurity researchers receiving CFAA and DMCA safe harbor could face reduced risk, Cybersecurity researchers participating in VDP-E could face reduced risk, and Cybersecurity firms and penetration testing companies could gain revenue opportunities.
Who Bears the Burden and How
Election system vendors required to share source code and patch critical vulnerabilities would take on compliance duties, Election system vendors seeking EAC certification would take on compliance duties, and Election system vendors required to provide systems and patch vulnerabilities would take on compliance duties.
Key Provisions
- Requires the Election Assistance Commission to mandate penetration testing as part of voting system hardware and software certification, decertification, and recertification within 180 days. NIST recommends entities...
- Amends the Help America Vote Act to establish a 5-year Independent Security Testing and Coordinated Vulnerability Disclosure Pilot Program (VDP-E) for election systems.
- Creates new Section 297 of HAVA establishing the VDP-E program with detailed requirements: vendor source code access for researchers, background checks, 180-day confidentiality, mandatory patching of critical/high...
Evidence Chain:
This summary is generated from the full bill text using AI analysis. Expand "Detailed Analysis" below for identified beneficiaries/burden bearers with clause-level evidence links.
At a Glance
What This Bill Does
The bill requires the Election Assistance Commission to mandate penetration testing as part of voting system hardware and software certification, decertification, and recertification within 180 days. NIST recommends entities, amends the Help America Vote Act to establish a 5-year Independent Security Testing and Coordinated Vulnerability Disclosure Pilot Program (VDP-E) for election systems, and creates new Section 297 of HAVA establishing the VDP-E program with detailed requirements: vendor source code access for researchers, background checks, 180-day confidentiality, mandatory patching of critical/high.
Key Policy Areas
Technology
Primary Purpose
The bill requires the Election Assistance Commission to mandate penetration testing as part of voting system hardware and software certification, decertification, and recertification within 180 days. NIST recommends entities, amends the Help America Vote Act to establish a 5-year Independent Security Testing and Coordinated Vulnerability Disclosure Pilot Program (VDP-E) for election systems, and creates new Section 297 of HAVA establishing the VDP-E program with detailed requirements: vendor source code access for researchers, background checks, 180-day confidentiality, mandatory patching of critical/high.
Policy Domains
Section 2 - Penetration Testing for Voting System Certification
Identified Gains
- Cybersecurity researchers receiving CFAA and DMCA safe harbor
- Cybersecurity researchers participating in VDP-E
- Cybersecurity firms and penetration testing companies
- State and local election officials receiving security patches
Identified Costs
- Election system vendors required to share source code and patch critical vulnerabilities
- Election system vendors seeking EAC certification
- Election system vendors required to provide systems and patch vulnerabilities
- Election Assistance Commission administering the program
- Election Assistance Commission
Sponsors
Legislative Progress
IntroducedMr. Valadao (for himself and Mr. Deluzio) introduced the following …
Stakeholder Effects
cui bono?How this legislation distributes effects. Mention counts reflect frequency, not effect magnitude.
Cybersecurity firms and penetration testing companies, Cybersecurity researchers participating in VDP-E, Cybersecurity researchers receiving CFAA and DMCA safe harbor
Positive-direction: Cybersecurity firms and penetration testing companies, Cybersecurity researchers participating in VDP-E, Cybersecurity researchers receiving CFAA and DMCA safe harbor
Negative-direction: Election system vendors required to provide systems and patch vulnerabilities, Election system vendors required to share source code and patch critical vulnerabilities, Election system vendors seeking EAC certification
Election Assistance Commission, Election Assistance Commission administering the program, State and local election officials receiving security patches
Positive-direction: State and local election officials receiving security patches
Negative-direction: Election Assistance Commission, Election Assistance Commission administering the program
Bill Structure & Actor Mappings
Who is "The Secretary" in each section?
- "the_commission"
- → Election Assistance Commission
- "the_director_nist"
- → Director of NIST
- "the_secretary"
- → Secretary of Homeland Security
- "the_commission"
- → Election Assistance Commission
- "the_director_cisa"
- → Director of CISA
Key Definitions
Terms defined in this bill
Any security vulnerability that affects an election system
Storage facilities, polling places, centralized vote tabulation locations, and related ICT including voter registration databases, election management systems, voting machines, and communications systems
Any information system that is part of election infrastructure
Any person providing, supporting, or maintaining an election system on behalf of State or local election officials
Secretary of Homeland Security
We use a combination of our own taxonomy and classification in addition to large language models to assess meaning and potential beneficiaries. High confidence means strong textual evidence. Always verify with the original bill text.
Learn more about our methodology