Skip to main content
HR 451 114th Congress House Government Operations and Politics Administrative law and regulatory procedures Computer security and identity theft Government information and archives Internet and video services Internet, web applications, social media Office of Management and Budget (OMB) Right of privacy

Safe and Secure Federal Websites Act of 2015

Introduced: May 14, 2015 Introduced by: Fleischmann, Charles J. "Chuck" Republican · Tennessee See on congress.gov
This bill died when the 114th Congress ended
It never became law before the 114th Congress (2015–2016) adjourned, and bills don't carry over to the next Congress. It would have to be reintroduced. You can still save it for reference, but it won't receive updates.
 Everywhere this bill has been 6 steps
Introduced
In committee
Reported out
Passed House
Passed Senate
To President
Became law
Jan 6, 2016
Placed on the Union Calendar, Calendar No. 293.
Jan 6, 2016
Reported (Amended) by the Committee on Oversight and Government Reform. H. Rept. 114-390.
May 19, 2015
Ordered to be Reported (Amended) by Voice Vote.
May 19, 2015
Committee Consideration and Mark-up Session Held.
Jan 21, 2015
Introduced in House
Jan 21, 2015
Referred to the House Committee on Oversight and Government Reform.
 Ask about this bill AI · grounded in the bill text

Have a question about what this bill does? Ask in plain English; the answer is drawn from the bill's actual text and official record, and it'll tell you when something isn't in the text rather than guess.

AI answers can be imperfect; always confirm against the full bill text.

 Plain-English summary Congressional Research Service

Safe and Secure Federal Websites Act of 2015

This bill establishes security and privacy requirements for new federal websites that collect personally identifiable information (PII) (i.e., information that can be used to distinguish or trace the identity of an individual or that is linked or linkable to an individual).

(Sec. 2) A federal agency may not deploy or make available to the public a new federal PII website until the agency's chief information officer (CIO) certifies to Congress that the website is fully functional and secure. The CIO must make such certification within 90 days after enactment of this Act. After such 90-day period, any new federal PII website that has not been certified must be rendered inaccessible until certification is submitted.

The prohibition does not apply to a website that is: (1) operated entirely by an entity that is independent of the federal government, or (2) in a development or testing phase (beta website). The exemption for beta websites applies only if: (1) a member of the public may access PII-related portions of the website only after executing an agreement that acknowledges the risks involved; and (2) no agency compelled, enjoined, or otherwise provided incentives for a member of the public to access such website.

The bill defines a "new federal PII website" as a website that: (1) is operated by (or under contract with) an agency; (2) elicits, collects, stores, or maintains PII and is accessible to the public; and (3) is first made accessible to the public and collects or stores PII on or after October 1, 2012. The bill also sets forth requirements that must be met to deem a new federal PII website as "secure."

(Sec. 3) The Director of the Office of Management and Budget (OMB) must establish and oversee policies and procedures for federal agencies to follow in the event of a breach of information security involving the disclosure of PII, including: (1) notice, not later than 72 hours after discovery of a breach or possible breach, to individuals whose PII could be compromised; and (2) timely reporting to a federal cybersecurity center designated by the OMB and defined in this Act.

Agency heads must ensure that agency actions taken in response to a breach of information security involving the disclosure of PII comply with OMB policies and procedures established by this Act. The OMB must report to Congress, not later than March 1 of each year, on agency compliance with such policies and procedures.

A "federal cybersecurity center" is defined to include: (1) the Department of Defense Cyber Crime Center, (2) the Intelligence Community Incident Response Center, (3) the U.S. Cyber Command Joint Operations Center, (4) the National Cyber Investigative Task Force, (5) the Central Security Service Threat Operations Center of the National Security Agency, (6) the U.S. Computer Emergency Readiness Team, and (7) any center that the OMB determines is appropriate to carry out privacy breach notice and reporting requirements.

What's happening now January 6, 2016

Placed on the Union Calendar, Calendar No. 293.

 Bill text 2 versions

Source documents hosted by congress.gov.

 Committees of jurisdiction 1
Cite this page click to expand
APA
U.S. Congress. (2026). H.R. 451: Safe and Secure Federal Websites Act of 2015. 114th Congress. Open America. https://openamerica.io/bill/114-HR-451/
MLA
"H.R. 451: Safe and Secure Federal Websites Act of 2015." 114th Congress, 2026, Open America, https://openamerica.io/bill/114-HR-451/.
Bluebook (legal)
H.R. 451, 114th Cong. (2026), https://openamerica.io/bill/114-HR-451/.
Markdown link
[H.R. 451: Safe and Secure Federal Websites Act of 2015](https://openamerica.io/bill/114-HR-451/)
Report a problem