Skip to main content
S 917 118th Congress Senate Government Operations and Politics Advisory bodies Computer security and identity theft Computers and information technology Congressional oversight Government information and archives Government studies and investigations Performance measurement

Securing Open Source Software Act of 2023

Introduced: March 22, 2023 Introduced by: Peters, Gary C. Democratic · Michigan See on congress.gov
This bill died when the 118th Congress ended
It never became law before the 118th Congress (2023–2024) adjourned, and bills don't carry over to the next Congress. It would have to be reintroduced. You can still save it for reference, but it won't receive updates.
 Everywhere this bill has been 5 steps
Introduced
In committee
Reported out
Passed House
Passed Senate
To President
Became law
May 16, 2023
Placed on Senate Legislative Calendar under General Orders. Calendar No. 76.
May 16, 2023
Committee on Homeland Security and Governmental Affairs. Reported by Senator Peters with amendments. With written report No. 118-32.
Mar 29, 2023
Committee on Homeland Security and Governmental Affairs. Ordered to be reported without amendment favorably.
Mar 22, 2023
Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
Mar 22, 2023
Introduced in Senate
 Ask about this bill AI · grounded in the bill text

Have a question about what this bill does? Ask in plain English; the answer is drawn from the bill's actual text and official record, and it'll tell you when something isn't in the text rather than guess.

AI answers can be imperfect; always confirm against the full bill text.

 Plain-English summary Congressional Research Service

Securing Open Source Software Act of 2023

This bill sets forth the duties of the Cybersecurity and Infrastructure Security Agency (CISA) regarding open source software security.

Open source software means software for which the human-readable source code is made available to the public for use, study, reuse, modification, enhancement, and redistribution.

Specifically, CISA must

  • perform outreach and engagement to bolster the security of open source software;
  • support federal efforts to strengthen open source software security;
  • coordinate with nonfederal entities on efforts to ensure long-term open source software security;
  • serve as a public point of contact regarding open source software security for nonfederal entities; and
  • support federal and nonfederal supply chain security efforts by encouraging efforts to bolster open source software security.

CISA must (1) publish a framework, incorporating government, industry, and open source software community frameworks and best practices, for assessing the risk of open source software components; (2) update the framework at least annually; and (3) ensure, to the greatest extent practicable, that the framework is usable by the open source software community.

The bill requires CISA to assess open source software components used by federal agencies based on the framework and provides for a pilot assessment of critical infrastructure.

CISA's Cybersecurity Advisory Committee may establish a software security subcommittee.

The Office of Management and Budget, in coordination with CISA, the Office of the National Cyber Director, and the General Services Administration, shall issue guidance on the responsibilities of the chief information officers at specified agencies regarding open source software.

What's happening now May 16, 2023

Placed on Senate Legislative Calendar under General Orders. Calendar No. 76.

 Bill text 2 versions

Source documents hosted by congress.gov.

 Committees of jurisdiction 1
 Lobbying activity 3

Registered lobbyists who named this bill in their disclosure filings. Source: federal Lobbying Disclosure Act filings.

Cite this page click to expand
APA
U.S. Congress. (2026). S. 917: Securing Open Source Software Act of 2023. 118th Congress. Open America. https://openamerica.io/bill/118-S-917/
MLA
"S. 917: Securing Open Source Software Act of 2023." 118th Congress, 2026, Open America, https://openamerica.io/bill/118-S-917/.
Bluebook (legal)
S. 917, 118th Cong. (2026), https://openamerica.io/bill/118-S-917/.
Markdown link
[S. 917: Securing Open Source Software Act of 2023](https://openamerica.io/bill/118-S-917/)
Report a problem