 Pillar Three: Shape Market Forces to Drive Security and Resilience 3.2 3.3 3.4 3.5 3.6 8 Drive the Development of Secure IoT Devices 3.2.1 Implement Federal Acquisition Regulation (FAR) requirements per the Internet of Things (IoT) Cybersecurity Improvement Act of 2020 3.2.2 Initiate a U.S. Government IoT security labeling program Shift Liability for Insecure Software Products and Services 3.3.1 Explore approaches to develop a long-term, flexible, and enduring software liability framework 3.3.2 Advance software bill of materials (SBOM) and mitigate the risk of unsupported software 3.3.3 Coordinated vulnerability disclosure Use Federal Grants and Other Incentives to Build in Security 3.4.1 Leverage Federal grants to improve infrastructure cybersecurity 3.4.2 Prioritize funding for cybersecurity research 3.4.3 Prioritize cybersecurity research, development, and demonstration on social, behavioral, and economic research in cybersecurity Leverage Federal Procurement to Improve Accountability 3.5.1 Implement Federal Acquisition Regulation (FAR) changes required under EO 14028 3.5.2 Leverage the False Claims Act to improve vendor cybersecurity Explore a Federal Cyber Insurance Backstop 3.6.1 Assess the need for a Federal insurance response to a catastrophic cyber event NATIONAL CYBERSECURITY STRATEGY IMPLEMENTATION PLAN

Select target paragraph3