Strategic Objective 3.5: Leverage Federal Procurement to
Improve Accountability
Initiative Number: 3.5.1
Initiative Title: Implement Federal Acquisition Regulation (FAR) changes required under EO
14028
Initiative Description
The Office of Management and Budget, acting through the Office of Federal Procurement
Policy, will work with the Federal Acquisition Regulatory Council to propose changes to the
FAR required under EO 14028. Through the release of draft rules (cybersecurity incident
reporting, standardizing cybersecurity contract requirements, and secure software) public
comment will be considered before the changes are finalized.
NCS Reference
EO 14028, "Improving the Nation's Cybersecurity," expands upon this approach, ensuring that
contract requirements for cybersecurity are strengthened and standardized across Federal
agencies.
Responsible Agency: OMB
Completion Date: 1Q FY24
Initiative Number: 3.5.2
Initiative Title: Leverage the False Claims Act to improve vendor cybersecurity
Initiative Description
The Department of Justice will expand efforts to identify, pursue, and deter knowing failures to
comply with cybersecurity requirements in Federal contracts and grants with the aim of building
resilience, increasing vulnerability disclosures, reducing the competitive disadvantage for
responsible vendors, and recovering damages for affected Federal programs and agencies.
NCS Reference
The Civil Cyber-Fraud Initiative (CCFI) uses DOJ authorities under the False Claims Act to
pursue civil actions against government grantees and contractors who fail to meet cybersecurity
obligations. The CCFI will hold accountable entities or individuals that put U.S. information or
systems at risk by knowingly providing deficient cybersecurity products or services, knowingly
misrepresenting their cybersecurity practices or protocols, or knowingly violating obligations to
monitor and report cyber incidents and breaches.
Responsible Agency: DOJ
Completion Date: 4Q FY25
NATIONAL CYBERSECURITY STRATEGY
IMPLEMENTATION PLAN
33