FISMA
FISMA: Coordination with FedRAMP, EO 14028, OMB Memoranda and Status

FISMA FISMA-Reform-Pipeline: FISMA 2.0 Reform Pipeline, Legislative Activity and Future State

FISMA 2.0 reform pipeline + legislative activity. PROPOSED LEGISLATION: (a) FISMA REFORM ACT OF 2023 (S.2251 + H.R.6395 of the 118th Congress) introduced by Senators Peters (D-MI) + Lankford (R-OK) + bipartisan support; would: (i) ELEVATE CISA authority + consolidate federal cybersecurity oversight; (ii) extend FISMA-like reporting to CRITICAL INFRASTRUCTURE entities beyond federal agencies; (iii) align incident-reporting timelines with CIRCIA; (iv) require AGENCY VULNERABILITY DISCLOSURE POLICIES + bug bounty programs (mandatory); (v) strengthen SUPPLY CHAIN RISK MANAGEMENT requirements per EO 14017 + the 2024 OMB ICT supply chain guidance; (vi) align with the NATIONAL CYBERSECURITY STRATEGY (March 2023); (b) NCD AUTHORIZATION ACT - codifies the National Cyber Director role + budget oversight; (c) FEDERAL CYBERSECURITY VULNERABILITY REDUCTION ACT - mandates federal vulnerability disclosure programs. STATUS: as of early 2026, FISMA 2.0 reform proposals have advanced through committee in both chambers but have NOT been enacted into law; the 119th Congress (January 2025 to January 2027) is considering revised text. KEY DEBATES: (i) scope expansion to critical infrastructure beyond federal agencies; (ii) CISA vs OMB authority allocation; (iii) supply-chain + foreign-vendor restrictions; (iv) AI integration; (v) state + local + tribal coordination via StateRAMP + GovRAMP. EXECUTIVE ACTION: in absence of legislation, the Administration is acting through OMB Memoranda + Executive Orders + CISA BODs.

Maintained by Gerard BlokdykControl text last updated

Other controls in FISMA: Coordination with FedRAMP, EO 14028, OMB Memoranda and Status

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.