
Loading

Loading
We use strictly necessary cookies to run this site, and — only with your consent — analytics cookies to understand how it's used. See our Privacy Policy for details.
The Business Software Alliance in a recent letter to House and Senate Armed Services and party leaders highlights provisions the trade group supports in the pending fiscal 2027 National Defense Authorization Act, including on cybersecurity, artificial intelligence, post-quantum computing, procurement and tech modernization, while flagging a handful of concerns over language putting place requirements related to China.
Summary
“Thank you for your leadership in advancing this year’s NDAA. These provisions will determine how effectively the Department can leverage commercial innovation, strengthen IT infrastructure, and responsibly harness AI and quantum technologies. We stand ready to work with you and your staff to refine these provisions and ensure a strong, future-ready NDAA,” BSA CEO Victoria Espinel says in the letter dated Aug.
27. It was publicly shared on Sept. 10.
The detailed letter was addressed to House Speaker Mike Johnson (R-LA) and Minority Leader Hakeem Jeffries (D-NY), Senate Majority Leader John Thune (R-SD) and Minority Leader Charles Schumer (D-NY), and the chairs and ranking members of the House and Senate Armed Services committees. Most notably, the letter backs the reauthorization of the Cybersecurity Information Sharing Act of 2015 through fiscal 2035, which was included in the House version of the fiscal 2027 NDAA. A short-term extension of CISA 2015 was included in a continuing resolution to fund the government until Dec.
11. The letter says CISA 2015 “provides the foundation for industry and government to efficiently share cyber threat information.” The House in July passed its version of the annual defense policy bill but the measure stalled in the Senate prior to floor action. It appears that House and Senate negotiators will work from the House-passed and Senate committee-passed language as the basis for a final NDAA agreement.
The negotiations will likely extend into a lame-duck session of Congress in November. The software trade group in the release points to “BSA-supported provisions” including: [House] Rules Committee Print 119-33, Amendment #800: Establishes a FedRAMP high reciprocity pilot for DoD cloud security requirements. House Sec.
830: Establishes permanent, government-wide authority to acquire services through consumption-based, usage-billed solutions. House Sec. 1523: Establishes a framework to accelerate deployment of AI models within the Department.
BSA supports this language, and we ask that conferees ensure alignment with commercial AI acquisition preferences. House Sec. 1507: Requires covered contractors to implement a vulnerability disclosure policy consistent with NIST guidelines, with FAR Council follow-through and CIO waiver authority.
BSA supports this language that aligns cyber requirements to NIST and international standards. On cybersecurity, the letter highlights several measures including: House Sec. 1507: Requires covered contractors to implement a vulnerability disclosure policy consistent with NIST guidelines, with FAR Council follow-through and CIO waiver authority.
BSA supports this language that aligns cyber requirements to NIST and international standards. [House] Rules Committee Print 119-33, Amendment #1175, Offered by Reps. Moore and Harrigan: Establishes an Army Quantum Readiness and Advanced Computing Initiative. Senate Sec.
1631: Mandates that DoD cryptographic solutions adopt NIST-approved post-quantum algorithms for key establishment by December 31, 2030, and for digital signatures by December 31, 2031. Senate Amendment 6664 (Young): Comprehensively reauthorizes and modernizes the National Quantum Initiative through 2034, expanding DOE/NIST/NSF/NASA quantum R&D and adding a postquantum cryptography upgrade strategy. BSA raises concerns over an amendment in the House NDAA from Rep.
Troy Nehls (R-TX) to “require the Department to review existing programs and implement software-based cryptographic protections in place of hardware-based approaches.” The letter says, “While intended to advance the Department’s post-quantum transition and reduce vendor lock-in, the provision as drafted uses non-standard cryptographic parameters that conflict with commercial cloud key-management architectures, raises IP disclosure risks for vendors, and embeds procurement terms within what is framed as a security mandate.” A separate amendment from House Homeland Security cyber subcommittee Chairman Andy Ogles (R-TN) also comes up in the letter. BSA says the provision “[b]ars DoD contracts with providers that give advance vulnerability disclosure to countries-of-concern entities.” The letter says, “Coordinated vulnerability disclosure is a standard commercial software and hardware security practice, and this provision could be read broadly enough to capture routine practices rather than only adversary-facing ones. BSA opposes this provision and asks that conferees not include it in the final bill.” An amendment to the House bill from Rep.
Nick Begich (R-AK) also comes up. The letter says the provision “[a]dds a 72-hour reporting deadline for discovering Chinese-linked hardware, software, or firmware in covered contractor networks, layered onto existing cyber incident reporting requirements. BSA opposes this provision as currently drafted and asks that conferees not include it in the final bill.” On artificial intelligence, the letter says, “AI continues to represent a critical area for national security innovation, and BSA supports measures that accelerate secure, competitive AI adoption within the Department.” BSA’s Espinel notes in the letter, “BSA represents the global enterprise software sector, whose innovations underpin U.S. competitiveness in cybersecurity, cloud infrastructure, data analytics, artificial intelligence (AI), and supply chain resilience.
KazaSec's take
A newly disclosed vulnerability is only a real risk to your organization once it's confirmed present and exploitable in your own environment — not every CVE applies equally to every network. Knowing the difference is exactly what a proper vulnerability assessment is for.
Coverage details
Relevant from KazaSec
More security news
We help organizations find and fix the gaps before they make headlines.