---
title: "Analyzing the Securing Open Source Software Act"
description: "An overview of the Securing Open Source Software Act, its implications for federal agencies, and potential effects on the private sector."
canonical_url: "https://fossa.com/blog/analyzing-securing-open-source-software-act/"
markdown_url: "https://fossa.com/blog/analyzing-securing-open-source-software-act.md"
content_type: "blog"
language: "en"
date_published: "2022-09-29"
date_modified: "2022-09-29"
author: "Andy Drukarev"
organization: "FOSSA"
---

# Analyzing the Securing Open Source Software Act

> An overview of the Securing Open Source Software Act, its implications for federal agencies, and potential effects on the private sector.

<p>
  On Sept. 22, 2022, U.S. Senators Gary Peters (D-MI) and Rob Portman (R-OH) introduced bipartisan
  legislation to strengthen open source software security: the
  <a href="https://www.hsgac.senate.gov/media/majority-media/peters-and-portman-introduce-bipartisan-legislation-to-help-secure-open-source-software_#:~:text=WASHINGTON%2C%20DC%20%E2%80%93%20U.S.%20Senators%20Gary,security%20of%20open%20source%20software.">
    <em>Securing Open Source Software Act</em>
  </a>
  .
</p>

<p>
  If enacted, the legislation would instruct the U.S. Cybersecurity and Infrastructure Security
  Agency (CISA) to develop a framework for assessing the risk of open source components used by
  federal agencies. It would also amend the Homeland Security Act of 2002 to formally recognise open
  source software as part of the nation’s critical infrastructure.
</p>

<p>
  The proposed bill has its roots in the
  <a href="https://fossa.com/blog/quickly-find-remediate-log4j-vulnerabilities-log4shell/">
    Log4j vulnerability
  </a>
  (also known as “Log4Shell”), which caused widespread and significant damage, including to federal
  systems and critical infrastructure. Although the private sector has steadily increased interest
  and funding for open source security efforts, Log4j served as a wake-up call of sorts for the
  federal government.
</p>

<p>
  The <em>Securing Open Source Software Act</em> aims to guard against Log4Shell-like incidents by
  mitigating risk in systems that use open source and strengthening collaboration between the
  government and open source communities.
</p>

<p>
  “As we saw with the Log4Shell vulnerability, the computers, phones, and websites we all use every
  day contain open source software that is vulnerable to cyberattack,” Senator Portman said in a
  statement announcing the legislation<strong>.</strong> “The bipartisan
  <em>Securing Open Source Software Act</em> will ensure that the U.S. government anticipates and
  mitigates security vulnerabilities in open source software to protect Americans’ most sensitive
  data.”
</p>

> <b>
> <strong style={{ whiteSpace: 'pre-wrap' }}>RELATED: </strong>
> </b>
> <a
> href="https://gateway.on24.com/wcc/eh/4613607/lp/4641169/the-dos-and-donts-of-using-sboms-for-security?utm_source=fossa&amp;utm_medium=blog"
> rel="noreferrer"
> >
> <b>
> <strong style={{ whiteSpace: 'pre-wrap' }}>
> The Dos and Don'ts of Using SBOMs for Security
> </strong>
> </b>
> </a>

## Key Provisions in the Securing Open Source Software Act

<p>
  The proposed legislation includes several new requirements for CISA, the U.S. government’s
  Cybersecurity and Infrastructure Security Agency. It extends the agency’s current responsibilities
  to supporting the secure usage and deployment of software, including open source software
  throughout the software development lifecycle at federal agencies.
</p>

<p>These updated duties include:</p>
<ul>
  <li>
    Establishing a framework for assessing the risk of open source components; the framework should
    incorporate best practices from government bodies, private industry, and open source communities
  </li>
  <li>Coordinating with federal agencies to bolster open source software security</li>
  <li>
    Serving as a public point of contact regarding open source software security for state, local,
    and private entities
  </li>
  <li>Assisting with coordinated vulnerability disclosures for open source software</li>
  <li>Employing individuals with open source expertise and experience</li>
</ul>

<p>
  As you might expect, specific elements of the open source risk assessment framework have not been
  finalised. But, at minimum, the proposed law directs CISA to consider the following factors:
</p>
<ol>
  <li>The security properties of code</li>
  <li>The security practices of code development and deployment</li>
  <li>The number and nature of vulnerabilities in an open source software component</li>
  <li>The breadth of deployment of an open source software component</li>
  <li>The level of risk associated with each open source software component</li>
  <li>The health of the community around each open source software component.</li>
</ol>

<p>
  CISA would then use this framework to conduct an assessment of all open source software in use at
  federal agencies.
</p>

## Duties and Timelines for Federal Agencies

<p>
  The <em>Securing Open Source Software Act</em> includes a timeline for CISA to complete the
  required activities. Key dates are as follows:
</p>
<ul>
  <li>
    <strong>Within one year</strong>: Develop and publicly publish the risk assessment framework
  </li>
  <li>
    <strong>Annually</strong>: Update the framework as needed
  </li>
  <li>
    <strong>
      Within one year of the publishing date of the framework, and every two years thereafter:
    </strong>
    Conduct an assessment of open source software components used by federal agencies; the
    assessment should be based on information such as software bill of materials (SBOMs), software
    inventories obtained through the CISA, and publicly available information.
  </li>
  <li>
    <strong>
      Within one year of the enactment of the legislation, and every two years thereafter
    </strong>
    : Submit a report to congressional committees regarding their activities on open source
    software, including the framework and assessments developed under the legislation
  </li>
</ul>

### Responsibilities for Other Departments

<p>
  While CISA is tasked with leading most of the activities in the proposed legislation, several
  other agencies will also pick up additional responsibilities.
</p>

<p>
  For example, the bill would instruct the Director of the Office of Management and Budget (OMB) to
  issue guidance for CIOs at covered federal agencies (major executive departments such as the
  Department of Commerce and Department of Defense) regarding the use of open source software. This
  guidance includes best practices for open source software usage, how to minimise the risks around
  open source software, and how to contribute to open source projects.
</p>

<p>
  Additionally, the CIO of each covered agency would be directed to establish a pilot
  <a href="https://fossa.com/blog/building-open-source-program-office-ospo/">
    open source program office
  </a>
  of sorts. These OSPO-type functions would develop policies and processes around using open source,
  releasing open source, and collaborating with the broader open source community.
</p>

## What the Securing Open Source Software Act Means for Private Entities

<p>
  Although the proposed legislation would only directly impact federal agencies, it would still be
  relevant to the private sector. This is the case for many of the same reasons that the
  mid-September 2022
  <a href="https://fossa.com/blog/omb-memo-requires-self-attestation-secure-development-practices/">
    self-attestation memo
  </a>
  and the 2021 cybersecurity executive order impacted private enterprises.
</p>

<p>
  For one, many of these new and proposed regulations require organisations to provide a software
  bill of materials (and/or similar software inventory) when selling into the federal government.
</p>

<p>
  Additionally, regulatory action on
  <a href="https://fossa.com/learn/sboms" rel="noreferrer">
    SBOMs and software transparency
  </a>
  are trickling down to the private sector — we’re seeing more and more businesses require SBOM-type
  documentation as part of the procurement process.
</p>

<p>
  In other words, the public and private sectors are continuing to prioritise
  <a href="https://fossa.com/software-supply-chain-security">software supply chain security</a>.
  And, this puts a premium on capabilities like SBOM generation, understanding the direct and
  transitive dependencies in your software, and having effective vulnerability management programs.
</p>

<p>
  <a href="https://fossa.com/complete-guide-software-composition-analysis">
    Software composition analysis
  </a>
  tools like FOSSA play an important role in managing these processes. FOSSA provides a
  comprehensive inventory of your software dependencies and automates vulnerability management and
  SBOM creation. For more information on getting started with FOSSA,
  <a href="https://fossa.com/request-demo">please reach out to our team</a>.
</p>

## Related resources

- [Analyzing 5 Major OSS License Compliance Lawsuits](https://fossa.com/blog/analyzing-5-major-oss-license-compliance-lawsuits.md): Learn about five lawsuits that have helped shape global enforcement of open source software licenses.
- [May 2025 FOSSA Product Updates](https://fossa.com/blog/may-2025-product-updates.md): Learn about several recent FOSSA product updates, including container scanning and CycloneDX report improvements.
- [Annotate Dependencies with Context: Introducing Package Labels in FOSSA](https://fossa.com/blog/annotate-dependencies-context-introducing-package-labels.md): Introducing FOSSA Package Labels - a powerful way to annotate packages with contextual metadata, enabling more efficient and insightful reporting and filtering.
- [License Compliance, SBOM, and Vulnerability Management for Smaller Teams: FOSSA Business Tier](https://fossa.com/blog/fossa-business-tier.md): FOSSA introduces a new business tier tailored for smaller teams, offering flexible pricing and comprehensive features for SBOM, vulnerability management, and license compliance.
- [Fall 2024 Software Licensing Roundup](https://fossa.com/blog/fall-2024-software-licensing-roundup.md): Explore the significant licensing stories of fall 2024, including Elastics return to open source, the new fair source licensing model, and the PearAI controversy.

## Source

Canonical page: https://fossa.com/blog/analyzing-securing-open-source-software-act/
