"To further incentivize the adoption of secure software development practices, the Administration will encourage coordinated vulnerability disclosure across all technology types and sectors."
Requires NIST to issue guidance identifying practices that enhance security of the software supply chain. In the guidance NIST must include standards, procedures, or criteria related to, among other issues, "participating in a vulnerability disclosure program that includes a reporting and disclosure process."
App Store Operators and App Developers listing apps on them should have a VDP (contact details/contact form); App Store Operators should verify that App Developers abide by these practices; App Store Operators should accept vulnerability disclosure reports on behalf of App Developers if they have not acknowledged the vulnerability - if the App Developer still fails to acknowledge the vulnerability, the App Store Operator should delist the app from its platform.