Congressional Legislation · bill 119hr872 · built from our database

Both sides have signed this (Bill Ranking)

Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025

H.R. 872 · 119th Congress (2025-2026)

H.R. 872119TH CONGRESSINTRODUCED 01/31/2025REP. MACER-SC · SPONSORLeft: no (Sponsor Ranking)Lean left: no (Sponsor Ranking)Center: no (Sponsor Ranking)Lean right: DW-NOMINATE +0.35 (Sponsor Ranking)Right: no (Sponsor Ranking)LEAN RIGHT(SPONSOR RANKING)GOVERNMENT OPERATIONS AND POLITICS

2 members · Left 1 · Center 0 · Right 1 (Bill Ranking)

SponsorRep. Mace, Nancy (R-SC) (Introduced 01/31/2025)
Sponsor Voting RecordLean right · DW-NOMINATE +0.35 · measured from every roll-call vote this member has cast (voteview.com) (Sponsor Ranking)
Support
LLLCLRR

support across the spectrum: 2 members signed on (Bill Ranking) this bill: sponsor + current cosponsors, each once

CommitteesSenate - Homeland Security and Governmental Affairs Committee; House - Armed Services Committee; House - Oversight and Government Reform Committee
Latest Action03/04/2025 Received in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
Roll Call VotesThere have been no roll call votes
Sourceview on congress.gov →
IntroducedPassed HousePassed SenateResolving DifferencesTo PresidentBecame Law

Summary (1)

Introduced in House (01/31/2025)

Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025

This bill requires revisions to acquisition regulations related to information systems vulnerabilities for certain federal contractors. The revisions apply to contractors whose contract is at or above the simplified acquisition threshold ($250,000 in most cases) or that use, operate, manage, or maintain a federal information system on behalf of an agency. 

Under the bill, the Office of Management and Budget must review the Federal Acquisition Regulation (FAR) and recommend updated contract requirements and language for contractor vulnerability disclosure programs. (Such programs establish processes for identifying, reporting, and mitigating information system vulnerabilities discovered by security researchers, software developers, and others.) The recommendations must include requirements to ensure that such contractors implement vulnerability disclosure policies consistent with guidelines from the National Institute of Standards and Technology. The Federal Acquisition Regulation Council must review these recommendations and update the FAR as necessary to incorporate requirements for such contractors to receive information about potential security vulnerabilities in contractor information systems used in performance of contract.

The Department of Defense (DOD) must conduct a similar review and update of regulations with respect to the DOD Supplement to the FAR.

Text (3)

Engrossed in House (EH)

119 HR 872 EH: Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025 U.S. House of Representatives text/xml EN Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain. I 119th CONGRESS 1st Session H. R. 872

IN THE HOUSE OF REPRESENTATIVES AN ACT To require covered contractors implement a vulnerability disclosure policy consistent with NIST guidelines, and for other purposes.

1.Short titleThis Act may be cited as the Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025.

2.Federal contractor vulnerability disclosure policy (a)Recommendations (1)In generalNot later than 180 days after the date of the enactment of this Act, the Director of the Office of Management and Budget, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, the National Cyber Director, the Director of the National Institute of Standards and Technology, and any other appropriate head of an Executive department, shall— (A)review the Federal Acquisition Regulation contract requirements and language for contractor vulnerability disclosure programs; and (B)recommend updates to such requirements and language to the Federal Acquisition Regulation Council. (2)ContentsThe recommendations required by paragraph (1) shall include updates to such requirements designed to ensure that covered contractors implement a vulnerability disclosure policy consistent with NIST guidelines for contractors as required under section 5 of the IoT Cybersecurity Improvement Act of 2020 (15 U.S.C. 278g–3c; Public Law 116–207). (b)Procurement requirementsNot later than 180 days after the date on which the recommended contract language developed pursuant to subsection (a) is received, the Federal Acquisition Regulation Council shall review the recommended contract language and update the FAR as necessary to incorporate requirements for covered contractors to receive information about a potential security vulnerability relating to an information system owned or controlled by a contractor, in performance of the contract. (c)ElementsThe update to the FAR pursuant to subsection (b) shall— (1)to the maximum extent practicable, align with the security vulnerability disclosure process and coordinated disclosure requirements relating to Federal information systems under sections 5 and 6 of the IoT Cybersecurity Improvement Act of 2020 (Public Law 116–207; 15 U.S.C. 278g–3c and 278g–3d); and (2)to the maximum extent practicable, be aligned with industry best practices and Standards 29147 and 30111 of the International Standards Organization (or any successor standard) or any other appropriate, relevant, and widely used standard. (d)WaiverThe head of an agency may waive the security vulnerability disclosure policy requirement under subsection (b) if— (1)the agency Chief Information Officer determines that the waiver is necessary in the interest of national security or research purposes; and (2)if, not later than 30 days after granting a waiver, such head submits a notification and justification (including information about the duration of the waiver) to the Committee on Oversight and Government Reform of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate. (e)Department of defense supplement to the federal acquisition regulation (1)ReviewNot later than 180 days after the date of the enactment of this Act, the Secretary of Defense shall review the Department of Defense Supplement to the Federal Acquisition Regulation contract requirements and language for contractor vulnerability disclosure programs and develop updates to such requirements designed to ensure that covered contractors implement a vulnerability disclosure policy consistent with NIST guidelines for contractors as required under section 5 of the IoT Cybersecurity Improvement Act of 2020 (15 U.S.C. 278g–3c; Public Law 116–207). (2)RevisionsNot later than 180 days after the date on which the review required under subsection (a) is completed, the Secretary shall revise the DFARS as necessary to incorporate requirements for covered contractors to receive information about a potential security vulnerability relating to an information system owned or controlled by a contractor, in performance of the contract. (3)ElementsThe Secretary shall ensure that the revision to the DFARS described in this subsection is carried out in accordance with the requirements of paragraphs (1) and (2) of subsection (c). (4)WaiverThe Chief Information Officer of the Department of Defense, in consultation with the National Manager for National Security Systems, may waive the security vulnerability disclosure policy requirements under paragraph (2) if the Chief Information Officer— (A)determines that the waiver is necessary in the interest of national security or research purposes; and (B)not later than 30 days after granting a waiver, submits a notification and justification (including information about the duration of the waiver) to the Committees on Armed Services of the House of Representatives and the Senate. (f)DefinitionsIn this section: (1)The term agency has the meaning given the term in section 3502 of title 44, United States Code. (2)The term covered contractor means a contractor (as defined in section 7101 of title 41, United States Code)— (A)whose contract is in an amount the same as or greater than the simplified acquisition threshold; or (B)that uses, operates, manages, or maintains a Federal information system (as defined by section 11331 of title 40, United Stated Code) on behalf of an agency. (3)The term DFARS means the Department of Defense Supplement to the Federal Acquisition Regulation. (4)The term Executive department has the meaning given that term in section 101 of title 5, United States Code. (5)The term FAR means the Federal Acquisition Regulation. (6)The term NIST means the National Institute of Standards and Technology. (7)The term OMB means the Office of Management and Budget. (8)The term security vulnerability has the meaning given that term in section 2200 of the Homeland Security Act of 2002 (6 U.S.C. 650). (9)The term simplified acquisition threshold has the meaning given that term in section 134 of title 41, United States Code. Passed the House of Representatives March 3, 2025.Kevin F. McCumber,Clerk.

Introduced in House (IH)

116 HR 872 IH: Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025 U.S. House of Representatives 2025-01-31 text/xml EN Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain. I119th CONGRESS1st SessionH. R. 872IN THE HOUSE OF REPRESENTATIVESJanuary 31, 2025Ms. Mace (for herself and Ms. Brown) introduced the following bill; which was referred to the Committee on Oversight and Government Reform, and in addition to the Committee on Armed Services, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concernedA BILLTo require covered contractors implement a vulnerability disclosure policy consistent with NIST guidelines, and for other purposes.1.Short titleThis Act may be cited as the Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025.2.Federal contractor vulnerability disclosure policy(a)Recommendations(1)In generalNot later than 180 days after the date of the enactment of this Act, the Director of the Office of Management and Budget, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, the National Cyber Director, the Director of the National Institute of Standards and Technology, and any other appropriate head of an Executive department, shall—(A)review the Federal Acquisition Regulation contract requirements and language for contractor vulnerability disclosure programs; and(B)recommend updates to such requirements and language to the Federal Acquisition Regulation Council.(2)ContentsThe recommendations required by paragraph (1) shall include updates to such requirements designed to ensure that covered contractors implement a vulnerability disclosure policy consistent with NIST guidelines for contractors as required under section 5 of the IoT Cybersecurity Improvement Act of 2020 (15 U.S.C. 278g–3c; Public Law 116–207).(b)Procurement requirementsNot later than 180 days after the date on which the recommended contract language developed pursuant to subsection (a) is received, the Federal Acquisition Regulation Council shall review the recommended contract language and update the FAR as necessary to incorporate requirements for covered contractors to receive information about a potential security vulnerability relating to an information system owned or controlled by a contractor, in performance of the contract.(c)ElementsThe update to the FAR pursuant to subsection (b) shall—(1)to the maximum extent practicable, align with the security vulnerability disclosure process and coordinated disclosure requirements relating to Federal information systems under sections 5 and 6 of the IoT Cybersecurity Improvement Act of 2020 (Public Law 116–207; 15 U.S.C. 278g–3c and 278g–3d); and(2)to the maximum extent practicable, be aligned with industry best practices and Standards 29147 and 30111 of the International Standards Organization (or any successor standard) or any other appropriate, relevant, and widely used standard.(d)WaiverThe head of an agency may waive the security vulnerability disclosure policy requirement under subsection (b) if—(1)the agency Chief Information Officer determines that the waiver is necessary in the interest of national security or research purposes; and(2)if, not later than 30 days after granting a waiver, such head submits a notification and justification (including information about the duration of the waiver) to the Committee on Oversight and Government Reform of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate.(e)Department of defense supplement to the federal acquisition regulation(1)ReviewNot later than 180 days after the date of the enactment of this Act, the Secretary of Defense shall review the Department of Defense Supplement to the Federal Acquisition Regulation contract requirements and language for contractor vulnerability disclosure programs and develop updates to such requirements designed to ensure that covered contractors implement a vulnerability disclosure policy consistent with NIST guidelines for contractors as required under section 5 of the IoT Cybersecurity Improvement Act of 2020 (15 U.S.C. 278g–3c; Public Law 116–207).(2)RevisionsNot later than 180 days after the date on which the review required under subsection (a) is completed, the Secretary shall revise the DFARS as necessary to incorporate requirements for covered contractors to receive information about a potential security vulnerability relating to an information system owned or controlled by a contractor, in performance of the contract.(3)ElementsThe Secretary shall ensure that the revision to the DFARS described in this subsection is carried out in accordance with the requirements of paragraphs (1) and (2) of subsection (c).(4)WaiverThe Chief Information Officer of the Department of Defense may waive the security vulnerability disclosure policy requirements under paragraph (2) if the Chief Information Officer—(A)determines that the waiver is necessary in the interest of national security or research purposes; and(B)not later than 30 days after granting a waiver, submits a notification and justification (including information about the duration of the waiver) to the Committees on Armed Services of the House of Representatives and the Senate.(f)DefinitionsIn this section:(1)The term agency has the meaning given the term in section 3502 of title 44, United States Code.(2)The term covered contractor means a contractor (as defined in section 7101 of title 41, United States Code)—(A)whose contract is in an amount the same as or greater than the simplified acquisition threshold; or(B)that uses, operates, manages, or maintains a Federal information system (as defined by section 11331 of title 40, United Stated Code) on behalf of an agency.(3)The term DFARS means the Department of Defense Supplement to the Federal Acquisition Regulation.(4)The term Executive department has the meaning given that term in section 101 of title 5, United States Code.(5)The term FAR means the Federal Acquisition Regulation.(6)The term NIST means the National Institute of Standards and Technology.(7)The term OMB means the Office of Management and Budget.(8)The term security vulnerability has the meaning given that term in section 2200 of the Homeland Security Act of 2002 (6 U.S.C. 650).(9)The term simplified acquisition threshold has the meaning given that term in section 134 of title 41, United States Code.

Referred in Senate (RFS)

116 HR 872 : Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025 U.S. House of Representatives 2025-03-04 text/xml EN Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain. IIB119th CONGRESS1st SessionH. R. 872IN THE SENATE OF THE UNITED STATESMarch 4, 2025Received; read twice and referred to the Committee on Homeland Security and Governmental AffairsAN ACTTo require covered contractors implement a vulnerability disclosure policy consistent with NIST guidelines, and for other purposes.1.Short titleThis Act may be cited as the Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025.2.Federal contractor vulnerability disclosure policy(a)Recommendations(1)In generalNot later than 180 days after the date of the enactment of this Act, the Director of the Office of Management and Budget, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, the National Cyber Director, the Director of the National Institute of Standards and Technology, and any other appropriate head of an Executive department, shall—(A)review the Federal Acquisition Regulation contract requirements and language for contractor vulnerability disclosure programs; and(B)recommend updates to such requirements and language to the Federal Acquisition Regulation Council.(2)ContentsThe recommendations required by paragraph (1) shall include updates to such requirements designed to ensure that covered contractors implement a vulnerability disclosure policy consistent with NIST guidelines for contractors as required under section 5 of the IoT Cybersecurity Improvement Act of 2020 (15 U.S.C. 278g–3c; Public Law 116–207).(b)Procurement requirementsNot later than 180 days after the date on which the recommended contract language developed pursuant to subsection (a) is received, the Federal Acquisition Regulation Council shall review the recommended contract language and update the FAR as necessary to incorporate requirements for covered contractors to receive information about a potential security vulnerability relating to an information system owned or controlled by a contractor, in performance of the contract.(c)ElementsThe update to the FAR pursuant to subsection (b) shall—(1)to the maximum extent practicable, align with the security vulnerability disclosure process and coordinated disclosure requirements relating to Federal information systems under sections 5 and 6 of the IoT Cybersecurity Improvement Act of 2020 (Public Law 116–207; 15 U.S.C. 278g–3c and 278g–3d); and(2)to the maximum extent practicable, be aligned with industry best practices and Standards 29147 and 30111 of the International Standards Organization (or any successor standard) or any other appropriate, relevant, and widely used standard.(d)WaiverThe head of an agency may waive the security vulnerability disclosure policy requirement under subsection (b) if—(1)the agency Chief Information Officer determines that the waiver is necessary in the interest of national security or research purposes; and(2)if, not later than 30 days after granting a waiver, such head submits a notification and justification (including information about the duration of the waiver) to the Committee on Oversight and Government Reform of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate.(e)Department of defense supplement to the federal acquisition regulation(1)ReviewNot later than 180 days after the date of the enactment of this Act, the Secretary of Defense shall review the Department of Defense Supplement to the Federal Acquisition Regulation contract requirements and language for contractor vulnerability disclosure programs and develop updates to such requirements designed to ensure that covered contractors implement a vulnerability disclosure policy consistent with NIST guidelines for contractors as required under section 5 of the IoT Cybersecurity Improvement Act of 2020 (15 U.S.C. 278g–3c; Public Law 116–207).(2)RevisionsNot later than 180 days after the date on which the review required under subsection (a) is completed, the Secretary shall revise the DFARS as necessary to incorporate requirements for covered contractors to receive information about a potential security vulnerability relating to an information system owned or controlled by a contractor, in performance of the contract.(3)ElementsThe Secretary shall ensure that the revision to the DFARS described in this subsection is carried out in accordance with the requirements of paragraphs (1) and (2) of subsection (c).(4)WaiverThe Chief Information Officer of the Department of Defense, in consultation with the National Manager for National Security Systems, may waive the security vulnerability disclosure policy requirements under paragraph (2) if the Chief Information Officer—(A)determines that the waiver is necessary in the interest of national security or research purposes; and(B)not later than 30 days after granting a waiver, submits a notification and justification (including information about the duration of the waiver) to the Committees on Armed Services of the House of Representatives and the Senate.(f)DefinitionsIn this section:(1)The term agency has the meaning given the term in section 3502 of title 44, United States Code.(2)The term covered contractor means a contractor (as defined in section 7101 of title 41, United States Code)—(A)whose contract is in an amount the same as or greater than the simplified acquisition threshold; or(B)that uses, operates, manages, or maintains a Federal information system (as defined by section 11331 of title 40, United Stated Code) on behalf of an agency.(3)The term DFARS means the Department of Defense Supplement to the Federal Acquisition Regulation.(4)The term Executive department has the meaning given that term in section 101 of title 5, United States Code.(5)The term FAR means the Federal Acquisition Regulation.(6)The term NIST means the National Institute of Standards and Technology.(7)The term OMB means the Office of Management and Budget.(8)The term security vulnerability has the meaning given that term in section 2200 of the Homeland Security Act of 2002 (6 U.S.C. 650).(9)The term simplified acquisition threshold has the meaning given that term in section 134 of title 41, United States Code.Passed the House of Representatives March 3, 2025.Kevin F. McCumber,Clerk.

The bill's own words, from our database (synced from the GPO BILLS XML); paragraph breaks added at the bill's section boundaries, nothing else changed.

All Actions (11)

DateChamberAll Actions
01/31/2025Library of CongressIntroduced in House
01/31/2025Library of CongressIntroduced in House
01/31/2025House floor actionsReferred to the Committee on Oversight and Government Reform, and in addition to the Committee on Armed Services, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.
01/31/2025House floor actionsReferred to the Committee on Oversight and Government Reform, and in addition to the Committee on Armed Services, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.
03/03/2025House floor actionsMr. Comer moved to suspend the rules and pass the bill, as amended.
03/03/2025House floor actionsConsidered under suspension of the rules. (consideration: CR H930-932)
03/03/2025House floor actionsDEBATE - The House proceeded with forty minutes of debate on H.R. 872.
03/03/2025Library of CongressPassed/agreed to in House: On motion to suspend the rules and pass the bill, as amended Agreed to by voice vote. (text: CR H930-931)
03/03/2025House floor actionsOn motion to suspend the rules and pass the bill, as amended Agreed to by voice vote. (text: CR H930-931)
03/03/2025House floor actionsMotion to reconsider laid on the table Agreed to without objection.
03/04/2025SenateReceived in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs.

Titles (6)

Title TypeTitle
Official Titles from EH (Engrossed in House) bill textTo require covered contractors implement a vulnerability disclosure policy consistent with NIST guidelines, and for other purposes.
Short Titles from RFS (Referred to Senate) bill textFederal Contractor Cybersecurity Vulnerability Reduction Act of 2025
Short Title(s) as Passed HouseFederal Contractor Cybersecurity Vulnerability Reduction Act of 2025
Display TitleFederal Contractor Cybersecurity Vulnerability Reduction Act of 2025
Short Title(s) as IntroducedFederal Contractor Cybersecurity Vulnerability Reduction Act of 2025
Official Title as IntroducedTo require covered contractors implement a vulnerability disclosure policy consistent with NIST guidelines, and for other purposes.

Amendments (0)

There are no amendments to this bill.

Cosponsors (1)

* = Original cosponsor

Committees (3)

CommitteeActivity
Senate - Homeland Security and Governmental Affairs Committee03/04/2025 Referred To
House - Armed Services Committee01/31/2025 Referred To
House - Oversight and Government Reform Committee01/31/2025 Referred To

Related Bills (1)

Subjects (3)

Policy Area: Government Operations and Politics

All data on this page comes from our own database (legislation.congress_* tables), synced daily from the GPO govinfo BILLSTATUS and BILLS collections. Formatted after congress.gov; nothing is generated. Member placement is their DW-NOMINATE score (voteview.com, Lewis et al.) - a measurement of roll-call voting behavior, not our judgement. Buckets: Left below −0.50 · Lean Left to −0.25 · Center to +0.25 · Lean Right to +0.50 · Right above +0.50. The bill's Support meter aggregates the people who signed the bill - sponsor and current cosponsors, each counted once - nothing else.