H.R. 872House119th Congress (2025-2027)Passed House

Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025

Sponsored by Nancy MaceRep. Nancy Mace (R-SC)
Introduced January 31, 2025

AI-Generated Summary

Updated November 24, 2025 at 3:09 AM UTC

The Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025 requires the federal government to update its acquisition rules so that large contractors and those handling federal information systems must have a vulnerability‑disclosure policy that follows NIST guidelines. It directs the OMB and the Department of Defense to revise the FAR and DFARS within 180 days, adds reporting requirements for security flaws, and allows limited waivers for national‑security or research purposes. The law mainly impacts federal agencies, defense agencies, and the contractors that do business with them.

Key Provisions

  • Within 180 days of enactment, the OMB Director, in consultation with the CISA Director, the National Cyber Director, NIST, and other officials, must review the Federal Acquisition Regulation (FAR) and recommend updates so that covered contractors adopt a vulnerability‑disclosure policy that follows NIST guidelines.
  • The FAR Council must then incorporate those recommendations into the FAR, requiring contractors to report potential security vulnerabilities in the systems they own or operate for the government.
  • The new FAR language must align as closely as possible with the IoT Cybersecurity Improvement Act’s disclosure rules and with widely‑used industry standards such as ISO/IEC 29147 and 30111.
  • Agency heads may waive the disclosure requirement for national‑security or research reasons, but must notify the relevant House and Senate oversight committees within 30 days and explain the waiver’s duration.
  • The Secretary of Defense must similarly review and update the Defense FAR Supplement (DFARS) to impose the same disclosure obligations on defense contractors, with a comparable waiver process for the DoD CIO.
  • The bill defines a “covered contractor” as any contractor with a contract at or above the simplified acquisition threshold or that manages a federal information system on behalf of an agency.

Legislative Activity

Stay on top of the latest movement without scrolling through every action

8 earlier actions
SenateIntro Referral Latest Action

Received in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs.

March 4, 2025

View full timeline
HouseIntro Referral

Introduced in House

January 31, 2025

HouseIntro Referral

Referred to the Committee on Oversight and Government Reform, and in addition to the Committee on Armed Services, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.

January 31, 2025

HouseFloor

Mr. Comer moved to suspend the rules and pass the bill, as amended.

March 3, 2025 • 3:51 PM

HouseFloor

Considered under suspension of the rules. (consideration: CR H930-932)

March 3, 2025 • 3:51 PM

HouseFloor

DEBATE - The House proceeded with forty minutes of debate on H.R. 872.

March 3, 2025 • 3:51 PM

HouseFloor

Passed/agreed to in House: On motion to suspend the rules and pass the bill, as amended Agreed to by voice vote. (text: CR H930-931)

March 3, 2025 • 4:02 PM

HouseFloor

On motion to suspend the rules and pass the bill, as amended Agreed to by voice vote. (text: CR H930-931)

March 3, 2025 • 4:02 PM

HouseFloor

Motion to reconsider laid on the table Agreed to without objection.

March 3, 2025 • 4:02 PM

SenateIntro Referral

Received in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs.

March 4, 2025

Floor Debate

3 members

What members said about H.R. 872 on the floor

2 Republicans1 Democrat
Nancy Mace
Rep. Nancy MaceR-SC-1 · Mar 3, 2025

Mr. Speaker, I thank my friend and the distinguished chairman of the Committee on Oversight and Government Reform, the gentleman from Kentucky (Mr. Comer), for yielding. I thank both the chairman and…

James Comer
Rep. James ComerR-KY-1 · Mar 3, 2025

Mr. Speaker, I move to suspend the rules and pass the bill (H.R. 872) to require covered contractors implement a vulnerability disclosure policy consistent with NIST guidelines, and for other…

Gerald E. Connolly
Rep. Gerald E. ConnollyD-VA-11 · Mar 3, 2025

Mr. Speaker, I yield myself such time as I may consume. Mr. Speaker, I appreciate today's consideration of the Federal Contractor Cybersecurity Vulnerability Reduction Act, as well as the work of…

Bill Text

3 versions available

Reading Mode
Latest
Referred in SenateIssued March 4, 2025

IIB

119th CONGRESS

1st Session

H. R. 872

IN THE SENATE OF THE UNITED STATES

March 4, 2025

Received; read twice and referred to the Committee on Homeland Security and Governmental Affairs

AN ACT

To require covered contractors implement a vulnerability disclosure policy consistent with NIST guidelines, and for other purposes.


1.

Short title

This Act may be cited as the Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025.

2.

Federal contractor vulnerability disclosure policy

(a)

Recommendations

(1)

In general

Not later than 180 days after the date of the enactment of this Act, the Director of the Office of Management and Budget, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, the National Cyber Director, the Director of the National Institute of Standards and Technology, and any other appropriate head of an Executive department, shall—

(A)

review the Federal Acquisition Regulation contract requirements and language for contractor vulnerability disclosure programs; and

(B)

recommend updates to such requirements and language to the Federal Acquisition Regulation Council.

(2)

Contents

The recommendations required by paragraph (1) shall include updates to such requirements designed to ensure that covered contractors implement a vulnerability disclosure policy consistent with NIST guidelines for contractors as required under section 5 of the IoT Cybersecurity Improvement Act of 2020 (15 U.S.C. 278g–3c; Public Law 116–207).

(b)

Procurement requirements

Not later than 180 days after the date on which the recommended contract language developed pursuant to subsection (a) is received, the Federal Acquisition Regulation Council shall review the recommended contract language and update the FAR as necessary to incorporate requirements for covered contractors to receive information about a potential security vulnerability relating to an information system owned or controlled by a contractor, in performance of the contract.

(c)

Elements

The update to the FAR pursuant to subsection (b) shall—

(1)

to the maximum extent practicable, align with the security vulnerability disclosure process and coordinated disclosure requirements relating to Federal information systems under sections 5 and 6 of the IoT Cybersecurity Improvement Act of 2020 (Public Law 116–207; 15 U.S.C. 278g–3c and 278g–3d); and

(2)

to the maximum extent practicable, be aligned with industry best practices and Standards 29147 and 30111 of the International Standards Organization (or any successor standard) or any other appropriate, relevant, and widely used standard.

(d)

Waiver

The head of an agency may waive the security vulnerability disclosure policy requirement under subsection (b) if—

(1)

the agency Chief Information Officer determines that the waiver is necessary in the interest of national security or research purposes; and

(2)

if, not later than 30 days after granting a waiver, such head submits a notification and justification (including information about the duration of the waiver) to the Committee on Oversight and Government Reform of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate.

(e)

Department of defense supplement to the federal acquisition regulation

(1)

Review

Not later than 180 days after the date of the enactment of this Act, the Secretary of Defense shall review the Department of Defense Supplement to the Federal Acquisition Regulation contract requirements and language for contractor vulnerability disclosure programs and develop updates to such requirements designed to ensure that covered contractors implement a vulnerability disclosure policy consistent with NIST guidelines for contractors as required under section 5 of the IoT Cybersecurity Improvement Act of 2020 (15 U.S.C. 278g–3c; Public Law 116–207).

(2)

Revisions

Not later than 180 days after the date on which the review required under subsection (a) is completed, the Secretary shall revise the DFARS as necessary to incorporate requirements for covered contractors to receive information about a potential security vulnerability relating to an information system owned or controlled by a contractor, in performance of the contract.

(3)

Elements

The Secretary shall ensure that the revision to the DFARS described in this subsection is carried out in accordance with the requirements of paragraphs (1) and (2) of subsection (c).

(4)

Waiver

The Chief Information Officer of the Department of Defense, in consultation with the National Manager for National Security Systems, may waive the security vulnerability disclosure policy requirements under paragraph (2) if the Chief Information Officer—

(A)

determines that the waiver is necessary in the interest of national security or research purposes; and

(B)

not later than 30 days after granting a waiver, submits a notification and justification (including information about the duration of the waiver) to the Committees on Armed Services of the House of Representatives and the Senate.

(f)

Definitions

In this section:

(1)

The term agency has the meaning given the term in section 3502 of title 44, United States Code.

(2)

The term covered contractor means a contractor (as defined in section 7101 of title 41, United States Code)—

(A)

whose contract is in an amount the same as or greater than the simplified acquisition threshold; or

(B)

that uses, operates, manages, or maintains a Federal information system (as defined by section 11331 of title 40, United Stated Code) on behalf of an agency.

(3)

The term DFARS means the Department of Defense Supplement to the Federal Acquisition Regulation.

(4)

The term Executive department has the meaning given that term in section 101 of title 5, United States Code.

(5)

The term FAR means the Federal Acquisition Regulation.

(6)

The term NIST means the National Institute of Standards and Technology.

(7)

The term OMB means the Office of Management and Budget.

(8)

The term security vulnerability has the meaning given that term in section 2200 of the Homeland Security Act of 2002 (6 U.S.C. 650).

(9)

The term simplified acquisition threshold has the meaning given that term in section 134 of title 41, United States Code.

Passed the House of Representatives March 3, 2025.

Kevin F. McCumber,

Clerk.