Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025 | ChamberLight
Bills · HR 872
PASSED HOUSE· 119TH CONGRESS
House BillHR 872Computer security and identity theftPublic contracts and procurement
Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025
INTRO JAN 31· LAST ACTION MAR 4
READING
5MIN
COSPONSORS
1
READER REACTIONS0 TOTAL
NO VOTES YET · BE THE FIRST
One chamber only
LEGISLATIVE PROGRESS
STEP 4 / 8
Introduced
In Committee
Reported
Passed House
Passed Senate
Conference
To President
Became Law
WHAT THE BILL DOES
AI-written
Voters should care about this bill because it aims to improve the security of computer systems used by federal contractors. These systems often handle sensitive government data or support essential public services. If these contractor systems have unaddressed security weaknesses, they become targets for cyberattacks, which could lead to data theft, disruptions to government operations, or even threats to national security.
If this bill becomes law, it means that federal contractors will have a more consistent and robust way to identify and fix cybersecurity vulnerabilities, potentially reducing the overall risk of cyber incidents. If it does not become law, varying and potentially less effective cybersecurity practices among contractors could continue, leaving critical government-related systems more exposed to cyber threats and their consequences.
KEY PROVISIONS
5AI-extracted
PROVISION 01
The Office of Management and Budget (OMB) and other federal agencies must review and recommend updates to federal contracting rules (FAR) to ensure contractors implement security vulnerability disclosure policies.
This establishes a standardized framework for how contractors must handle cybersecurity weaknesses, aiming to enhance the security of the federal supply chain.
PROVISION 02
The Federal Acquisition Regulation Council must update federal contracting rules to incorporate requirements for covered contractors to have policies for receiving information about security vulnerabilities.
This makes it a mandatory contractual obligation for contractors to adopt specific procedures for identifying and addressing security flaws.
PROVISION 03
The Department of Defense (DoD) must review and revise its specific contracting rules (DFARS) to include similar requirements for its contractors to have vulnerability disclosure policies.
This extends enhanced cybersecurity practices to contractors working on national defense projects, which often involve highly sensitive information and critical systems.
PROVISION 04
Agencies can waive these vulnerability disclosure policy requirements in specific situations related to national security or research purposes.
This provides necessary flexibility for critical government operations while maintaining oversight through congressional notification.
PROVISION 05
The new contracting requirements must align with existing government cybersecurity standards (like the IoT Cybersecurity Improvement Act) and international industry best practices.
This ensures the new policies are effective, up-to-date, and consistent with broader cybersecurity efforts and established benchmarks.
Voters should care about this bill because it aims to improve the security of computer systems used by federal contractors. These systems often handle sensitive government data or support essential public services. If these contractor systems have unaddressed security weaknesses, they become targets for cyberattacks, which could lead to data theft, disruptions to government operations, or even threats to national security.
If this bill becomes law, it means that federal contractors will have a more consistent and robust way to identify and fix cybersecurity vulnerabilities, potentially reducing the overall risk of cyber incidents. If it does not become law, varying and potentially less effective cybersecurity practices among contractors could continue, leaving critical government-related systems more exposed to cyber threats and their consequences.
KEY PROVISIONS
AI-extracted
high
The Office of Management and Budget (OMB) and other federal agencies must review and recommend updates to federal contracting rules (FAR) to ensure contractors implement security vulnerability disclosure policies.
This establishes a standardized framework for how contractors must handle cybersecurity weaknesses, aiming to enhance the security of the federal supply chain.
high
The Federal Acquisition Regulation Council must update federal contracting rules to incorporate requirements for covered contractors to have policies for receiving information about security vulnerabilities.
This makes it a mandatory contractual obligation for contractors to adopt specific procedures for identifying and addressing security flaws.
high
The Department of Defense (DoD) must review and revise its specific contracting rules (DFARS) to include similar requirements for its contractors to have vulnerability disclosure policies.
This extends enhanced cybersecurity practices to contractors working on national defense projects, which often involve highly sensitive information and critical systems.
med
Agencies can waive these vulnerability disclosure policy requirements in specific situations related to national security or research purposes.
This provides necessary flexibility for critical government operations while maintaining oversight through congressional notification.
med
The new contracting requirements must align with existing government cybersecurity standards (like the IoT Cybersecurity Improvement Act) and international industry best practices.
This ensures the new policies are effective, up-to-date, and consistent with broader cybersecurity efforts and established benchmarks.
Not later than 180 days after the date of enactment.
Director of OMB (in consultation with others) reviews FAR contract requirements and recommends updates to the FAR Council.
Not later than 180 days after receiving recommended language.
Federal Acquisition Regulation Council reviews recommended contract language and updates the FAR.
Not later than 180 days after the date of enactment.
Secretary of Defense reviews DFARS contract requirements and develops updates.
Not later than 180 days after the review is completed.
Secretary of Defense revises the DFARS.
Not later than 30 days after granting a waiver.
Agency head or DoD CIO submits notification and justification after granting a waiver.
GLOSSARY
AI-written
Vulnerability Disclosure Policy
A formal plan that outlines how an organization will receive, investigate, and fix reports of security weaknesses (vulnerabilities) in its computer systems or products.
NIST Guidelines
Cybersecurity recommendations and best practices developed by the National Institute of Standards and Technology, a U.S. government agency that promotes innovation and industrial competitiveness.
Federal Acquisition Regulation (FAR)
The primary set of rules used by all federal executive agencies in the United States for purchasing goods and services.
Department of Defense Supplement to the Federal Acquisition Regulation (DFARS)
Additional rules and regulations specific to the Department of Defense that supplement the standard Federal Acquisition Regulation.
Covered Contractor
A company that has a federal contract above a certain monetary value or that manages federal computer systems on behalf of a government agency.
Security Vulnerability
A weakness or flaw in a computer system, network, or software that could be exploited by an attacker to gain unauthorized access or cause harm.
Simplified Acquisition Threshold
ACTION TIMELINE
9 EVENTS
MAR 4, 25
Received in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
INTROREFERRAL
MAR 3, 25
Mr. Comer moved to suspend the rules and pass the bill, as amended.
FLOOR
MAR 3, 25
Considered under suspension of the rules. (consideration: CR H930-932)
FLOOR
MAR 3, 25
DEBATE - The House proceeded with forty minutes of debate on H.R. 872.