H.R. 872
119th Congress
Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025
1
Cosponsors
11
Actions
0
Amendments
3
Committees
—
Since introduced
Received in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
4 March 2025·1 year ago
Summary
Introduced in House · Updated 3 March 2025
Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025
This bill requires revisions to acquisition regulations related to information systems vulnerabilities for certain federal contractors. The revisions apply to contractors whose contract is at or above the simplified acquisition threshold ($250,000 in most cases) or that use, operate, manage, or maintain a federal information system on behalf of an agency.
Under the bill, the Office of Management and Budget must review the Federal Acquisition Regulation (FAR) and recommend updated contract requirements and language for contractor vulnerability disclosure programs. (Such programs establish processes for identifying, reporting, and mitigating information system vulnerabilities discovered by security researchers, software developers, and others.) The recommendations must include requirements to ensure that such contractors implement vulnerability disclosure policies consistent with guidelines from the National Institute of Standards and Technology. The Federal Acquisition Regulation Council must review these recommendations and update the FAR as necessary to incorporate requirements for such contractors to receive information about potential security vulnerabilities in contractor information systems used in performance of contract.
The Department of Defense (DOD) must conduct a similar review and update of regulations with respect to the DOD Supplement to the FAR.
Timeline
11 actions
Received in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
4 March 2025 · IntroReferral
DEBATE - The House proceeded with forty minutes of debate on H.R. 872.
3 March 2025 · Floor
Considered under suspension of the rules. (consideration: CR H930-932)
3 March 2025 · Floor
Mr. Comer moved to suspend the rules and pass the bill, as amended.
3 March 2025 · Floor
Motion to reconsider laid on the table Agreed to without objection.
3 March 2025 · Floor
Passed/agreed to in House: On motion to suspend the rules and pass the bill, as amended Agreed to by voice vote. (text: CR H930-931)
3 March 2025 · Floor
On motion to suspend the rules and pass the bill, as amended Agreed to by voice vote. (text: CR H930-931)
3 March 2025 · Floor
Referred to the Committee on Oversight and Government Reform, and in addition to the Committee on Armed Services, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.
31 January 2025 · IntroReferral
Referred to the Committee on Oversight and Government Reform, and in addition to the Committee on Armed Services, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.
31 January 2025 · IntroReferral
Introduced in House
31 January 2025 · IntroReferral
Introduced in House
31 January 2025 · IntroReferral
Sponsorship
1 cosponsors
Sponsor
Republican:Rep. Mace, Nancy [R-SC-1]SCCosponsors
- Democrat1100%
- Democrat:Rep. Brown, Shontel M. [D-OH-11]OH
Classification
Policy area
Government Operations and PoliticsLegislative subjects
Committees
3
Armed Services Committee
House · Standing
- Referred To31 Jan 2025
Oversight and Government Reform Committee
House · Standing
- Referred To31 Jan 2025
Homeland Security and Governmental Affairs Committee
Senate · Standing
- Referred To4 Mar 2025
Track Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025 as it moves through Congress
Get alerts on votes, amendments, and stock-market impact