0
0

Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025

3/7/2025, 4:23 AM

Summary of Bill HR 872

Bill 119 HR 872, also known as the "Vulnerability Disclosure Policy Act," aims to ensure that contractors working with the US government have a clear and consistent policy in place for reporting and addressing cybersecurity vulnerabilities. The bill specifically requires covered contractors to implement a vulnerability disclosure policy that aligns with the guidelines set forth by the National Institute of Standards and Technology (NIST).

The purpose of this legislation is to enhance the overall cybersecurity posture of the federal government by promoting transparency and accountability in the handling of vulnerabilities. By requiring contractors to establish a formal process for receiving and addressing reports of vulnerabilities, the bill seeks to improve the timely identification and remediation of potential security threats.

In addition to mandating the implementation of a vulnerability disclosure policy, the bill also includes provisions for the protection of individuals who report vulnerabilities in good faith. This is intended to encourage individuals to come forward with information about potential security weaknesses without fear of retaliation. Overall, Bill 119 HR 872 represents a proactive approach to strengthening cybersecurity within the federal government by promoting best practices for vulnerability management and fostering a culture of collaboration between contractors and government agencies.

Congressional Summary of HR 872

Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025

This bill requires revisions to acquisition regulations related to information systems vulnerabilities for certain federal contractors. The revisions apply to contractors whose contract is at or above the simplified acquisition threshold ($250,000 in most cases) or that use, operate, manage, or maintain a federal information system on behalf of an agency. 

Under the bill, the Office of Management and Budget must review the Federal Acquisition Regulation (FAR) and recommend updated contract requirements and language for contractor vulnerability disclosure programs. (Such programs establish processes for identifying, reporting, and mitigating information system vulnerabilities discovered by security researchers, software developers, and others.) The recommendations must include requirements to ensure that such contractors implement vulnerability disclosure policies consistent with guidelines from the National Institute of Standards and Technology. The Federal Acquisition Regulation Council must review these recommendations and update the FAR as necessary to incorporate requirements for such contractors to receive information about potential security vulnerabilities in contractor information systems used in performance of contract.

The Department of Defense (DOD) must conduct a similar review and update of regulations with respect to the DOD Supplement to the FAR.

Current Status of Bill HR 872

Bill HR 872 is currently in the status of Introduced to Senate since March 4, 2025. Bill HR 872 was introduced during Congress 119 and was introduced to the House on January 31, 2025.  Bill HR 872's most recent activity was Received in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs. as of March 4, 2025

Bipartisan Support of Bill HR 872

Total Number of Sponsors
8
Democrat Sponsors
0
Republican Sponsors
8
Unaffiliated Sponsors
0
Total Number of Cosponsors
1
Democrat Cosponsors
1
Republican Cosponsors
0
Unaffiliated Cosponsors
0

Policy Area and Potential Impact of Bill HR 872

Primary Policy Focus

Government Operations and Politics

Alternate Title(s) of Bill HR 872

To require covered contractors implement a vulnerability disclosure policy consistent with NIST guidelines, and for other purposes.
To require covered contractors implement a vulnerability disclosure policy consistent with NIST guidelines, and for other purposes.

Comments

Matheo King profile image

Matheo King

30,696

11 months ago

This bill is bad for us, it make things harder for everyone. Why they do this? It not good for me.

Esmeralda Lanier profile image

Esmeralda Lanier

31,155

1 year ago

This bill is so dumb, like seriously? Contractors need to have a policy for vulnerabilities? What a waste of time and money. Like, who even cares about this stuff? It's just a bunch of nonsense. I can't believe they're actually making this a thing. SMH.

Latest Bills

To amend title III of the Public Health Service Act to ensure that Federally-qualified health centers are not required to pay more than the 340B ceiling price for covered outpatient drugs at the time of purchase.
Bill HR 7391February 11, 2026
To amend the Consolidated Farm and Rural Development Act to reauthorize certain water infrastructure grants, and for other purposes.
Bill HR 7476February 11, 2026
To direct the Administrator of the Federal Emergency Management Agency to submit a monthly report on the status of all projects and activities funded through the Disaster Relief Fund, and for other purposes.
Bill HR 7461February 11, 2026
Electing a Member to a certain standing committee of the House of Representatives.
Bill HRES 1048February 11, 2026
To amend the Internal Revenue Code of 1986 to allow certain distributions from long-term qualified tuition programs for first home purchases, and for other purposes.
Bill HR 7468February 11, 2026
To authorize civil actions against institutions of higher education and athletic associations that negligently or recklessly permit a biologically male student athlete to compete in an athletic competition intended exclusively for female student athletes, resulting in harm.
Bill HR 7368February 11, 2026
ROUTE Act
Bill HR 6642February 11, 2026
To amend section 477 of the Social Security Act to increase the maximum education and training voucher amount and provide greater support for foster youth pursuing postsecondary education.
Bill HR 7463February 11, 2026
Recognizing the cultural and historical significance of Mardi Gras and the celebration's origins in Mobile, Alabama.
Bill HRES 1051February 11, 2026
Home School Graduation Recognition Act
Bill HR 6392February 11, 2026