govt.fyi
US Congress · H.R. 872 · Passed the House

Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025

Introduced
Moved
Reached a final decision
Introduced 2025-01-31
Derived from the official record below.

Officially: “Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025 Read the full text

Government Operations and Politics

What it does

Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025 This bill requires revisions to acquisition regulations related to information systems vulnerabilities for certain federal contractors. The revisions apply to contractors whose contract is at or above the simplified acquisition threshold ($250,000 in most cases) or that use, operate, manage, or maintain a federal information system on behalf of an agency. Under the bill, the Office of Management and Budget must review the Federal Acquisition Regulation (FAR) and recommend updated contract requirements and language for contrac
Summary by the Congressional Research Service, from the official record. Plain-language version below. Not legal advice.

Read it in plain language

AI plain language2 sections
Written by AI from the complete official bill text and independently fact-checked against it. Not legal advice.
1Short title

This section would give the Act its short title, the Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025.

Show official text
Official text, verbatim from the record

1. Short title This Act may be cited as the Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025 .

2Federal contractor vulnerability disclosure policy

This section would require federal contract rules to be updated so that certain contractors must have a policy for handling reports of security vulnerabilities in their information systems. Within 180 days after enactment, the Director of the Office of Management and Budget, working with the Director of the Cybersecurity and Infrastructure Security Agency, the National Cyber Director, the Director of the National Institute of Standards and Technology, and other relevant agency heads, would have to review the Federal Acquisition Regulation's current contract requirements and language on contractor vulnerability disclosure programs and recommend updates to the Federal Acquisition Regulation Council. Those recommended updates would have to be designed to ensure that covered contractors adopt a vulnerability disclosure policy consistent with NIST guidelines for contractors, the same guidelines already required for certain contractors under the IoT Cybersecurity Improvement Act of 2020. Within 180 days after the Council receives that recommended contract language, the Federal Acquisition Regulation Council would have to review it and update the Federal Acquisition Regulation as necessary so that covered contractors are required to receive information about a potential security vulnerability in an information system that the contractor owns or controls while performing the contract. To the maximum extent practicable, that update would have to align with the vulnerability disclosure and coordinated disclosure requirements for federal information systems under the IoT Cybersecurity Improvement Act of 2020. To the maximum extent practicable, it would also have to align with industry best practices and International Standards Organization Standards 29147 and 30111 (or any successor standards) or any other appropriate, relevant, and widely used standard. An agency head could waive this procurement requirement if the agency's Chief Information Officer determines the waiver is necessary in the interest of national security or for research purposes, and if the agency head, not later than 30 days after granting the waiver, submits a notification and justification, including information about how long the waiver will last, to the House Committee on Oversight and Government Reform and the Senate Committee on Homeland Security and Governmental Affairs. Separately, within 180 days after enactment, the Secretary of Defense would have to review the Department of Defense Supplement to the Federal Acquisition Regulation's contract requirements and language on contractor vulnerability disclosure programs and develop updates designed to ensure covered contractors adopt a policy consistent with those same NIST guidelines. Within 180 days after the earlier review led by the Director of the Office of Management and Budget is completed, the Secretary would have to revise the Department of Defense Supplement as necessary to require covered contractors to receive information about a potential security vulnerability in a contractor-owned or controlled information system used in performing the contract, and that revision would have to meet the same alignment requirements described above for the Federal Acquisition Regulation update. The Department of Defense's Chief Information Officer could waive this Department of Defense requirement if the Chief Information Officer determines the waiver is necessary in the interest of national security or for research purposes, and if, not later than 30 days after granting the waiver, the Chief Information Officer submits a notification and justification, including information about how long the waiver will last, to the House and Senate Committees on Armed Services. The section also defines terms used throughout: an agency has the meaning given that term in section 3502 of title 44 of the United States Code; a covered contractor is a contractor whose contract amount is the same as or greater than the simplified acquisition threshold, or that uses, operates, manages, or maintains a federal information system on behalf of an agency; DFARS means the Department of Defense Supplement to the Federal Acquisition Regulation; an Executive department is defined the same way it is defined elsewhere in federal law; FAR means the Federal Acquisition Regulation; NIST means the National Institute of Standards and Technology; OMB means the Office of Management and Budget; security vulnerability has the meaning given that term in the Homeland Security Act of 2002; and the simplified acquisition threshold has the meaning given that term in title 41 of the United States Code.

Show official text
Official text, verbatim from the record

2. Federal contractor vulnerability disclosure policy (a) Recommendations (1) In general Not later than 180 days after the date of the enactment of this Act, the Director of the Office of Management and Budget, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, the National Cyber Director, the Director of the National Institute of Standards and Technology, and any other appropriate head of an Executive department, shall— (A) review the Federal Acquisition Regulation contract requirements and language for contractor vulnerability disclosure programs; and (B) recommend updates to such requirements and language to the Federal Acquisition Regulation Council. (2) Contents The recommendations required by paragraph (1) shall include updates to such requirements designed to ensure that covered contractors implement a vulnerability disclosure policy consistent with NIST guidelines for contractors as required under section 5 of the IoT Cybersecurity Improvement Act of 2020 (15 U.S.C. 278g–3c; Public Law 116–207 ). (b) Procurement requirements Not later than 180 days after the date on which the recommended contract language developed pursuant to subsection (a) is received, the Federal Acquisition Regulation Council shall review the recommended contract language and update the FAR as necessary to incorporate requirements for covered contractors to receive information about a potential security vulnerability relating to an information system owned or controlled by a contractor, in performance of the contract. (c) Elements The update to the FAR pursuant to subsection (b) shall— (1) to the maximum extent practicable, align with the security vulnerability disclosure process and coordinated disclosure requirements relating to Federal information systems under sections 5 and 6 of the IoT Cybersecurity Improvement Act of 2020 ( Public Law 116–207 ; 15 U.S.C. 278g–3c and 278g–3d); and (2) to the maximum extent practicable, be aligned with industry best practices and Standards 29147 and 30111 of the International Standards Organization (or any successor standard) or any other appropriate, relevant, and widely used standard. (d) Waiver The head of an agency may waive the security vulnerability disclosure policy requirement under subsection (b) if— (1) the agency Chief Information Officer determines that the waiver is necessary in the interest of national security or research purposes; and (2) if, not later than 30 days after granting a waiver, such head submits a notification and justification (including information about the duration of the waiver) to the Committee on Oversight and Government Reform of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate. (e) Department of defense supplement to the federal acquisition regulation (1) Review Not later than 180 days after the date of the enactment of this Act, the Secretary of Defense shall review the Department of Defense Supplement to the Federal Acquisition Regulation contract requirements and language for contractor vulnerability disclosure programs and develop updates to such requirements designed to ensure that covered contractors implement a vulnerability disclosure policy consistent with NIST guidelines for contractors as required under section 5 of the IoT Cybersecurity Improvement Act of 2020 (15 U.S.C. 278g–3c; Public Law 116–207 ). (2) Revisions Not later than 180 days after the date on which the review required under subsection (a) is completed, the Secretary shall revise the DFARS as necessary to incorporate requirements for covered contractors to receive information about a potential security vulnerability relating to an information system owned or controlled by a contractor, in performance of the contract. (3) Elements The Secretary shall ensure that the revision to the DFARS described in this subsection is carried out in accordance with the requirements of paragraphs (1) and (2) of subsection (c). (4) Waiver The Chief Information Officer of the Department of Defense may waive the security vulnerability disclosure policy requirements under paragraph (2) if the Chief Information Officer— (A) determines that the waiver is necessary in the interest of national security or research purposes; and (B) not later than 30 days after granting a waiver, submits a notification and justification (including information about the duration of the waiver) to the Committees on Armed Services of the House of Representatives and the Senate. (f) Definitions In this section: (1) The term agency has the meaning given the term in section 3502 of title 44, United States Code. (2) The term covered contractor means a contractor (as defined in section 7101 of title 41, United States Code)— (A) whose contract is in an amount the same as or greater than the simplified acquisition threshold; or (B) that uses, operates, manages, or maintains a Federal information system (as defined by section 11331 of title 40, United Stated Code) on behalf of an agency. (3) The term DFARS means the Department of Defense Supplement to the Federal Acquisition Regulation. (4) The term Executive department has the meaning given that term in section 101 of title 5, United States Code. (5) The term FAR means the Federal Acquisition Regulation. (6) The term NIST means the National Institute of Standards and Technology. (7) The term OMB means the Office of Management and Budget. (8) The term security vulnerability has the meaning given that term in section 2200 of the Homeland Security Act of 2002 ( 6 U.S.C. 650 ). (9) The term simplified acquisition threshold has the meaning given that term in section 134 of title 41, United States Code.

AI plain languageRead the whole bill in plain language, 2 sections

Where it is

Introduced · 2025-01-31

In the House.

Passed the House · 2025-03-03
Senate floor vote · next · the next step

Official documents

The on-site text is shown verbatim from the GovInfo publication, captured 2026-07-23. The same version at GovInfo.

The numbers

29%
of bills that passed one chamber became law in the 118th Congress, 2023 to 2024 (n=939)
2
sponsors, out of 218 needed to pass

Who is lobbying on this

GOOGLE CLIENT SERVICES LLCvia GOOGLE CLIENT SERVICES LLC
6 filings
HACKERONEvia VENABLE LLP
6 filings
NATIONAL SMALL BUSINESS ASSOCIATIONvia NATIONAL SMALL BUSINESS ASSOCIATION
6 filings
AIR TRANSPORT ASSOCIATION OF AMERICA, INC. (D/B/A AIRLINES FOR AMERICA)via AIR TRANSPORT ASSOCIATION OF AMERICA, INC. (D/B/A AIRLINES FOR AMERICA)
3 filings
RED HAT INCvia RED HAT INC
3 filings
CHAMBER OF COMMERCE OF THE U.S.A.via CHAMBER OF COMMERCE OF THE U.S.A.
2 filings
From 26 filings in federal lobbying disclosures (LDA), via lda.gov, naming this bill (2025 to 2026). Filings are self-reported by lobbying firms and show who is paid to influence this bill. They do not say which side, or whether it worked.
Every fact on this page links to its source, starting with the official bill record. Last action: Received in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs. (2025-03-04).