0
0

Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025

3/7/2025, 4:23 AM

Summary of Bill HR 872

Bill 119 HR 872, also known as the "Vulnerability Disclosure Policy Act," aims to ensure that contractors working with the US government have a clear and consistent policy in place for reporting and addressing cybersecurity vulnerabilities. The bill specifically requires covered contractors to implement a vulnerability disclosure policy that aligns with the guidelines set forth by the National Institute of Standards and Technology (NIST).

The purpose of this legislation is to enhance the overall cybersecurity posture of the federal government by promoting transparency and accountability in the handling of vulnerabilities. By requiring contractors to establish a formal process for receiving and addressing reports of vulnerabilities, the bill seeks to improve the timely identification and remediation of potential security threats.

In addition to mandating the implementation of a vulnerability disclosure policy, the bill also includes provisions for the protection of individuals who report vulnerabilities in good faith. This is intended to encourage individuals to come forward with information about potential security weaknesses without fear of retaliation. Overall, Bill 119 HR 872 represents a proactive approach to strengthening cybersecurity within the federal government by promoting best practices for vulnerability management and fostering a culture of collaboration between contractors and government agencies.

Congressional Summary of HR 872

Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025

This bill requires revisions to acquisition regulations related to information systems vulnerabilities for certain federal contractors. The revisions apply to contractors whose contract is at or above the simplified acquisition threshold ($250,000 in most cases) or that use, operate, manage, or maintain a federal information system on behalf of an agency. 

Under the bill, the Office of Management and Budget must review the Federal Acquisition Regulation (FAR) and recommend updated contract requirements and language for contractor vulnerability disclosure programs. (Such programs establish processes for identifying, reporting, and mitigating information system vulnerabilities discovered by security researchers, software developers, and others.) The recommendations must include requirements to ensure that such contractors implement vulnerability disclosure policies consistent with guidelines from the National Institute of Standards and Technology. The Federal Acquisition Regulation Council must review these recommendations and update the FAR as necessary to incorporate requirements for such contractors to receive information about potential security vulnerabilities in contractor information systems used in performance of contract.

The Department of Defense (DOD) must conduct a similar review and update of regulations with respect to the DOD Supplement to the FAR.

Current Status of Bill HR 872

Bill HR 872 is currently in the status of Introduced to Senate since March 4, 2025. Bill HR 872 was introduced during Congress 119 and was introduced to the House on January 31, 2025.  Bill HR 872's most recent activity was Received in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs. as of March 4, 2025

Bipartisan Support of Bill HR 872

Total Number of Sponsors
8
Democrat Sponsors
0
Republican Sponsors
8
Unaffiliated Sponsors
0
Total Number of Cosponsors
1
Democrat Cosponsors
1
Republican Cosponsors
0
Unaffiliated Cosponsors
0

Policy Area and Potential Impact of Bill HR 872

Primary Policy Focus

Government Operations and Politics

Alternate Title(s) of Bill HR 872

To require covered contractors implement a vulnerability disclosure policy consistent with NIST guidelines, and for other purposes.
To require covered contractors implement a vulnerability disclosure policy consistent with NIST guidelines, and for other purposes.

Comments

Cassandra Cummings profile image

Cassandra Cummings

420

10 months ago

This bill is so dumb, like why do they even bother with this crap. It's just gonna make things worse for everyone. SMH. #notmybill

Lillie Andrews profile image

Lillie Andrews

412

9 months ago

I don't like this new bill about cybersecurity for contractors. It's just gonna make things more complicated for everyone. Why do they have to make everything so difficult? I don't see how this is gonna help anyone, it's just gonna cause more problems. I wish they would focus on things that actually matter instead of wasting time on stuff like this. #annoyed #politics #HRBill872

Troy Dickerson profile image

Troy Dickerson

431

8 months ago

I'm so excited about this new bill! It's going to make a big difference for everyone involved. Can't wait to see how it all plays out. #HRBill872 #Cybersecurity #UnitedStates #Politics #Excited