HR872Passed House

Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025

Share:
Introduced
In Committee
Passed One Chamber
4
Passed Both
5
Signed into Law
119th
Congress
2025-01-31
Introduced
1
Cosponsors
HR
Type

Sponsor

Nancy Mace
Nancy Mace
Republican · SC · Representative
Votes with party: 94.3% (492 recorded votes)

Full profile: /officials/M000194

Source: Congress.gov · FEC

Cosponsors (1)

Members who have signed on to support this bill since introduction. Source: Congress.gov.

1 cosponsor on record at Congress.gov. The named list is syncing into Govwatch and will appear here shortly — view on Congress.gov in the meantime.

Latest Action

The most recent step in the bill's legislative path. Committee Activity below shows referrals and reports; the full action-by-action history including floor proceedings lives at Congress.gov →

Received in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs.

2025-03-04

Source: Congress.gov

Committee Activity

Plain-English Summary

Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025 This bill requires revisions to acquisition regulations related to information systems vulnerabilities for certain federal contractors. The revisions apply to contractors whose contract is at or above the simplified acquisition threshold ($250,000 in most cases) or that use, operate, manage, or maintain a federal information system on behalf of an agency. Under the bill, the Office of Management and Budget must review the Federal Acquisition Regulation (FAR) and recommend updated contract requirements and language for contractor vulnerability disclosure programs. (Such programs establish processes for identifying, reporting, and mitigating information system vulnerabilities discovered by security researchers, software developers, and others.) The recommendations must include requirements to ensure that such contractors implement vulnerability disclosure policies consistent with guidelines from the National Institute of Standards and Technology. The Federal Acquisition Regulation Council must review these recommendations and update the FAR as necessary to incorporate requirements for such contractors to receive information about potential security vulnerabilities in contractor information systems used in performance of contract. The Department of Defense (DOD) must conduct a similar review and update of regulations with respect to the DOD Supplement to the FAR.

Plain-English rewrite of the Congressional Research Service summary published on Congress.gov. Cached and reviewed.

Subjects

Government Operations and Politics
Full bill text is not yet cached locally.