119th Congress · HOUSE BILLBILL

H.R. 872Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025

To require covered contractors implement a vulnerability disclosure policy consistent with NIST guidelines, and for other purposes.

Government operations and politics
Introduced Jan 31, 2025
Last action Mar 4, 2025
Pipeline · Bill → Law
Step 1
Introduced
Jan 31, 2025
Step 2
Referred
Jan 31, 2025
Armed Services · Oversight · Homeland Security and Governmental Affairs
Step 3
Committee
Step 4
House floor
Step 5
Senate
Mar 4, 2025
Step 6
Resolve Changes
Step 7
Signed
SummaryCRS Summary

This bill requires revisions to acquisition regulations related to information systems vulnerabilities for certain federal contractors. The revisions apply to contractors whose contract is at or above the simplified acquisition threshold ($250,000 in most cases) or that use, operate, manage, or maintain a federal information system on behalf of an agency.  Under the bill, the Office of Management and Budget must review the Federal Acquisition Regulation (FAR) and recommend updated contract requirements and language for contractor vulnerability disclosure programs. (Such programs establish processes for identifying, reporting, and mitigating information system vulnerabilities discovered by s...

Provisions · 2 sectionsEngrossed in House
3 versions
Engrossed in House · 2 provisions
AI
Timeline · 9 actions
Mar 4, 2025
Received in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
Mar 3, 2025
Mr. Comer moved to suspend the rules and pass the bill, as amended.
Mar 3, 2025
Considered under suspension of the rules.
Mar 3, 2025
DEBATE - The House proceeded with forty minutes of debate on H.R. 872.
Mar 3, 2025
On motion to suspend the rules and pass the bill, as amended Agreed to by voice vote.
Mar 3, 2025
Motion to reconsider laid on the table Agreed to without objection.
Jan 31, 2025
Introduced in House
Jan 31, 2025
Referred to the Committee on Oversight and Government Reform, and in addition to the Committee on Armed Services, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.
Jan 31, 2025
Referred to the Committee on Oversight and Government Reform, and in addition to the Committee on Armed Services, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.