Bill

Bill > HR872


US HR872

US HR872
Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025


summary

Introduced
01/31/2025
In Committee
01/31/2025
Crossed Over
03/04/2025
Passed
Dead

Introduced Session

119th Congress

Bill Summary

AN ACT To require covered contractors implement a vulnerability disclosure policy consistent with NIST guidelines, and for other purposes.

AI Summary

This bill requires federal contractors to implement a vulnerability disclosure policy in line with National Institute of Standards and Technology (NIST) guidelines. Specifically, the bill directs the Office of Management and Budget (OMB), in consultation with key cybersecurity agencies, to review and recommend updates to Federal Acquisition Regulation (FAR) contract requirements within 180 days. These updates will ensure that "covered contractors" (defined as contractors with contracts at or above the simplified acquisition threshold or those managing federal information systems) have a standardized process for receiving and addressing potential security vulnerabilities. The bill mandates that these vulnerability disclosure policies align with existing cybersecurity improvement acts and international standards. The Department of Defense is also required to conduct a similar review of its supplement to the FAR (DFARS). Agency heads are allowed to seek waivers for national security or research purposes, but must notify congressional committees within 30 days of granting such waivers. The goal is to create a more consistent and robust approach to identifying and addressing cybersecurity risks across federal contractor networks, ultimately enhancing the overall security of federal information systems.

Committee Categories

Government Affairs, Military Affairs and Security

Sponsors (2)

Last Action

Received in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs. (on 03/04/2025)

bill text


bill summary

Loading...

bill summary

Loading...
Loading...