H.R. 872 · 119th Congress
Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025
Introduced on Jan 31, 2025 by Nancy Mace (R-SC-1). One cosponsor. Latest action (Mar 4, 2025): Received in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
- Stage
- Passed one chamber
- Introduced
- Jan 31, 2025
- Cosponsors
- 1
- 1 from the other party
- Policy area
- Government Operations and Politics
Progress
The furthest stage the measure reached. Simple and concurrent resolutions do not go to the President.
- Introduced
- Reported by committee
- Passed one chamber
- 4Passed both chambers
- 5Sent to the President
- 6Became law
Official title
To require covered contractors implement a vulnerability disclosure policy consistent with NIST guidelines, and for other purposes.
Subjects
- Computer security and identity theft
- Government information and archives
- Public contracts and procurement
Summary
By the Congressional Research Service (Introduced in House, Jan 31, 2025). Public domain.
Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025
This bill requires revisions to acquisition regulations related to information systems vulnerabilities for certain federal contractors. The revisions apply to contractors whose contract is at or above the simplified acquisition threshold ($250,000 in most cases) or that use, operate, manage, or maintain a federal information system on behalf of an agency.
Under the bill, the Office of Management and Budget must review the Federal Acquisition Regulation (FAR) and recommend updated contract requirements and language for contractor vulnerability disclosure programs. (Such programs establish processes for identifying, reporting, and mitigating information system vulnerabilities discovered by security researchers, software developers, and others.) The recommendations must include requirements to ensure that such contractors implement vulnerability disclosure policies consistent with guidelines from the National Institute of Standards and Technology. The Federal Acquisition Regulation Council must review these recommendations and update the FAR as necessary to incorporate requirements for such contractors to receive information about potential security vulnerabilities in contractor information systems used in performance of contract.
The Department of Defense (DOD) must conduct a similar review and update of regulations with respect to the DOD Supplement to the FAR.
Sponsor and cosponsors
Cosponsors by party as of the day they signed on. Original cosponsors signed on the day of introduction.
Democrats · 1
- Shontel M. BrownD-OH-11original
Roll calls
Recorded votes on the measure. Most measures move by voice vote or unanimous consent, which record no individual positions.
No recorded roll call on this measure: it moved by voice vote or unanimous consent, or has not reached the floor.
History
Every action as published, oldest first. Roll calls link to how each member voted.
- Jan 31, 2025Introduced in House
- Jan 31, 2025Introduced in House
- Jan 31, 2025 · HouseReferred to the Committee on Oversight and Government Reform, and in addition to the Committee on Armed Services, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.
- Jan 31, 2025 · HouseReferred to the Committee on Oversight and Government Reform, and in addition to the Committee on Armed Services, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.
- Mar 3, 2025 · HouseMr. Comer moved to suspend the rules and pass the bill, as amended.
- Mar 3, 2025 · HouseConsidered under suspension of the rules. (consideration: CR H930-932)
- Mar 3, 2025 · HouseDEBATE - The House proceeded with forty minutes of debate on H.R. 872.
- Mar 3, 2025Passed/agreed to in House: On motion to suspend the rules and pass the bill, as amended Agreed to by voice vote. (text: CR H930-931)
- Mar 3, 2025 · HouseOn motion to suspend the rules and pass the bill, as amended Agreed to by voice vote. (text: CR H930-931)
- Mar 3, 2025 · HouseMotion to reconsider laid on the table Agreed to without objection.
- Mar 4, 2025 · SenateReceived in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
Committees
Committees and subcommittees the measure was referred to.
Agencies in its committees' jurisdiction
Analisa's mapping of committee jurisdiction to federal agencies; the bill may touch others, or none of these.
Who lobbied on it
Organizations whose lobbying reports (LD-2) name this measure. Spending is what they reported for those quarters on all issues, not on this measure alone.
- Google Client Services LLC6 reports$19.5M reported (all issues)
- HackerOne6 reports$60K reported (all issues)Federal contractor: HACKERONE INC.$162.8K in contracts, FY2026AI match · 100%
- NATIONAL SMALL BUSINESS ASSOCIATION6 reports$221K reported (all issues)
- Air Transport Association of America, Inc. (d/b/a Airlines for America)3 reports$3.3M reported (all issues)
- RED HAT INC3 reports$210K reported (all issues)
- Chamber of Commerce of the U.S.A.2 reports$31.6M reported (all issues)
Reports filed in 2025, 2026.
Sources and method
Every figure on this page traces to these records.
- Bill status: bills and resolutions, sponsors, actions, subjects and CRS summaries (U.S. Government Publishing Office (GovInfo), from Congress.gov (Library of Congress))GovInfo Bill Status bulk data (Congress.gov; summaries by the Congressional Research Service) · data current to Oct 6, 2026 · loaded Oct 6, 2026 · license: Public domain (U.S. Government work, 17 U.S.C. § 105)
- Members of Congress, their terms, committees and identifiers (The @unitedstates project (from the Biographical Directory of the U.S. Congress, the House and the Senate))unitedstates/congress-legislators: legislators, committees and current committee membership · data current to Oct 3, 2026 · loaded Oct 3, 2026 · license: CC0 1.0 (public domain dedication)
- House roll-call votes (Office of the Clerk, U.S. House of Representatives)Office of the Clerk, U.S. House of Representatives, roll-call vote records · data current to Oct 3, 2026 · loaded Oct 3, 2026 · license: Public domain (U.S. Government work, 17 U.S.C. § 105)
- Senate roll-call votes and DW-NOMINATE scores (Voteview (UCLA Department of Political Science))Lewis, Jeffrey B., Keith Poole, Howard Rosenthal, Adam Boche, Aaron Rudkin, and Luke Sonnet (2026). Voteview: Congressional Roll-Call Votes Database. https://voteview.com/ · data current to Oct 3, 2026 · loaded Oct 3, 2026 · license: Free to use with the required citation
- Lobbying disclosures (LD-1 registrations, LD-2 quarterly reports, LD-203 contribution reports) (Clerk of the U.S. House of Representatives)Clerk of the House, Lobbying Disclosure Act filings (organizations only; lobbyists' names are not loaded) · data current to Oct 6, 2026 · loaded Oct 6, 2026 · license: Public domain (U.S. Government work, 17 U.S.C. § 105)
- Positions are shown only where a roll call recorded them; voice votes and unanimous consent record none.
- Money and votes are shown side by side; neither explains the other.