Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

H.R. 872, the Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025, would prompt reviews of federal acquisition rules to strengthen vulnerability disclosure requirements for certain contractors. The House passed it on March 3, 2025, but it has not become law: the official record shows it referred to a Senate committee. Its Senate counterpart, S. 1899, has a separate legislative history and has not advanced beyond committee referral.

What is the bill, and where does it stand?

The Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025 was introduced in the 119th Congress as House bill H.R. 872 and Senate bill S. 1899. These are companion proposals, not a single bill that has passed both chambers. Congress.gov’s H.R. 872 record labels the bill “Passed House.” The House approved it by voice vote on March 3, 2025; it was received in the Senate and referred to the Committee on Homeland Security and Governmental Affairs on March 4.

The Senate counterpart was introduced on May 22, 2025 and referred to the same committee. Its record shows no further action. Congress.gov’s S. 1899 record tracks that bill separately. Neither referral nor House passage makes the proposal an operative contractor mandate.

What would H.R. 872 change?

The bill would set a process for reviewing and potentially revising federal acquisition rules, rather than immediately inserting a new, effective clause into every covered contract. Under the proposal, the Office of Management and Budget (OMB) would review the Federal Acquisition Regulation (FAR) and recommend updated contractor requirements and contract language. The FAR Council would consider OMB’s recommendations and update the FAR as necessary. The Department of Defense would conduct a similar review of the Defense Federal Acquisition Regulation Supplement (DFARS).

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The goal is to establish vulnerability disclosure programs: organized ways for researchers, software developers, and others to report potential security flaws and for organizations to receive and handle those reports. The bill calls for policy requirements consistent with National Institute of Standards and Technology (NIST) guidance, focused on vulnerabilities affecting contractor information systems used in performing federal contracts.

Which contractors could be covered?

The House bill’s summary describes two broad coverage routes:

  • A contractor has a contract at or above the simplified acquisition threshold, which Congress.gov describes as $250,000 in most cases.
  • A contractor uses, operates, manages, or maintains a federal information system on an agency’s behalf.

These are proposed coverage criteria, not a final determination of which companies or contract clauses would be covered. The acquisition-rule reviews and any resulting rule changes would shape how requirements are implemented.

How H.R. 872 compares with S. 1899

Bill Chamber and action Status in the official record
H.R. 872 House; passed by voice vote March 3, 2025 Received in the Senate and referred to the Homeland Security and Governmental Affairs Committee March 4, 2025; labeled “Passed House”
S. 1899 Senate; introduced May 22, 2025 Referred to the Homeland Security and Governmental Affairs Committee; no further action shown

Each bill’s procedural status can change. The linked Congress.gov records are the authoritative trackers for subsequent action.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How it relates to existing federal vulnerability disclosure policy

H.R. 872 would not be the first federal law to address vulnerability disclosure by government suppliers. The IoT Cybersecurity Improvement Act, signed in December 2020, established a related requirement for contractors and vendors providing information systems to the U.S. government to adopt coordinated vulnerability disclosure policies, as described in Senator Maggie Hassan’s account of the law.

That IoT-related statutory setting is distinct from H.R. 872’s proposed, broader acquisition-rule reviews. The House bill’s focus is on using the FAR and DFARS processes to recommend or adopt updated requirements for covered contractors; it should not be described as though the 2020 law and this proposal impose identical obligations.

What NIST SP 800-216 recommends

NIST Special Publication 800-216, Recommendations for Federal Vulnerability Disclosure Guidelines, was published in May 2023. NIST says formalizing how organizations accept, assess, and manage vulnerability disclosure reports can help reduce known vulnerabilities. The publication recommends a federal framework for handling reports and communicating mitigation or remediation, and says the framework should apply to software, hardware, and digital services under federal control. See the NIST SP 800-216 publication page.

This guidance helps explain the kind of process the proposed legislation points toward: a channel for reports, a way to assess them, and a means to manage and communicate a response. It is technical guidance, not evidence that the proposed FAR or DFARS changes have already taken effect.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What federal contractors can assess now

Because H.R. 872 is not enacted, contractors should treat it as a proposal rather than a current legal obligation created by this bill. For planning, organizations can assess whether their contract values or systems fit the bill’s described coverage routes and whether their existing process can:

  • Provide a clear channel for receiving vulnerability reports.
  • Assess and manage reports through a defined process.
  • Communicate mitigation or remediation to relevant parties.

Those are practical readiness questions informed by the proposal and NIST guidance; they do not substitute for checking the requirements in a specific contract or any applicable existing law.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.