- H.R. 10171August 27, 2026
- H.R. 10156August 27, 2026
- H.R. 10172August 27, 2026
- H.R. 10160August 27, 2026
- H.R. 10181August 27, 2026
- H.R. 10176August 27, 2026
- H.Res. 1496August 27, 2026
- H.R. 10164August 27, 2026
- H.R. 10170August 27, 2026
- H.Res. 1494August 27, 2026
- H.R. 10163August 27, 2026
- H.R. 10157August 27, 2026
- Administration
- Agriculture
- Agriculture, Nutrition, And Forestry
- Appropriations
- Armed Services
- Banking, Housing, And Urban Affairs
- Budget
- Commerce, Science, And Transportation
- Education and Workforce
- Energy And Commerce
- Energy And Natural Resources
- Environment And Public Works
- Ethics
- Finance
- Financial Services
- Foreign Affairs
- Foreign Relations
- Health, Education, Labor, And Pensions
- Homeland Security
- Homeland Security And Governmental Affa…
- Indian Affairs
- Indian and Insular Affairs
- Intelligence
- Judiciary
- Natural Resources
- Oversight And Government Reform
- Permanent Select Intelligence
- Rules
- Rules And Administration
- Science, Space, And Technology
- Select Intelligence
- Small Business
- Small Business And Entrepreneurship
- Subcommittee on Aviation
- Subcommittee on Border Security and Enf…
- Subcommittee on Coast Guard and Maritim…
- Subcommittee on Commodity Markets, Digi…
- Subcommittee on Conservation, Research,…
- Subcommittee on Counterterrorism and In…
- Subcommittee on Cybersecurity and Infra…
- Subcommittee on Disability Assistance a…
- Subcommittee on Economic Development, P…
- Subcommittee on Economic Opportunity
- Subcommittee on Emergency Management an…
- Subcommittee on Energy and Mineral Reso…
- Subcommittee on Federal Lands
- Subcommittee on Forestry and Horticultu…
- Subcommittee on General Farm Commoditie…
- Subcommittee on Health
- Subcommittee on Highways and Transit
- Subcommittee on Livestock, Dairy, and P…
- Subcommittee on Nutrition and Foreign A…
- Subcommittee on Oversight and Investiga…
- Subcommittee on Oversight, Investigatio…
- Subcommittee on Railroads, Pipelines, a…
- Subcommittee on Transportation and Mari…
- Subcommittee on Water Resources and Env…
- Subcommittee on Water, Wildlife and Fis…
- Transportation And Infrastructure
- Veterans' Affairs
- Ways And Means

H.R. 872
U.S. House•In Senate Committee
Summary
H.R. 872, the Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025, was introduced in the House on Jan 31, 2025 by Rep. Nancy Mace (R) with 1 co-sponsor. It was referred to Homeland Security And Governmental Affairs, and last saw action on Mar 4, 2025: Received in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
Record
Text
H.R. 872 has 1 co-sponsor.
hb872/engrossed-in-house.txt119 HR 872 EH: Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025U.S. House of Representativestext/xmlENPursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.I119th CONGRESS 1st SessionH. R. 872IN THE HOUSE OF REPRESENTATIVESAN ACTTo require covered contractors implement a vulnerability disclosure policy consistent with NIST guidelines, and for other purposes.1.Short titleThis Act may be cited as the Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025 .2.Federal contractor vulnerability disclosure policy(a)Recommendations(1)In generalNot later than 180 days after the date of the enactment of this Act, the Director of the Office of Management and Budget, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, the National Cyber Director, the Director of the National Institute of Standards and Technology, and any other appropriate head of an Executive department, shall—(A)review the Federal Acquisition Regulation contract requirements and language for contractor vulnerability disclosure programs; and(B)recommend updates to such requirements and language to the Federal Acquisition Regulation Council.(2)ContentsThe recommendations required by paragraph (1) shall include updates to such requirements designed to ensure that covered contractors implement a vulnerability disclosure policy consistent with NIST guidelines for contractors as required under section 5 of the IoT Cybersecurity Improvement Act of 2020 (15 U.S.C. 278g–3c; Public Law 116–207 ).(b)Procurement requirementsNot later than 180 days after the date on which the recommended contract language developed pursuant to subsection (a) is received, the Federal Acquisition Regulation Council shall review the recommended contract language and update the FAR as necessary to incorporate requirements for covered contractors to receive information about a potential security vulnerability relating to an information system owned or controlled by a contractor, in performance of the contract.(c)ElementsThe update to the FAR pursuant to subsection (b) shall—(1)to the maximum extent practicable, align with the security vulnerability disclosure process and coordinated disclosure requirements relating to Federal information systems under sections 5 and 6 of the IoT Cybersecurity Improvement Act of 2020 ( Public Law 116–207 ; 15 U.S.C. 278g–3c and 278g–3d); and(2)to the maximum extent practicable, be aligned with industry best practices and Standards 29147 and 30111 of the International Standards Organization (or any successor standard) or any other appropriate, relevant, and widely used standard.(d)WaiverThe head of an agency may waive the security vulnerability disclosure policy requirement under subsection (b) if—(1)the agency Chief Information Officer determines that the waiver is necessary in the interest of national security or research purposes; and(2)if, not later than 30 days after granting a waiver, such head submits a notification and justification (including information about the duration of the waiver) to the Committee on Oversight and Government Reform of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate.(e)Department of defense supplement to the federal acquisition regulation(1)ReviewNot later than 180 days after the date of the enactment of this Act, the Secretary of Defense shall review the Department of Defense Supplement to the Federal Acquisition Regulation contract requirements and language for contractor vulnerability disclosure programs and develop updates to such requirements designed to ensure that covered contractors implement a vulnerability disclosure policy consistent with NIST guidelines for contractors as required under section 5 of the IoT Cybersecurity Improvement Act of 2020 (15 U.S.C. 278g–3c; Public Law 116–207 ).(2)RevisionsNot later than 180 days after the date on which the review required under subsection (a) is completed, the Secretary shall revise the DFARS as necessary to incorporate requirements for covered contractors to receive information about a potential security vulnerability relating to an information system owned or controlled by a contractor, in performance of the contract.(3)ElementsThe Secretary shall ensure that the revision to the DFARS described in this subsection is carried out in accordance with the requirements of paragraphs (1) and (2) of subsection (c).(4)WaiverThe Chief Information Officer of the Department of Defense, in consultation with the National Manager for National Security Systems, may waive the security vulnerability disclosure policy requirements under paragraph (2) if the Chief Information Officer—(A)determines that the waiver is necessary in the interest of national security or research purposes; and(B)not later than 30 days after granting a waiver, submits a notification and justification (including information about the duration of the waiver) to the Committees on Armed Services of the House of Representatives and the Senate.(f)DefinitionsIn this section:(1)The term agency has the meaning given the term in section 3502 of title 44, United States Code.(2)The term covered contractor means a contractor (as defined in section 7101 of title 41, United States Code)—(A)whose contract is in an amount the same as or greater than the simplified acquisition threshold; or(B)that uses, operates, manages, or maintains a Federal information system (as defined by section 11331 of title 40, United Stated Code) on behalf of an agency.(3)The term DFARS means the Department of Defense Supplement to the Federal Acquisition Regulation.(4)The term Executive department has the meaning given that term in section 101 of title 5, United States Code.(5)The term FAR means the Federal Acquisition Regulation.(6)The term NIST means the National Institute of Standards and Technology.(7)The term OMB means the Office of Management and Budget.(8)The term security vulnerability has the meaning given that term in section 2200 of the Homeland Security Act of 2002 ( 6 U.S.C. 650 ).(9)The term simplified acquisition threshold has the meaning given that term in section 134 of title 41, United States Code.Passed the House of Representatives March 3, 2025. Kevin F. McCumber, Clerk.
Tracker
The tracker indicates the progress of this legislation as it moves through the legislative process.
- Introduced2025-01-31
- Passed House2025-03-03
- Passed Senate
- Conference
- To President
- Became Law
CRS Summary
The summaries are the Congressional Research Service’s, one per stage. Read them in full.
Introduced in House Jan 31, 2025
hb872/introduced-in-house.mdShown Here:
Introduced in House (01/31/2025)
Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025
This bill requires revisions to acquisition regulations related to information systems vulnerabilities for certain federal contractors. The revisions apply to contractors whose contract is at or above the simplified acquisition threshold ($250,000 in most cases) or that use, operate, manage, or maintain a federal information system on behalf of an agency.
Under the bill, the Office of Management and Budget must review the Federal Acquisition Regulation (FAR) and recommend updated contract requirements and language for contractor vulnerability disclosure programs. (Such programs establish processes for identifying, reporting, and mitigating information system vulnerabilities discovered by security researchers, software developers, and others.) The recommendations must include requirements to ensure that such contractors implement vulnerability disclosure policies consistent with guidelines from the National Institute of Standards and Technology. The Federal Acquisition Regulation Council must review these recommendations and update the FAR as necessary to incorporate requirements for such contractors to receive information about potential security vulnerabilities in contractor information systems used in performance of contract.
The Department of Defense (DOD) must conduct a similar review and update of regulations with respect to the DOD Supplement to the FAR.
Sponsors
Rep. Nancy Mace (R) sponsors H.R. 872, and 1 member has co-sponsored it from the day it was introduced.
Committees
H.R. 872 went before 3 committees: Homeland Security and Governmental Affairs, Armed Services and Oversight and Government Reform.


Actions
H.R. 872 has taken 9 actions since Jan 31, 2025, the latest on Mar 4, 2025.
| Chamber | Action | |||
|---|---|---|---|---|
Mar 4, 2025 | Senate | Received in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs.Homeland Security and Governmental Affairs Committee | ||
Mar 3, 202515:51 | House | Mr. Comer moved to suspend the rules and pass the bill, as amended. | ||
Mar 3, 202515:51 | House | Considered under suspension of the rules. (consideration: CR H930-932) | ||
Mar 3, 202515:51 | House | DEBATE - The House proceeded with forty minutes of debate on H.R. 872. | ||
Mar 3, 202516:02 | House | On motion to suspend the rules and pass the bill, as amended Agreed to by voice vote. (text: CR H930-931) |
Votes
H.R. 872 has not gone to a roll call.
Related bills
1 bill is related to H.R. 872.
Titles
H.R. 872 goes by 6 titles, 3 of them short titles.
- To require covered contractors implement a vulnerability disclosure policy consistent with NIST guidelines, and for other purposes. — Official Titles from EH (Engrossed in House) bill text
- Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025 — Short Titles from RFS (Referred to Senate) bill text
- Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025 — Short Title(s) as Passed House
- Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025 — Display Title
- Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025 — Short Title(s) as Introduced
- To require covered contractors implement a vulnerability disclosure policy consistent with NIST guidelines, and for other purposes. — Official Title as Introduced
Lobbying
6 clients hired 6 firms and 118 registered lobbyists who named H.R. 872 in 26 quarterly filings, 2025 to 2026. Reported under the Lobbying Disclosure Act; a filing’s income covers everything its registrant worked that quarter, so the amounts below are the filings’, not this bill’s.
Filed under Small Business, Defense, Computer Industry, Budget/Appropriations, Copyright/Patent/Trademark, Education, Energy/Nuclear, Foreign Relations.
Clients
Who paid to be heard, by how many filings named the bill.
| Client | Business | State | Firms | Filings | Reported |
|---|---|---|---|---|---|
| HACKERONE | Cybersecurity company | California | 1 | 6 | $60K |
| GOOGLE CLIENT SERVICES LLC | — | District of Columbia | 1 | 6 | — |
| NATIONAL SMALL BUSINESS ASSOCIATION | — | District of Columbia | 1 | 6 | — |
| AIR TRANSPORT ASSOCIATION OF AMERICA, INC. (D/B/A AIRLINES FOR AMERICA) | — | District of Columbia | 1 | 3 | — |
| RED HAT INC | — | North Carolina | 1 | 3 | — |
| CHAMBER OF COMMERCE OF THE U.S.A. | — | District of Columbia | 1 | 2 | — |
Firms
Registrants who filed on the bill, by filings.
| Registrant | Clients | Filings | Reported |
|---|---|---|---|
| GOOGLE CLIENT SERVICES LLC | 1 | 6 | — |
| NATIONAL SMALL BUSINESS ASSOCIATION | 1 | 6 | — |
| VENABLE LLP | 1 | 6 | $60K |
| AIR TRANSPORT ASSOCIATION OF AMERICA, INC. (D/B/A AIRLINES FOR AMERICA) | 1 | 3 | — |
| RED HAT INC | 1 | 3 | — |
| CHAMBER OF COMMERCE OF THE U.S.A. | 1 | 2 | — |
Lobbyists
Named on the filings that cite the bill. The 20 named most often, of 118.
| Lobbyist | Firms | Clients | Filings |
|---|---|---|---|
| ANDREW LADNER | 1 | 1 | 6 |
| CHRISTY WOODRUFF | 1 | 1 | 6 |
| EDWARD AN | 1 | 1 | 6 |
| FRANNIE LASALA | 1 | 1 | 6 |
| JOHN FURTH | 1 | 1 | 6 |
| JOHN V. DRZEWICKI | 1 | 1 | 6 |
| JOSH FINESTONE | 1 | 1 | 6 |
| NICHOLAS CHOATE | 1 | 1 | 6 |
| SAMANTHA DYBAS | 1 | 1 | 6 |
| TODD MCCRACKEN | 1 | 1 | 6 |
| ANNA HEGRENESS | 1 | 1 | 5 |
| RACHEL GREY | 1 | 1 | 4 |
| REED WESTCOTT | 1 | 1 | 4 |
| CHERYL BRUNER | 1 | 1 | 3 |
| JARROD THOMPSON | 1 | 1 | 3 |
| JOSHUA SALTZMAN | 1 | 1 | 3 |
| SHARON PINKERTON | 1 | 1 | 3 |
| STEPHANIE DOHERTY | 1 | 1 | 3 |
| ABELARDO TORRES | 1 | 1 | 2 |
| ALEXA BRANSON | 1 | 1 | 2 |
Filings
The documents themselves, on the Senate’s Lobbying Disclosure site, largest reported first.
| Client | Registrant | Period | Reported | Document |
|---|---|---|---|---|
| CHAMBER OF COMMERCE OF THE U.S.A. | CHAMBER OF COMMERCE OF THE U.S.A. | 2025 fourth_quarter | $18M | 4th Quarter - Report |
| CHAMBER OF COMMERCE OF THE U.S.A. | CHAMBER OF COMMERCE OF THE U.S.A. | 2025 third_quarter | $13.7M | 3rd Quarter - Report |
| GOOGLE CLIENT SERVICES LLC | GOOGLE CLIENT SERVICES LLC | 2026 second_quarter | $3.6M | 2nd Quarter - Report |
| GOOGLE CLIENT SERVICES LLC | GOOGLE CLIENT SERVICES LLC | 2025 third_quarter | $3.6M | 3rd Quarter - Report |
| GOOGLE CLIENT SERVICES LLC | GOOGLE CLIENT SERVICES LLC | 2025 fourth_quarter | $3.4M | 4th Quarter - Report |
| GOOGLE CLIENT SERVICES LLC | GOOGLE CLIENT SERVICES LLC | 2025 second_quarter | $3.2M | 2nd Quarter - Report |
| GOOGLE CLIENT SERVICES LLC | GOOGLE CLIENT SERVICES LLC | 2025 first_quarter | $3M | 1st Quarter - Report |
| GOOGLE CLIENT SERVICES LLC | GOOGLE CLIENT SERVICES LLC | 2026 first_quarter | $2.9M | 1st Quarter - Report |
| AIR TRANSPORT ASSOCIATION OF AMERICA, INC. (D/B/A AIRLINES FOR AMERICA) | AIR TRANSPORT ASSOCIATION OF AMERICA, INC. (D/B/A AIRLINES FOR AMERICA) | 2025 fourth_quarter | $1.2M | 4th Quarter - Report |
| AIR TRANSPORT ASSOCIATION OF AMERICA, INC. (D/B/A AIRLINES FOR AMERICA) | AIR TRANSPORT ASSOCIATION OF AMERICA, INC. (D/B/A AIRLINES FOR AMERICA) | 2026 second_quarter | $1.1M | 2nd Quarter - Report |
| AIR TRANSPORT ASSOCIATION OF AMERICA, INC. (D/B/A AIRLINES FOR AMERICA) | AIR TRANSPORT ASSOCIATION OF AMERICA, INC. (D/B/A AIRLINES FOR AMERICA) | 2026 first_quarter | $1M | 1st Quarter - Report |
| RED HAT INC | RED HAT INC | 2025 fourth_quarter | $70K | 4th Quarter - Report |
| RED HAT INC | RED HAT INC | 2025 third_quarter | $70K | 3rd Quarter - Report |
| RED HAT INC | RED HAT INC | 2025 second_quarter | $70K | 2nd Quarter - Report |
| NATIONAL SMALL BUSINESS ASSOCIATION | NATIONAL SMALL BUSINESS ASSOCIATION | 2025 second_quarter | $60K | 2nd Quarter - Report |
| NATIONAL SMALL BUSINESS ASSOCIATION | NATIONAL SMALL BUSINESS ASSOCIATION | 2025 third_quarter | $50K | 3rd Quarter - Report |
| NATIONAL SMALL BUSINESS ASSOCIATION | NATIONAL SMALL BUSINESS ASSOCIATION | 2025 first_quarter | $50K | 1st Quarter - Report |
| NATIONAL SMALL BUSINESS ASSOCIATION | NATIONAL SMALL BUSINESS ASSOCIATION | 2025 fourth_quarter | $30K | 4th Quarter - Report |
| NATIONAL SMALL BUSINESS ASSOCIATION | NATIONAL SMALL BUSINESS ASSOCIATION | 2026 second_quarter | $16K | 2nd Quarter - Report |
| NATIONAL SMALL BUSINESS ASSOCIATION | NATIONAL SMALL BUSINESS ASSOCIATION | 2026 first_quarter | $15K | 1st Quarter - Report |
Classification
The Congressional Research Service files H.R. 872 under Government Operations and Politics, one of its 31 policy areas, and gives it 3 legislative subjects.
CRS Subjects
CRS assigns every bill one policy area from its 31; H.R. 872’s is Government Operations and Politics.
hr872/policy-areas.txtLegislative Subjects
H.R. 872 carries 3 of CRS’s legislative subjects, from Computer security and identity theft to Public contracts and procurement.
hr872/subjects.txtConstitutional authority
The clause the sponsor cites as Congress’s power to enact H.R. 872, as entered in the Congressional Record.
[Congressional Record Volume 171, Number 21 (Friday, January 31, 2025)][House]From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]By Ms. MACE:H.R. 872.Congress has the power to enact this legislation pursuantto the following:Article I, Section 8 of the Constitution.[Page H434]
Source: congress.gov · legiscan.com