Skip to content

Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025

Passed first chamber: it can still change before the session ends.

US HR 872 · House Bill · 119th Congress

Stage
Passed first chamber
Started in
House
Sponsors
2
Latest action
Mar 4, 2025

What it does

Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025 This bill requires revisions to acquisition regulations related to information systems vulnerabilities for certain federal contractors. The revisions apply to contractors whose contract is at or above the simplified acquisition threshold ($250,000 in most cases) or that use, operate, manage, or maintain a federal information system on behalf of an agency. Under the bill, the Office of Management and Budget must review the Federal Acquisition Regulation (FAR) and recommend updated contract requirements and language for contractor vulnerability disclosure programs. (Such programs establish processes for identifying,…

Official summary · Introduced in House · Jan 31, 2025

Titles and provisions can change as the bill moves.

Read the full textRead it on the official site

Where it stands

  1. Introduced (Done)

    Jan 31, 2025

  2. Committee (Done)

  3. Floor (Current step)

    Passed first chamber · Mar 4, 2025

  4. Law (Not started)

What moved

Loading recorded actions…

Who is involved

Sponsors

The lawmakers who put their names on it, lead sponsors first.

In the news

Reporting that may mention this subject. Possible matches are labeled.

Loading coverage…

Where it goes next

While a bill can still move, the questions are about people and money.

Work with this bill

Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025 | 52