Federal contractors must now report security flaws to government
H.R. 872 — Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025 · Filed by Nancy Mace (R-SC) · 1 cosponsor · Introduced Jan 31, 2025 · Passed chamber
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This bill requires federal contractors to adopt vulnerability disclosure policies aligned with NIST standards, allowing them to report security flaws they discover in government systems. OMB and DoD have 180 days to update federal procurement rules to mandate this practice; agencies can waive the requirement only for national security reasons with congressional notification.
Why we flagged it
The bill's operative mechanism is a procurement-rule update mandating vulnerability disclosure policies for federal contractors. It is a regulatory standard-setting measure, not a subsidy, carve-out, or deregulation.
What the text implies
- Contractors may face increased compliance costs to establish and maintain vulnerability disclosure programs, which could be passed to government through higher contract bids.
- The 180-day implementation timeline is aggressive; contractors with legacy systems may struggle to comply, potentially creating competitive advantage for larger firms with existing security infrastructure.
The full analysis lists 4 implications of this text.
Who stands to gain
cybersecurity consulting firms; vulnerability disclosure platform vendors; IT security service providers