Companies working for the nation must report security flaws.
H.R. 872 — Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025 · Filed by Nancy Mace (R-SC) · 1 cosponsor · Introduced Jan 31, 2025 · Passed chamber
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This bill requires companies working for the nation to set up ways to report flaws they find. The flaws must be reported using NIST standards. Two agencies have 180 days to update the rules for these companies. Agencies can skip this rule only for national defense reasons. They must tell Congress when they do.
Who it affects
Companies working for the nation must follow the new rules. The nation gets better protection for its systems and the facts it holds about people.
One thing to notice
Companies may have to spend more money to set up these ways to report flaws. They might pass that cost to the nation through higher prices.
From the analysis of the bill text, linked under Primary records below.
Where it stands
1 cosponsor: 1 Democrats.
- Jan 31, 2025 — Introduced · Congress.gov: “Introduced in House”
- Jan 31, 2025 — Referred to House Committee on Armed Services and House Committee on Oversight and Government Reform · Congress.gov: “Referred to the Committee on Oversight and Government Reform, and in addition to the Committee on Armed…”
- Mar 3, 2025 — Passed the House · Congress.gov: “Motion to reconsider laid on the table Agreed to without objection”
- Mar 3, 2025 — Floor vote scheduled · Congress.gov: “Mr. Comer moved to suspend the rules and pass the bill, as amended”
Dates and quoted wording are Congress.gov's action record; the timeline shows status changes, not every procedural step.
Money around this bill
4 groups reported lobbying about this bill. They filed 6 reports from Dec 2025 to Jun 2026.
Those reports show $24,970,000 in lobbying spending. Each report lists about 40 bills. So that money was not all for this bill.
More groups named this bill than 72% of bills with any report.
Nancy Mace, who sponsored the bill, received $8,000 from PACs for the 2026 election.
- Chamber of Commerce of the U.S.A. — $17,960,000 in 1 report
- Google Client Services LLC — $6,920,000 in 2 reports
- Red Hat Inc — $70,000 in 1 report
- Hackerone — $20,000 in 2 reports
Lobbying is legal. These reports show who lobbied about this bill, not what changed.
Words to know
- NIST standards — Rules for keeping computer systems safe made by the National Institute of Standards and Technology.
- national defense — Keeping the country and its military safe from harm.
- agencies — Parts of the nation's system that do specific jobs.
- Congress — The group of people who make laws for the nation.
- lobbying — Trying to influence lawmakers about a bill. Companies and groups pay people to do this.
- PACs — Groups that collect money and give it to candidates for office.
How this was measured
Analysis — Quorum's AI read the bill text published by Congress.gov (5,855 characters) on Aug 20, 2026. Section numbers in the findings refer to that text, linked below; transparency and hidden-provision scores are compared against the median of 14,342 analysed bills.
Status and sponsors — Congress.gov's bill record — actions, committee referrals and cosponsors — loaded nightly. The timeline shows status changes, not every procedural action.
Money — Senate Lobbying Disclosure Act filings whose specific-issue field names this bill for quarters ending Dec 2025 to Jun 2026. A filing's amount is reported whole beside the median number of bills a filing names; it is never divided across them. PAC receipts are FEC-reported contributions to the sponsor's candidate committee in the 2026 cycle.
As of — lobbying records through Jul 20, 2026 · page rendered 2026-09-18.
“Companies working for the nation must report security flaws.” QuorumCivic. https://share.quorumcivic.app/bill/119/hr872/simple Report an error