Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025
Click any stage to learn more about the legislative process.
The bill would require federal agencies to update contracting rules so that many federal contractors must adopt a vulnerability disclosure policy for reporting and fixing cybersecurity flaws in their information systems.
It would apply to contractors above a $250,000 acquisition threshold or that manage federal information systems, aiming to close a gap where contractor systems connected to government networks lack standard processes for reporting security vulnerabilities.
What this bill would do
What it would do
The bill would direct the Office of Management and Budget, working with cybersecurity and standards agencies, to review Federal Acquisition Regulation (FAR) requirements for contractor vulnerability disclosure programs and recommend updates within 180 days of enactment. The FAR Council would then have 180 days to revise the FAR to require covered contractors to let agencies receive information about security vulnerabilities in contractor-owned systems used in contract performance. The Department of Defense would separately review and update its own FAR supplement (DFARS) on the same timeline and requirements. The recommendations must align with NIST guidelines and existing IoT Cybersecurity Improvement Act disclosure requirements, and align with industry standards where practicable. Agency heads and the Defense Department's Chief Information Officer may waive the requirement for national-security or research reasons, with notification to relevant congressional committees within 30 days of granting a waiver.
Key provisions
- 1Would require OMB to review FAR contractor vulnerability disclosure requirements and recommend updates within 180 days of enactment
- 2Would require recommendations to ensure covered contractors implement disclosure policies consistent with NIST guidelines
- 3Would require the FAR Council to update the FAR within 180 days of receiving recommendations so contractors must report potential security vulnerabilities to agencies
- 4Would require alignment with IoT Cybersecurity Improvement Act disclosure processes and international standards where practicable
- 5Would allow agency heads to waive the disclosure requirement for national security or research purposes, with notification to Congress within 30 days
- 6Would require the Department of Defense to conduct a parallel review and update of its FAR supplement (DFARS) on the same timeline
Who would be affected
Federal contractors whose contracts meet or exceed the simplified acquisition threshold (generally $250,000) or who operate, manage, or maintain federal information systems, along with the Office of Management and Budget, the Federal Acquisition Regulation Council, and the Department of Defense, which must revise their respective procurement regulations.
Why it matters
Contractors covered by the bill would need to establish formal processes for security researchers and others to report vulnerabilities in systems connected to federal contract work, potentially closing gaps that could otherwise let cybersecurity flaws go unreported or unfixed. Agencies gain a waiver option for sensitive national-security or research contracts.
What would change
Changes to existing law
Amends Federal Acquisition Regulation (Sec. 2(b))
Would add contractor vulnerability disclosure policy requirements consistent with NIST guidelines to procurement rules
Amends Department of Defense Supplement to the Federal Acquisition Regulation (DFARS) (Sec. 2(e))
Would add parallel vulnerability disclosure requirements for Defense Department contractors
Amends IoT Cybersecurity Improvement Act of 2020 (Sec. 2(a)(2))
New FAR requirements must align with this Act's existing vulnerability disclosure and coordinated disclosure processes
Agencies directed to act
Effective dates
- OMB review and recommendations on FAR vulnerability disclosure requirements
- FAR Council update to FAR after receiving OMB recommendations
- Defense Department review of DFARS contractor requirements
- Defense Department revision of DFARS after completing review
How implementation would work
OMB, in consultation with the Cybersecurity and Infrastructure Security Agency, the National Cyber Director, and NIST, must review FAR language and issue recommendations within 180 days of enactment. The FAR Council then has 180 days from receiving those recommendations to update the FAR, aligning with NIST guidance, the IoT Cybersecurity Improvement Act, and ISO standards where practicable. The Defense Department runs a parallel process for its own supplement. Agency heads or the Defense CIO may waive requirements for national-security or research reasons but must notify relevant congressional committees with justification within 30 days of any waiver.
Legislative status & sources
Latest action
Received in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
Official CRS summary
Show the CRS summaryHide the CRS summary
This bill requires revisions to acquisition regulations related to information systems vulnerabilities for certain federal contractors. The revisions apply to contractors whose contract is at or above the simplified acquisition threshold ($250,000 in most cases) or that use, operate, manage, or maintain a federal information system on behalf of an agency.
Under the bill, the Office of Management and Budget must review the Federal Acquisition Regulation (FAR) and recommend updated contract requirements and language for contractor vulnerability disclosure programs. (Such programs establish processes for identifying, reporting, and mitigating information system vulnerabilities discovered by security researchers, software developers, and others.) The recommendations must include requirements to ensure that such contractors implement vulnerability disclosure policies consistent with guidelines from the National Institute of Standards and Technology. The Federal Acquisition Regulation Council must review these recommendations and update the FAR as necessary to incorporate requirements for such contractors to receive information about potential security vulnerabilities in contractor information systems used in performance of contract.
The Department of Defense (DOD) must conduct a similar review and update of regulations with respect to the DOD Supplement to the FAR.
Legislative subjects
Computer security and identity theft; Government Operations and Politics; Government information and archives; Public contracts and procurement