Government contractors would need clear plans for reporting cybersecurity weaknesses.
This bill would require companies that do business with the federal government to have specific policies for reporting cybersecurity vulnerabilities. These new rules would help protect government information systems. They would do this by making sure contractors follow guidelines from the National Institute of Standards and Technology (NIST) for finding and reporting cyber flaws.
Today, federal contracting rules may not consistently require companies to have clear policies for reporting cybersecurity vulnerabilities. If this bill passes, the main government contracting rules (FAR) and the Department of Defense's rules (DFARS) would be updated. This would require covered contractors to implement vulnerability disclosure policies that follow NIST guidelines and set up ways to receive information about potential security weaknesses.
HR 872 · 119th Congress · January 31, 2025 · AI Summary by gemini-2.5-flash · 8/10
Sign in to see your representatives' phone numbers
9 filings mentioned this bill
Amounts reflect total quarterly lobbying spend reported to the Senate, not bill-specific spending. Source: Senate LDA filings.