Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Business and Policy - New Bill Aims to Strengthen Cybersecurity for Federal Contractors
Business and Policy Latest News News & Analysis Regulations and Compliance Security

New Bill Aims to Strengthen Cybersecurity for Federal Contractors

Kirsten DoyleBy Kirsten DoyleMarch 13, 2025Updated:March 13, 20256 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
New Bill
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The House of Representatives has passed a bill that mandates contractors working with the federal government implement vulnerability disclosure policies (VDPs) in alignment with NIST guidelines.   

The Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025, introduced by Chairwoman Nancy Mace (R-S.C.) and Ranking Member Shontel Brown (D-Ohio), directs the Office of Management and Budget (OMB) to work with CISA, the National Cyber Director’s Office, NIST, and other agencies.  

The bill also asks the Defense Department to ensure defense contractors adopt similar policies. 

The Office of Management and Budget and the Department of Defense will be required to update federal acquisition policies to reflect these changes. 

The Bill outlines several steps related to updating security vulnerability disclosure requirements for government contractors: 

  1. Recommendations (180 days): The Director of the Office of Management and Budget, in collaboration with other agencies, will review the Federal Acquisition Regulation on contractor vulnerability disclosure programs and recommend updates, ensuring they align with NIST guidelines. 
  1. Procurement Requirements (180 days after recommendations): The FAR Council will review and update contract language based on the recommendations to ensure contractors are informed about potential security vulnerabilities in the systems they manage. 
  1. Update Details: The updated FAR will align with the IoT Cybersecurity Improvement Act of 2020 and industry best practices. 
  1. Waivers: Agencies can waive vulnerability disclosure requirements if the CIO determines it’s necessary for national security or research but must report the waiver to certain Congressional committees within 30 days. 
  1. Department of Defense (DoD): Within 180 days, the Secretary of Defense will review and revise DoD-specific regulations to ensure contractors follow the same vulnerability disclosure policies as outlined above. 

Contractors are Prime Targets 

A matter of days before the bill passed the House, several major cybersecurity and tech companies inked a letter urging the House and Senate to approve the legislation.   

“Contractors, given the vast amount of sensitive data they handle, are prime targets for cyber threats. As a result, the bill ensures all companies contracting with the federal government adhere to security best practices,” reads the letter signed by Bugcrowd, HackerOne, Microsoft, Rapid7, Trend Micro, and others.  

The letter also stated: “We are encouraged by the bipartisan support this legislation has received thus far, and we urge the House to swiftly pass it, with the Senate following suit. Strengthening cybersecurity is a strategic priority for this Administration to outpace and outmaneuver our adversaries. By implementing a simple and effective approach to identifying vulnerabilities, we can stay ahead of emerging threats and better protect critical systems.” 

A Mandatory Procurement Requirement 

“HR 872 transforms Vulnerability Disclosure Programs (VDPs) and the reception of hacker feedback from a “nice-to-have” into a mandatory FAR/DFAR procurement requirement,” says Casey Ellis, Founder at Bugcrowd. “Building on strong VDP adoption within the US Government through initiatives such as Hack the Pentagon and various congressional and DHS/OMB directives (including BOD 20-01), HR 872 joins the IoT Cybersecurity Act as one of the few directives leveraging procurement to ensure widespread VDP implementation.  

By making VDP a procurement requirement, HR 872 will accelerate the acceptance of hacker feedback within the U.S. Government and among the many contractors and vendors that support federal agencies, says Ellis.  

“This legislation mandates that all companies contracting with the federal government adhere to recognized security best practices, elevating the overall standard of cybersecurity across federal supply chains. HR 872 highlights the U.S. Government’s growing recognition of the essential role hackers and security researchers play in safeguarding cyberspace, legitimizing ethical hackers—likened to “locksmiths” rather than “burglars”—in their efforts to protect critical systems,” Ellis explains. “Bugcrowd is proud to have supported the creation of this Bill and to continue to support passage of this bill through the Senate and into law, both directly and through our work with the Hacking Policy Council.” 

Aligning Contractors with Industry Best Practices 

“Every company building or implementing technology and services needs a Vulnerability Disclosure Program (VDP), and this is a significant milestone in aligning Contractors with industry best practices,” says Trey Ford, Chief Information Security Officer at Bugcrowd. “Ultimately, the performance of a VDP is the best external proxy indicator for the performance of a company’s security program.” 

Ford says establishing a VDP is necessary to create a safe harbor for users and researchers to report security concerns in good faith – a challenge that still exists in US laws, and is of particular concern for researchers when interacting with governmental targets.  

Just One Risk Dimension 

Piyush Pandey, CEO at Pathlock, adds that while ensuring application vulnerability is managed effectively is important, it’s just one risk dimension and perhaps not the most important.  

“Over the last five years, driven by digital modernization, unauthorized Identity-related access to critical applications at the transaction level has introduced far more risk. In fact, public company filings from 2021 to 2023 report double-digit increases in both significant deficiencies and, more importantly, material weaknesses.” 

While managing vulnerabilities is required, controlling unauthorized Identity-related access to critical applications is also required to manage the most critical business risks today, Pandey says.  

The Advantages of Framework-driven Operations 

Ken Dunham, Cyber Threat Director at Qualys, says VDP guidelines are based on NIST SP 800-216 to help manage risk related to reporting security vulnerabilities in software and information systems owned or utilized by the Federal Government. NIST SP 800-216  defines the terminology, coordination, scope, triage, and prioritization of vulnerability information, the management of advisory information and public disclosure, and the relevant stakeholders. It also addresses how VDP offices (VDPO) are to be managed and run.   

“The intended outcome of VDPO oversight and use of this framework is to increase visibility and compliance for vulnerability management in the Federal Government. This bill is focused on operational components of how vulnerability information is managed and disclosed to ensure compliance and oversight,” Dunham adds.  

Framework-driven operations are more cost-effective and better at reducing risk compared to those that are not, Dunham continues. “They also increase visibility and introduce a layer of governance and management that is not possible without such a framework and iterative approach to processes and controls.” 

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    AI-Powered Attacks Become Top Concern for Security Professionals, New Filigran Survey Reveals
  • Kirsten Doyle
    ShinyHunters targets Oracle PeopleSoft customers through critical zero-day
  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt
  • Kirsten Doyle
    Miasma worm spreads from Red Hat packages to Microsoft repositories

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Rethinking the Security Estate: Why IT Spend Isn’t the Same as Cybersecurity Readiness

February 5, 20264 Mins Read

Have You Read the F***ing Policy?

December 2, 20254 Mins Read

UK insurers pay nearly £200m to help businesses recover from cyber attacks

November 12, 20252 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}