HR-872-119
Received in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
Sponsored by Nancy Mace (R-SC)
What it does
This bill would require the Office of Management and Budget, in consultation with cybersecurity agencies, to review and recommend updates to Federal Acquisition Regulation (FAR) contract language within 180 days, ensuring that covered federal contractors implement vulnerability disclosure policies consistent with NIST guidelines. The Federal Acquisition Regulation Council would then have 180 days to update the FAR to incorporate those requirements. The bill also directs the Department of Defense to make parallel updates to its own procurement supplement (DFARS), and allows agency heads to waive requirements for national security or research purposes with congressional notification.
Who benefits
Federal agencies and the broader public, who would gain greater assurance that contractors handling government information systems have processes to identify and report security vulnerabilities. Cybersecurity firms and researchers who participate in coordinated vulnerability disclosure programs, as standardized policies create clearer channels for reporting. Taxpayers broadly, if reduced contractor vulnerabilities lower the cost and frequency of federal data breaches. Smaller contractors who currently lack formal disclosure programs may benefit from clear, standardized guidance rather than ad hoc agency requirements.
Who is hurt
Federal contractors — particularly small and mid-sized businesses — that would face new compliance costs to develop, implement, and maintain formal vulnerability disclosure programs. Contractors operating near the simplified acquisition threshold may face disproportionate administrative burdens relative to contract value. Defense contractors subject to DFARS updates would face a second, parallel compliance track. Contractors in niche or classified sectors may face uncertainty during the waiver process. Agencies themselves would bear administrative costs to review, update, and enforce new contract language.
Supporters argue
Supporters argue that federal contractors represent a significant and underregulated attack surface for adversaries targeting government systems — a vulnerability demonstrated by breaches such as the 2020 SolarWinds supply chain attack, which compromised multiple federal agencies through a private contractor. They contend that aligning contractor disclosure requirements with established NIST guidelines and ISO standards 29147 and 30111 imposes minimal new burden while closing a documented gap, since the IoT Cybersecurity Improvement Act of 2020 already established similar requirements for federal agencies themselves but left contractors without equivalent obligations.
Opponents argue
Opponents argue that adding another layer of procurement mandates increases compliance costs and contract complexity, particularly for small businesses that may lack dedicated cybersecurity staff to implement and maintain formal disclosure programs — potentially reducing competition for federal contracts. They contend that the bill's reliance on OMB recommendations and FAR Council rulemaking introduces significant implementation delays and agency discretion, and that post-Loper Bright, courts will independently scrutinize whether the resulting agency rules stay within the bill's statutory boundaries, creating legal uncertainty for contractors who invest in compliance infrastructure.
Constitutional context
The bill operates within Congress's broad authority to set conditions on federal procurement contracts, which is well-established and does not raise significant Commerce Clause questions. However, the bill's delegation of rulemaking authority to OMB and the FAR Council — with relatively open-ended direction to align with "industry best practices" and "appropriate" standards — could face scrutiny under the post-Loper Bright framework, where courts independently assess whether agency rules stay within statutory authorization rather than deferring to agency interpretation.
Checks and balances
The Executive Branch (OMB, CISA, FAR Council, and DoD) gains rulemaking authority to set contractor cybersecurity standards; Congress retains oversight through required notifications of any waivers to the House Oversight and Senate Homeland Security committees, and through its appropriations and confirmation powers over the relevant agencies.
Historical precedent
The IoT Cybersecurity Improvement Act of 2020 established analogous NIST-aligned vulnerability disclosure requirements for federal agencies' own information systems, and the Federal Acquisition Security Council has previously updated FAR provisions to address supply chain cybersecurity risks.