The bill standardizes coordinated vulnerability disclosure for government contractors—likely improving patching and transparency—while imposing compliance costs and potential market effects on contractors and leaving some security gaps via approved waivers.
Government contractors will be required to accept and process reports of security vulnerabilities, increasing the chance contractor-controlled systems are patched faster and reducing risk to systems used by the public and government.
Aligning contractor policies with NIST, IoT Act sections, and ISO standards creates consistent, widely accepted procedures for coordinated vulnerability disclosure across federal contracts.
Establishes a waiver process with required congressional notification, preserving flexibility for legitimate national security or research needs while adding transparency around exceptions.
Contractors will incur increased compliance costs to build and operate disclosure programs, which could raise the price of government contracts or administrative burdens borne by taxpayers.
Tighter contractor obligations could deter some suppliers—particularly small vendors—from bidding on federal contracts or increase contracting complexity for small businesses.
Permitting waivers for national security or research purposes could leave some systems without standardized disclosure processes, reducing the security benefits for those contracts and leaving residual risks to taxpayers.
Based on analysis of 2 sections of legislative text.
Requires FAR/DFARS updates so covered federal contractors must accept and handle reports of security vulnerabilities in contractor-controlled systems, aligned with IoT Act guidance and ISO standards.
Official title: To require covered contractors implement a vulnerability disclosure policy consistent with NIST guidelines, and for other purposes.
Introduced January 31, 2025 by Nancy Mace · Last progress March 4, 2025
Requires the Office of Management and Budget (OMB), working with CISA, NIST, the National Cyber Director, and others, to review and propose updates to Federal Acquisition Regulation (FAR) language so covered federal contractors must accept and handle reports of security vulnerabilities in contractor-controlled information systems used to perform federal contracts. The FAR Council must then revise the FAR to adopt that language within set timelines; the Department of Defense must make parallel DFARS changes. Agencies and the DoD CIO may grant limited waivers for national security or research reasons with required congressional notification.