Skip to content

Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025

In committee: it can still change before the session ends.

US S 1899 · Senate Bill · 119th Congress

Draft a letter
Stage
In committee
Started in
Senate
Sponsors
2
Latest action
May 22, 2025

What it does

The bill would require federal contractors to implement a vulnerability disclosure policy aligned with NIST guidelines, updating the Federal Acquisition Regulation (FAR) to mandate that covered contractors solicit and address security vulnerability information related to federal information systems they use or control. Covered contractors include those with contracts at or above the simplified acquisition threshold or those operating federal information systems on behalf of an agency. The bill allows agency heads to waive the requirement for national security or research purposes, provided they notify Congress within 30 days, and specifies that no additional funding is authorized for…

No official summary is available here. This one was written by AI from the bill’s text.

Read the full textRead it on the official site

Where it stands

  1. Introduced (Done)

    May 22, 2025

  2. Committee (Current step)

    In committee · May 22, 2025

  3. Floor (Not started)

  4. Law (Not started)

What moved

Loading recorded actions…

Who is involved

Sponsors

The lawmakers who put their names on it, lead sponsors first.

In the news

Reporting that may mention this subject. Possible matches are labeled.

Loading coverage…

Where it goes next

While a bill can still move, the questions are about people and money.

Work with this bill

Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025 | 52