Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025
In committee: it can still change before the session ends.
- Stage
- In committee
- Started in
- Senate
- Sponsors
- 2
- Latest action
- May 22, 2025
What it does
The bill would require federal contractors to implement a vulnerability disclosure policy aligned with NIST guidelines, updating the Federal Acquisition Regulation (FAR) to mandate that covered contractors solicit and address security vulnerability information related to federal information systems they use or control. Covered contractors include those with contracts at or above the simplified acquisition threshold or those operating federal information systems on behalf of an agency. The bill allows agency heads to waive the requirement for national security or research purposes, provided they notify Congress within 30 days, and specifies that no additional funding is authorized for…
No official summary is available here. This one was written by AI from the bill’s text.
Where it stands
Introduced (Done)
Committee (Current step)
Floor (Not started)
Law (Not started)
What moved
Who is involved
Sponsors
The lawmakers who put their names on it, lead sponsors first.
In the news
Reporting that may mention this subject. Possible matches are labeled.
Loading coverage…
Where it goes next
While a bill can still move, the questions are about people and money.