Skip to main content
CivicGate

S 1899
Introduced Re-checks Congress.gov for new actions and updates the bill's status, and fills in any sponsors, committees, or related bills that are missing. It does not re-pull sponsors/cosponsors/committees/related — those rarely change — and it skips all work if nothing has changed upstream, so it's cheap to click.

Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025

To require Federal contractors to implement a vulnerability disclosure policy consistent with NIST guidelines, and for other purposes.

Introduced May 22, 2025

Latest action (May 22, 2025) Read twice and referred to the Committee on Homeland Security and Governmental Affairs.

Summary

This bill requires the Office of Management and Budget to review and update Federal Acquisition Regulation (FAR) requirements to ensure federal contractors implement security vulnerability disclosure policies consistent with National Institute of Standards and Technology guidelines. Within 180 days of enactment, OMB must recommend updates to FAR contract language, and the FAR Council must incorporate requirements for covered contractors to identify and address security vulnerabilities in systems used for federal work. The vulnerability disclosure requirements should align with federal standards under the IoT Cybersecurity Improvement Act and industry best practices including ISO standards. Agency Chief Information Officers may waive the requirement for national security or research purposes with Congressional notification. No additional funding is authorized.

AI-generated plain-language summary of the bill text — neutral, and may be imperfect. See the full text below for the exact wording.

Sponsor (1)

Actions (2)

  1. May 22, 2025 Read twice and referred to the Committee on Homeland Security and Governmental Affairs. · senate
  2. May 22, 2025 Introduced in Senate

Similar bills (6)

Bills with similar text or summary — includes reintroductions across Congresses. Ranked by semantic similarity of the bill text (computed locally); a neutral discovery aid, not a claim the bills are duplicates.

Full text

IN THE SENATE OF THE UNITED STATES

May 22, 2025

Mr. Warner introduced the following bill; which was read twice and referred to the Committee on Homeland Security and Governmental Affairs

A BILL

To require Federal contractors to implement a vulnerability disclosure policy consistent with NIST guidelines, and for other purposes.

Be it enacted by the Senate and House of Representatives of the United States of America in Congress assembled,

SECTION 1. SHORT TITLE.

This Act may be cited as the “Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025”.

SEC. 2. FEDERAL CONTRACTOR VULNERABILITY DISCLOSURE POLICY.

(a) Recommendations.—

(1) In general.—Not later than 180 days after the date of the enactment of this Act, the Director of the Office of Management and Budget, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, the National Cyber Director, the Director of the National Institute of Standards and Technology, and any other appropriate head of an Executive department, shall—

(A) review the Federal Acquisition Regulation (FAR) contract requirements and language for contractor vulnerability disclosure programs; and

(B) recommend updates to such requirements and language to the Federal Acquisition Regulation Council.

(2) Contents.—The recommendations required by paragraph

(1) shall include updates to such requirements designed to ensure that covered contractors implement a vulnerability disclosure policy consistent with National Institute of Standards and Technology (NIST) guidelines for contractors as required under section 5 of the IoT Cybersecurity Improvement Act of 2020 (15 U.S.C. 278g-3c).

(b) Procurement Requirements.—Not later than 180 days after the date on which the recommended contract language developed pursuant to subsection (a) is received, the Federal Acquisition Regulation Council shall review the recommended contract language and amend the FAR as necessary to incorporate requirements for covered contractors to solicit and address information about potential security vulnerabilities relating to an information system owned or controlled by the contractor that is used in performance of a Federal contract.

(c) Elements.—The update to the FAR pursuant to subsection (b) shall—

(1) to the maximum extent practicable, align with the security vulnerability disclosure process and coordinated disclosure requirements relating to Federal information systems under sections 5 and 6 of the IoT Cybersecurity Improvement Act of 2020 (15 U.S.C. 278g-3c, 278g-3d); and

(2) to the maximum extent practicable, be aligned with industry best practices and Standards 29147 and 30111 of the International Standards Organization (or any successor standard) or any other appropriate, relevant, and widely used standard.

(d) Waiver.—The head of an agency may waive the security vulnerability disclosure policy requirement under subsection (b) if the agency Chief Information Officer—

(1) determines that the waiver is necessary in the interest of national security or research purposes; and

(2) not later than 30 days after granting the waiver, submits a notification and justification, including information about the duration of the waiver, to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Oversight and Reform of the House of Representatives.

(e) Definitions.—In this section:

(1) Agency.—The term “agency” has the meaning given the term in section 3502 of title 44, United States Code.

(2) Covered contractor.—The term “covered contractor” means a contractor (as defined in section 7101 of title 41, United States Code)—

(A) whose contract is in an amount the same as or greater than the simplified acquisition threshold; or

(B) that uses, operates, manages, or maintains a Federal information system (as defined by section 11331 of title 40, United Stated Code) on behalf of an agency.

(3) Executive department.—The term “Executive department” has the meaning given that term in section 101 of title 5, United States Code.

(4) Security vulnerability.—The term “security vulnerability” has the meaning given that term in section 2200 of the Homeland Security Act of 2002 (6 U.S.C. 650).

(5) Simplified acquisition threshold.—The term “simplified acquisition threshold” has the meaning given that term in section 134 of title 41, United States Code.

SEC. 3. NO ADDITIONAL FUNDING.

No additional funds are authorized to be appropriated for the purpose of carrying out this Act. <all>

Comments

Comments

Loading comments…