Nonpartisan civic infrastructure
AllCiv·Legis1
·

S. 1899

BillFederalSenateIn Committee
Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025
About This Bill
Committee
Latest Action · May 22, 2025
Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
Congress
119th (2025–2027)
Introduced
May 22, 2025
Cosponsors (1)
0D 1R
View PDF ↗

Summary

Highlight any text to annotate
This bill requires the federal government to establish new rules that mandate federal contractors implement formal policies for disclosing security vulnerabilities in their computer systems, following standards set by the National Institute of Standards and Technology (NIST). The Office of Management and Budget has 180 days from the bill's enactment to recommend updates to federal contracting rules, and the Federal Acquisition Regulation Council has an additional 180 days to incorporate these requirements into procurement contracts. The new rules will apply to contractors on federal contracts worth at least the simplified acquisition threshold (currently $250,000) and those managing federal information systems. Agencies can request waivers from these requirements if they determine it's necessary for national security or research purposes, but must notify Congress within 30 days if they do so. The bill requires no new federal funding to implement.

Take Action

Your position
Add a comment
to comment on this bill.
Annotate the text
Highlight any passage on the Summary or Full Text tab to attach a note. Annotations appear on the Annotations tab.