Bill

Bill > S1899


US S1899

US S1899
Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025


summary

Introduced
05/22/2025
In Committee
05/22/2025
Crossed Over
Passed
Dead

Introduced Session

119th Congress

Bill Summary

A bill to require Federal contractors to implement a vulnerability disclosure policy consistent with NIST guidelines, and for other purposes.

AI Summary

This bill aims to improve cybersecurity practices for federal contractors by requiring them to implement vulnerability disclosure policies aligned with National Institute of Standards and Technology (NIST) guidelines. Specifically, within 180 days of enactment, the Office of Management and Budget, in consultation with key cybersecurity agencies, must review and recommend updates to the Federal Acquisition Regulation (FAR) contract requirements. These recommendations will ensure that covered contractors, defined as those with contracts at or above the simplified acquisition threshold or those managing federal information systems, have a standardized process for identifying and addressing potential security vulnerabilities. The Federal Acquisition Regulation Council will then update contract language to require contractors to actively solicit and address security vulnerabilities, aligning with industry best practices and international standards. The bill allows agency heads to waive these requirements for national security or research purposes, but they must notify congressional committees within 30 days of doing so. Importantly, the bill does not authorize additional funding for its implementation, meaning agencies must absorb the costs within existing budgets.

Committee Categories

Military Affairs and Security

Sponsors (2)

Last Action

Read twice and referred to the Committee on Homeland Security and Governmental Affairs. (on 05/22/2025)

bill text


bill summary

Loading...

bill summary

Loading...
Loading...