Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025
This bill requires federal contractors with large contracts (over $250,000) or those managing government information systems to implement standardized processes for reporting security flaws. It directs federal agencies to update procurement rules to mandate these vulnerability disclosure policies, aligning with existing NIST cybersecurity guidelines and international standards like ISO 29147. Contractors must address potential security issues in systems used for government work, with limited waivers allowed only for national security reasons and requiring congressional notification. The policy applies directly to major federal contractors handling sensitive government data or systems. The bill does not authorize new funding for implementation.
Bill status
in committee
1 of 4 stages cleared
Introduction
May 2025
Committee Review
Floor Vote
President
Introduced May 22, 2025
Last action May 22, 2025
Floor votes
How they voted
No floor votes recorded yet.
Full legislative history
Actions timeline
Total actions
2
Key actions
0
Committee
1
May 22, 2025
Committee
Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
upper
May 22, 2025
Introduced
Introduced in Senate
upper
1 primary · 1 co-sponsor
Sponsors
Ask Maddy
·
AI policy assistant
Ask Maddy about S 1899
Scope: US
Hi! I can help you understand S 1899. What would you like to know?
Try one of these
i
Maddy answers using official bill text and legislative records. Always verify before sharing.
Sources cited inline