- H.R. 10171August 27, 2026
- H.R. 10156August 27, 2026
- H.R. 10172August 27, 2026
- H.R. 10160August 27, 2026
- H.R. 10181August 27, 2026
- H.R. 10176August 27, 2026
- H.Res. 1496August 27, 2026
- H.R. 10164August 27, 2026
- H.R. 10170August 27, 2026
- H.Res. 1494August 27, 2026
- H.R. 10163August 27, 2026
- H.R. 10157August 27, 2026
- Administration
- Agriculture
- Agriculture, Nutrition, And Forestry
- Appropriations
- Armed Services
- Banking, Housing, And Urban Affairs
- Budget
- Commerce, Science, And Transportation
- Education and Workforce
- Energy And Commerce
- Energy And Natural Resources
- Environment And Public Works
- Ethics
- Finance
- Financial Services
- Foreign Affairs
- Foreign Relations
- Health, Education, Labor, And Pensions
- Homeland Security
- Homeland Security And Governmental Affa…
- Indian Affairs
- Indian and Insular Affairs
- Intelligence
- Judiciary
- Natural Resources
- Oversight And Government Reform
- Permanent Select Intelligence
- Rules
- Rules And Administration
- Science, Space, And Technology
- Select Intelligence
- Small Business
- Small Business And Entrepreneurship
- Subcommittee on Aviation
- Subcommittee on Border Security and Enf…
- Subcommittee on Coast Guard and Maritim…
- Subcommittee on Commodity Markets, Digi…
- Subcommittee on Conservation, Research,…
- Subcommittee on Counterterrorism and In…
- Subcommittee on Cybersecurity and Infra…
- Subcommittee on Disability Assistance a…
- Subcommittee on Economic Development, P…
- Subcommittee on Economic Opportunity
- Subcommittee on Emergency Management an…
- Subcommittee on Energy and Mineral Reso…
- Subcommittee on Federal Lands
- Subcommittee on Forestry and Horticultu…
- Subcommittee on General Farm Commoditie…
- Subcommittee on Health
- Subcommittee on Highways and Transit
- Subcommittee on Livestock, Dairy, and P…
- Subcommittee on Nutrition and Foreign A…
- Subcommittee on Oversight and Investiga…
- Subcommittee on Oversight, Investigatio…
- Subcommittee on Railroads, Pipelines, a…
- Subcommittee on Transportation and Mari…
- Subcommittee on Water Resources and Env…
- Subcommittee on Water, Wildlife and Fis…
- Transportation And Infrastructure
- Veterans' Affairs
- Ways And Means

S. 1899
U.S. Senate•In Senate Committee
Summary
S. 1899, the Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025, was introduced in the Senate on May 22, 2025 by Sen. Mark Warner (D) with 1 co-sponsor. It was referred to Homeland Security And Governmental Affairs, and last saw action on May 22, 2025: Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
Record
Text
S. 1899 has 1 co-sponsor.
sb1899/introduced-in-senate.txt119 S1899 IS: Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025U.S. Senate2025-05-22text/xmlENPursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.II 119th CONGRESS 1st Session S. 1899 IN THE SENATE OF THE UNITED STATES May 22, 2025 Mr. Warner introduced the following bill;which was read twice and referred to the Committee on Homeland Security and GovernmentalAffairs A BILLTo require Federal contractors to implement a vulnerability disclosurepolicy consistent with NIST guidelines, and for other purposes.1.Short titleThis Act may be cited as the Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025 .2.Federal contractor vulnerability disclosure policy(a)Recommendations(1)In generalNot later than 180 days after the date of the enactment of this Act, the Director of the Office of Management and Budget, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, the National Cyber Director, the Director of the National Institute of Standards and Technology, and any other appropriate head of an Executive department, shall—(A)review the Federal Acquisition Regulation (FAR) contract requirements and language for contractor vulnerability disclosure programs; and(B)recommend updates to such requirements and language to the Federal Acquisition Regulation Council.(2)ContentsThe recommendations required by paragraph (1) shall include updates to such requirements designed to ensure that covered contractors implement a vulnerability disclosure policy consistent with National Institute of Standards and Technology (NIST) guidelines for contractors as required under section 5 of the IoT Cybersecurity Improvement Act of 2020 ( 15 U.S.C. 278g–3c ).(b)Procurement requirementsNot later than 180 days after the date on which the recommended contract language developed pursuant to subsection (a) is received, the Federal Acquisition Regulation Council shall review the recommended contract language and amend the FAR as necessary to incorporate requirements for covered contractors to solicit and address information about potential security vulnerabilities relating to an information system owned or controlled by the contractor that is used in performance of a Federal contract.(c)ElementsThe update to the FAR pursuant to subsection (b) shall—(1)to the maximum extent practicable, align with the security vulnerability disclosure process and coordinated disclosure requirements relating to Federal information systems under sections 5 and 6 of the IoT Cybersecurity Improvement Act of 2020 (15 U.S.C. 278g–3c, 278g–3d); and(2)to the maximum extent practicable, be aligned with industry best practices and Standards 29147 and 30111 of the International Standards Organization (or any successor standard) or any other appropriate, relevant, and widely used standard.(d)WaiverThe head of an agency may waive the security vulnerability disclosure policy requirement under subsection (b) if the agency Chief Information Officer—(1)determines that the waiver is necessary in the interest of national security or research purposes; and(2)not later than 30 days after granting the waiver, submits a notification and justification, including information about the duration of the waiver, to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Oversight and Reform of the House of Representatives.(e)DefinitionsIn this section:(1)AgencyThe term agency has the meaning given the term in section 3502 of title 44, United States Code.(2)Covered contractorThe term covered contractor means a contractor (as defined in section 7101 of title 41, United States Code)—(A)whose contract is in an amount the same as or greater than the simplified acquisition threshold; or(B)that uses, operates, manages, or maintains a Federal information system (as defined by section 11331 of title 40, United Stated Code) on behalf of an agency.(3)Executive departmentThe term Executive department has the meaning given that term in section 101 of title 5, United States Code.(4)Security vulnerabilityThe term security vulnerability has the meaning given that term in section 2200 of the Homeland Security Act of 2002 ( 6 U.S.C. 650 ).(5)Simplified acquisition thresholdThe term simplified acquisition threshold has the meaning given that term in section 134 of title 41, United States Code.3.No additional fundingNo additional funds are authorized to be appropriated for the purpose of carrying out this Act.
Tracker
The tracker indicates the progress of this legislation as it moves through the legislative process.
- Introduced2025-05-22
- Passed Senate
- Passed House
- Conference
- To President
- Became Law
A bill to require Federal contractors to implement a vulnerability disclosure policy consistent with NIST guidelines, and for other purposes.
Sponsors
Sen. Mark Warner (D) sponsors S. 1899, and 1 member has co-sponsored it.
Committees
S. 1899 went before 1 committee: Homeland Security and Governmental Affairs.

Actions
S. 1899 has taken 2 actions since May 22, 2025.
| Chamber | Action | |||
|---|---|---|---|---|
May 22, 2025 | Senate | Read twice and referred to the Committee on Homeland Security and Governmental Affairs.Homeland Security and Governmental Affairs Committee | ||
May 22, 2025 | — | Introduced in Senate |
Votes
S. 1899 has not gone to a roll call.
Titles
S. 1899 goes by 3 titles, 1 of them short titles.
- Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025 — Display Title
- Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025 — Short Title(s) as Introduced
- A bill to require Federal contractors to implement a vulnerability disclosure policy consistent with NIST guidelines, and for other purposes. — Official Title as Introduced
Lobbying
2 clients hired 2 firms and 101 registered lobbyists who named S. 1899 in 5 quarterly filings, 2025 to 2026. Reported under the Lobbying Disclosure Act; a filing’s income covers everything its registrant worked that quarter, so the amounts below are the filings’, not this bill’s.
Filed under Aviation/Airlines/Airports, Aerospace, Automotive Industry, Banking, Budget/Appropriations, Civil Rights/Civil Liberties, Copyright/Patent/Trademark, Defense.
Clients
Who paid to be heard, by how many filings named the bill.
| Client | Business | State | Firms | Filings | Reported |
|---|---|---|---|---|---|
| AIR TRANSPORT ASSOCIATION OF AMERICA, INC. (D/B/A AIRLINES FOR AMERICA) | — | District of Columbia | 1 | 3 | — |
| CHAMBER OF COMMERCE OF THE U.S.A. | — | District of Columbia | 1 | 2 | — |
Firms
Registrants who filed on the bill, by filings.
| Registrant | Clients | Filings | Reported |
|---|---|---|---|
| AIR TRANSPORT ASSOCIATION OF AMERICA, INC. (D/B/A AIRLINES FOR AMERICA) | 1 | 3 | — |
| CHAMBER OF COMMERCE OF THE U.S.A. | 1 | 2 | — |
Lobbyists
Named on the filings that cite the bill. The 20 named most often, of 101.
| Lobbyist | Firms | Clients | Filings |
|---|---|---|---|
| JARROD THOMPSON | 1 | 1 | 3 |
| JOSHUA SALTZMAN | 1 | 1 | 3 |
| SHARON PINKERTON | 1 | 1 | 3 |
| ABELARDO TORRES | 1 | 1 | 2 |
| ALEXA BRANSON | 1 | 1 | 2 |
| AMANDA MAYS | 1 | 1 | 2 |
| ANDREA PORWOLL | 1 | 1 | 2 |
| ASHLEY GUM | 1 | 1 | 2 |
| BRADLEY WATTS | 1 | 1 | 2 |
| BRINCE MANNING | 1 | 1 | 2 |
| BROOKE MILLER | 1 | 1 | 2 |
| CASSIA CARVALHO | 1 | 1 | 2 |
| CHAD WHITEMAN | 1 | 1 | 2 |
| CHANTEL SHEAKS | 1 | 1 | 2 |
| CHRISTOPHER CRENSHAW | 1 | 1 | 2 |
| CHRISTOPHER EYLER | 1 | 1 | 2 |
| CHRISTOPHER GUITH | 1 | 1 | 2 |
| CHRISTOPHER ROBERTI | 1 | 1 | 2 |
| CLARK JACKSON | 1 | 1 | 2 |
| DAN BYERS | 1 | 1 | 2 |
Filings
The documents themselves, on the Senate’s Lobbying Disclosure site, largest reported first.
| Client | Registrant | Period | Reported | Document |
|---|---|---|---|---|
| CHAMBER OF COMMERCE OF THE U.S.A. | CHAMBER OF COMMERCE OF THE U.S.A. | 2025 fourth_quarter | $18M | 4th Quarter - Report |
| CHAMBER OF COMMERCE OF THE U.S.A. | CHAMBER OF COMMERCE OF THE U.S.A. | 2025 third_quarter | $13.7M | 3rd Quarter - Report |
| AIR TRANSPORT ASSOCIATION OF AMERICA, INC. (D/B/A AIRLINES FOR AMERICA) | AIR TRANSPORT ASSOCIATION OF AMERICA, INC. (D/B/A AIRLINES FOR AMERICA) | 2025 fourth_quarter | $1.2M | 4th Quarter - Report |
| AIR TRANSPORT ASSOCIATION OF AMERICA, INC. (D/B/A AIRLINES FOR AMERICA) | AIR TRANSPORT ASSOCIATION OF AMERICA, INC. (D/B/A AIRLINES FOR AMERICA) | 2026 second_quarter | $1.1M | 2nd Quarter - Report |
| AIR TRANSPORT ASSOCIATION OF AMERICA, INC. (D/B/A AIRLINES FOR AMERICA) | AIR TRANSPORT ASSOCIATION OF AMERICA, INC. (D/B/A AIRLINES FOR AMERICA) | 2026 first_quarter | $1M | 1st Quarter - Report |
Classification
The Congressional Research Service files S. 1899 under Science, Technology, Communications, one of its 31 policy areas.
CRS Subjects
CRS assigns every bill one policy area from its 31; S. 1899’s is Science, Technology, Communications.
s1899/policy-areas.txtSource: congress.gov · legiscan.com