Search

Search bills, members, committees and pages...

S. 1899

U.S. SenateIn Senate Committee

Summary

S. 1899, the Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025, was introduced in the Senate on May 22, 2025 by Sen. Mark Warner (D) with 1 co-sponsor. It was referred to Homeland Security And Governmental Affairs, and last saw action on May 22, 2025: Read twice and referred to the Committee on Homeland Security and Governmental Affairs.


Record

Text

S. 1899 has 1 co-sponsor.

sb1899/introduced-in-senate.txt
119 S1899 IS: Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025
U.S. Senate
2025-05-22
text/xml
EN
Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.
II 119th CONGRESS 1st Session S. 1899 IN THE SENATE OF THE UNITED STATES May 22, 2025 Mr. Warner introduced the following bill;
which was read twice and referred to the Committee on Homeland Security and Governmental
Affairs A BILL
To require Federal contractors to implement a vulnerability disclosure
policy consistent with NIST guidelines, and for other purposes.
1.
Short title
This Act may be cited as the Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025 .
2.
Federal contractor vulnerability disclosure policy
(a)
Recommendations
(1)
In general
Not later than 180 days after the date of the enactment of this Act, the Director of the Office of Management and Budget, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, the National Cyber Director, the Director of the National Institute of Standards and Technology, and any other appropriate head of an Executive department, shall—
(A)
review the Federal Acquisition Regulation (FAR) contract requirements and language for contractor vulnerability disclosure programs; and
(B)
recommend updates to such requirements and language to the Federal Acquisition Regulation Council.
(2)
Contents
The recommendations required by paragraph (1) shall include updates to such requirements designed to ensure that covered contractors implement a vulnerability disclosure policy consistent with National Institute of Standards and Technology (NIST) guidelines for contractors as required under section 5 of the IoT Cybersecurity Improvement Act of 2020 ( 15 U.S.C. 278g–3c ).
(b)
Procurement requirements
Not later than 180 days after the date on which the recommended contract language developed pursuant to subsection (a) is received, the Federal Acquisition Regulation Council shall review the recommended contract language and amend the FAR as necessary to incorporate requirements for covered contractors to solicit and address information about potential security vulnerabilities relating to an information system owned or controlled by the contractor that is used in performance of a Federal contract.
(c)
Elements
The update to the FAR pursuant to subsection (b) shall—
(1)
to the maximum extent practicable, align with the security vulnerability disclosure process and coordinated disclosure requirements relating to Federal information systems under sections 5 and 6 of the IoT Cybersecurity Improvement Act of 2020 (15 U.S.C. 278g–3c, 278g–3d); and
(2)
to the maximum extent practicable, be aligned with industry best practices and Standards 29147 and 30111 of the International Standards Organization (or any successor standard) or any other appropriate, relevant, and widely used standard.
(d)
Waiver
The head of an agency may waive the security vulnerability disclosure policy requirement under subsection (b) if the agency Chief Information Officer—
(1)
determines that the waiver is necessary in the interest of national security or research purposes; and
(2)
not later than 30 days after granting the waiver, submits a notification and justification, including information about the duration of the waiver, to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Oversight and Reform of the House of Representatives.
(e)
Definitions
In this section:
(1)
Agency
The term agency has the meaning given the term in section 3502 of title 44, United States Code.
(2)
Covered contractor
The term covered contractor means a contractor (as defined in section 7101 of title 41, United States Code)—
(A)
whose contract is in an amount the same as or greater than the simplified acquisition threshold; or
(B)
that uses, operates, manages, or maintains a Federal information system (as defined by section 11331 of title 40, United Stated Code) on behalf of an agency.
(3)
Executive department
The term Executive department has the meaning given that term in section 101 of title 5, United States Code.
(4)
Security vulnerability
The term security vulnerability has the meaning given that term in section 2200 of the Homeland Security Act of 2002 ( 6 U.S.C. 650 ).
(5)
Simplified acquisition threshold
The term simplified acquisition threshold has the meaning given that term in section 134 of title 41, United States Code.
3.
No additional funding
No additional funds are authorized to be appropriated for the purpose of carrying out this Act.

Tracker

The tracker indicates the progress of this legislation as it moves through the legislative process.

  1. Introduced2025-05-22
  2. Passed Senate
  3. Passed House
  4. Conference
  5. To President
  6. Became Law

A bill to require Federal contractors to implement a vulnerability disclosure policy consistent with NIST guidelines, and for other purposes.

Sponsors

Sen. Mark Warner (D) sponsors S. 1899, and 1 member has co-sponsored it.

Committees

S. 1899 went before 1 committee: Homeland Security and Governmental Affairs.

Homeland Security and Governmental Affairs
Homeland Security and Governmental Affairs
Referred To · May 22, 2025 · 444 Bills

Actions

S. 1899 has taken 2 actions since May 22, 2025.

ChamberAction
May 22, 2025
Senate
Read twice and referred to the Committee on Homeland Security and Governmental Affairs.Homeland Security and Governmental Affairs Committee
May 22, 2025
Introduced in Senate

Votes

S. 1899 has not gone to a roll call.

Titles

S. 1899 goes by 3 titles, 1 of them short titles.

  • Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025 — Display Title
  • Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025 — Short Title(s) as Introduced
  • A bill to require Federal contractors to implement a vulnerability disclosure policy consistent with NIST guidelines, and for other purposes. — Official Title as Introduced

Lobbying

2 clients hired 2 firms and 101 registered lobbyists who named S. 1899 in 5 quarterly filings, 2025 to 2026. Reported under the Lobbying Disclosure Act; a filing’s income covers everything its registrant worked that quarter, so the amounts below are the filings’, not this bill’s.

Filed under Aviation/Airlines/Airports, Aerospace, Automotive Industry, Banking, Budget/Appropriations, Civil Rights/Civil Liberties, Copyright/Patent/Trademark, Defense.

Clients

Who paid to be heard, by how many filings named the bill.

ClientBusinessStateFirmsFilingsReported
AIR TRANSPORT ASSOCIATION OF AMERICA, INC. (D/B/A AIRLINES FOR AMERICA)District of Columbia13
CHAMBER OF COMMERCE OF THE U.S.A.District of Columbia12

Firms

Registrants who filed on the bill, by filings.

Lobbyists

Named on the filings that cite the bill. The 20 named most often, of 101.

Filings

The documents themselves, on the Senate’s Lobbying Disclosure site, largest reported first.

ClientRegistrantPeriodReportedDocument
CHAMBER OF COMMERCE OF THE U.S.A.CHAMBER OF COMMERCE OF THE U.S.A.2025 fourth_quarter$18M4th Quarter - Report
CHAMBER OF COMMERCE OF THE U.S.A.CHAMBER OF COMMERCE OF THE U.S.A.2025 third_quarter$13.7M3rd Quarter - Report
AIR TRANSPORT ASSOCIATION OF AMERICA, INC. (D/B/A AIRLINES FOR AMERICA)AIR TRANSPORT ASSOCIATION OF AMERICA, INC. (D/B/A AIRLINES FOR AMERICA)2025 fourth_quarter$1.2M4th Quarter - Report
AIR TRANSPORT ASSOCIATION OF AMERICA, INC. (D/B/A AIRLINES FOR AMERICA)AIR TRANSPORT ASSOCIATION OF AMERICA, INC. (D/B/A AIRLINES FOR AMERICA)2026 second_quarter$1.1M2nd Quarter - Report
AIR TRANSPORT ASSOCIATION OF AMERICA, INC. (D/B/A AIRLINES FOR AMERICA)AIR TRANSPORT ASSOCIATION OF AMERICA, INC. (D/B/A AIRLINES FOR AMERICA)2026 first_quarter$1M1st Quarter - Report

Classification

The Congressional Research Service files S. 1899 under Science, Technology, Communications, one of its 31 policy areas.

CRS Subjects

CRS assigns every bill one policy area from its 31; S. 1899’s is Science, Technology, Communications.

s1899/policy-areas.txt
Science, Technology, CommunicationsAgriculture and FoodAnimalsArmed Forces and National SecurityArts, Culture, ReligionCivil Rights and Liberties, Minority IssuesCommerceCongressCrime and Law EnforcementEconomics and Public FinanceEducationEmergency ManagementEnergyEnvironmental ProtectionFamiliesFinance and Financial SectorForeign Trade and International FinanceGovernment Operations and PoliticsHealthHousing and Community DevelopmentImmigrationInternational AffairsLabor and EmploymentLawNative AmericansPublic Lands and Natural ResourcesSocial WelfareSports and RecreationTaxationTransportation and Public WorksWater Resources Development

Source: congress.gov · legiscan.com