Federal contractors must now disclose security flaws—quietly.
S. 1899 — Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025 · Filed by Mark Warner (D-VA) · 1 cosponsor · Introduced May 22, 2025 · Referred to committee
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This bill requires the federal government to update its contractor rules so that companies working on federal contracts must have policies for reporting and fixing cybersecurity vulnerabilities in their systems. Within 180 days, the Office of Management and Budget must recommend updates to federal contracting rules; within another 180 days, those rules must be formally adopted. Contractors above a certain contract size or those managing federal computer systems must follow these vulnerability-disclosure standards, aligned with existing government and international best practices, though agencies can waive the requirement for national security reasons.
Why we flagged it
The bill's core function is to mandate vulnerability-disclosure policies in federal contractor agreements. It is a procurement and cybersecurity governance measure, not a subsidy, deregulation, or commemorative act.
What the text implies
- Contractors may face increased compliance costs (audits, disclosure processes, remediation) that could be passed to the government through higher contract bids, indirectly raising federal spending.
- The 180-day timeline for OMB recommendations and FAR updates is aggressive; delays or incomplete implementation could leave gaps in contractor cybersecurity oversight.
The full analysis lists 4 implications of this text.
Who stands to gain
cybersecurity consulting firms; IT compliance and audit service providers; software vendors specializing in vulnerability management