Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

S.1899, the Federal Contractor Cybersecurity Vulnerability Reduction Act of 2025, is a proposal to add formal vulnerability-disclosure policy expectations to federal contracting—not a law currently in force. Congress.gov lists it as introduced and referred to the Senate Homeland Security and Governmental Affairs Committee, with no later action shown on the bill page reviewed. A separate June 2026 executive order has directed the Federal Acquisition Regulatory Council to prepare a proposed rule on contractor vulnerability-disclosure programs, but that action does not mean S.1899 passed.

What would S.1899 require?

The bill would establish a two-stage process to update the Federal Acquisition Regulation (FAR), the rules governing federal acquisitions. Its requirements would apply only after enactment, and the bill’s deadlines would begin when their specified triggering events occur.

  1. OMB would review existing requirements. Within 180 days after enactment, the Office of Management and Budget (OMB), consulting the Cybersecurity and Infrastructure Security Agency (CISA), the National Cyber Director, the National Institute of Standards and Technology (NIST), and other appropriate department heads, would review FAR contract requirements and language concerning contractor vulnerability-disclosure programs. OMB would recommend updates to the FAR Council. Read the introduced bill text.
  2. The FAR Council would consider amendments. Within 180 days after receiving OMB’s recommended language, the FAR Council would review it and amend the FAR as necessary to require covered contractors to solicit and address information about potential vulnerabilities in contractor-owned or contractor-controlled systems used to perform federal contracts.

The proposal does not itself spell out a final, complete set of operational rules for every contractor. The bill would start a review and rulemaking process; the eventual FAR language and subsequent implementation would determine the final scope, mechanics, and effective dates.

What standards and exceptions are in the proposal?

The proposed FAR updates should align, to the maximum extent practicable, with federal vulnerability-disclosure and coordinated-disclosure requirements for information systems under the IoT Cybersecurity Improvement Act. The text also points to industry best practices and ISO/IEC 29147 and ISO/IEC 30111, or other appropriate, relevant, widely used standards. The introduced text sets out these alignment provisions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

An agency could waive the proposed requirement if its chief information officer determines a waiver is necessary for national security or research purposes. The bill also makes the waiver subject to notice and justification requirements; it is not a general exemption with no stated basis.

What is the bill’s status?

Senator Mark Warner introduced S.1899 on May 22, 2025. That day, it was read twice and referred to the Senate Committee on Homeland Security and Governmental Affairs. Congress.gov labels it “Introduced,” and the summary on the page reviewed was still marked in progress. No later action was listed there. Check the Congress.gov bill record for its status and action history.

That status matters: S.1899’s proposed deadlines do not begin merely because the bill was introduced. They depend on enactment and, for the FAR Council’s deadline, receipt of OMB’s recommendations.

How does the 2026 executive order relate to S.1899?

A separate executive order signed June 22, 2026, titled “Securing the Nation Against Advanced Cryptographic Attacks,” directs the FAR Council, in consultation with CISA and NIST, to publish a proposed FAR rule within 270 days. The proposed rule is to amend contractor vulnerability-disclosure requirements so covered contractors implement VDPs consistent with NIST guidelines and include reports of cryptographic vulnerabilities. The order specifically calls for checks involving lack of encryption and non-FIPS-approved algorithms. Read the executive order.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This is a distinct rulemaking direction, not proof that S.1899 became law. The order sets a deadline to publish a proposed rule; it does not itself complete the FAR amendment. The two mechanisms differ in their legal vehicle, instructions, timing, and stated emphasis:

Question S.1899 June 2026 executive order
Legal vehicle and status Proposed legislation; Congress.gov lists it as introduced and referred to committee. Executive order directing the preparation and publication of a proposed FAR rule.
Who acts? OMB would review FAR requirements and recommend language; the FAR Council would review and amend the FAR as necessary. The FAR Council, consulting CISA and NIST, is directed to publish a proposed rule.
Timing OMB’s review is due within 180 days after enactment; the FAR Council’s review is due within 180 days after receiving recommendations. The proposed rule is due within 270 days under the order.
Stated focus Potential vulnerabilities in contractor-owned or contractor-controlled systems used in federal contract performance, with alignment to federal disclosure requirements and recognized standards. Contractor VDPs consistent with NIST guidelines, including cryptographic vulnerability reports and checks for lack of encryption and non-FIPS-approved algorithms.
What is established? The bill is pending at the status shown on Congress.gov; its proposed FAR changes are not current law. The order directs a proposed rule, not a completed FAR amendment.

How does S.1899 relate to earlier and companion bills?

S.1899 is not the same measure as S.5028, a predecessor introduced by Warner and Senator James Lankford in the 118th Congress. The Senate committee reported S.5028 in December 2024 after adopting a substitute amendment. The committee report described proposed OMB and FAR Council roles, standards alignment, waivers, and a Defense Department review. That history belongs to the earlier bill and should not be treated as the text or status of S.1899. See S.5028’s separate Congress.gov record.

There is also a House measure with separate legislative history: GPO version records show H.R.872 was engrossed in the House on March 3, 2025, then received in the Senate and referred to the Homeland Security and Governmental Affairs Committee on March 4. Those events do not change S.1899’s Senate status. See the GPO record for H.R.872.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why did the sponsors support the proposal?

In a Senate press release announcing the measure, Warner said, “Vulnerability Disclosure Policies are crucial tools to help ensure that the federal government is operating using safe cybersecurity practices.” Lankford said, “Federal agencies and contractors must be quickly made aware of cyber vulnerabilities, so they can resolve them.” These are the sponsors’ stated rationale, not a description of requirements already imposed on contractors by S.1899. Read the sponsors’ announcement.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.