<?xml version="1.0" encoding="UTF-8"?><BillSummaries>
    <item congress="117" measure-type="hr" measure-number="3462" measure-id="id117hr3462" originChamber="HOUSE" orig-publish-date="2021-05-21" update-date="2023-01-04">
        <title>SBA Cyber Awareness Act</title>
        <summary summary-id="id117hr3462v49" currentChamber="BOTH" update-date="2023-01-04">
            <action-date>2022-12-21</action-date>
            <action-desc>Public Law</action-desc>
            <summary-text><![CDATA[
     <p><b>SBA Cyber Awareness Act</b></p> <p>This act requires the Small Business Administration (SBA) to annually report specified information related to cybersecurity awareness.</p> <p>Such reports must include (1) a strategy to increase the cybersecurity of the SBA's information technology (IT) infrastructure, (2) a supply chain risk management strategy that includes risk mitigation activities for IT components originating from an entity that has its principal place of business in China, and (3) any SBA cybersecurity incident that occurred during the two years prior to the initial report (including the SBA's action to respond to or remediate it).</p>
  ]]></summary-text>
        </summary>
        <summary summary-id="id117hr3462v59" currentChamber="HOUSE" update-date="2022-12-19">
            <action-date>2022-12-05</action-date>
            <action-desc>House agreed to Senate amendment</action-desc>
            <summary-text><![CDATA[
     <p><b>SBA Cyber Awareness Act</b></p> <p>This bill requires the Small Business Administration (SBA) to annually report specified information related to cybersecurity awareness.</p> <p>Such reports must include (1) a strategy to increase the cybersecurity of the SBA's information technology (IT) infrastructure, (2) a supply chain risk management strategy that includes risk mitigation activities for IT components originating from an entity that has its principal place of business in China, and (3) any SBA cybersecurity incident that occurred during the two years prior to the initial report (including the SBA's action to respond to or remediate it).</p>
  ]]></summary-text>
        </summary>
        <summary summary-id="id117hr3462v55" currentChamber="SENATE" update-date="2022-12-05">
            <action-date>2022-09-28</action-date>
            <action-desc>Passed Senate</action-desc>
            <summary-text><![CDATA[
     <p><b>SBA Cyber Awareness Act</b></p> <p>This bill requires the Small Business Administration (SBA) to annually report specified information related to cybersecurity awareness.</p> <p>Such reports must include (1) a strategy to increase the cybersecurity of the SBA's information technology (IT) infrastructure, (2) a supply chain risk management strategy that includes risk mitigation activities for IT components originating from an entity that has its principal place of business in China, and (3) any SBA cybersecurity incident that occurred during the two years prior to the initial report (including the SBA's action to respond to or remediate it).</p>
  ]]></summary-text>
        </summary>
        <summary summary-id="id117hr3462v25" currentChamber="SENATE" update-date="2022-02-28">
            <action-date>2022-02-17</action-date>
            <action-desc>Reported to Senate</action-desc>
            <summary-text><![CDATA[ <p><b>SBA Cyber Awareness Act</b></p> <p>This bill requires the Small Business Administration (SBA) to annually report specified information related to cybersecurity awareness.</p> <p>Such reports must provide (1) an assessment of the SBA's information technology (IT) and cybersecurity infrastructure, (2) a strategy to increase such infrastructure, (3) a detailed account of the SBA's IT equipment that is manufactured by an entity that has its principal place of business in China, and (4) any SBA cybersecurity risk or incident that occurred during the two years prior to the report (including the SBA's action to respond to or remediate it).</p>]]></summary-text>
        </summary>
        <summary summary-id="id117hr3462v53" currentChamber="HOUSE" update-date="2021-11-10">
            <action-date>2021-11-02</action-date>
            <action-desc>Passed House</action-desc>
            <summary-text><![CDATA[ <p><b>SBA Cyber Awareness Act</b></p> <p>This bill requires the Small Business Administration (SBA) to annually report specified information related to cybersecurity awareness.</p> <p>Such reports must provide (1) an assessment of the SBA's information technology (IT) and cybersecurity infrastructure, (2) a strategy to increase such infrastructure, (3) a detailed account of the SBA's IT equipment that is manufactured by an entity that has its principal place of business in China, and (4) any SBA cybersecurity risk or incident that occurred during the two years prior to the report (including the SBA's action to respond to or remediate it).</p>]]></summary-text>
        </summary>
        <summary summary-id="id117hr3462v07" currentChamber="HOUSE" update-date="2021-11-09">
            <action-date>2021-10-12</action-date>
            <action-desc>Reported to House</action-desc>
            <summary-text><![CDATA[ <p><b>SBA Cyber Awareness Act</b></p> <p>This bill requires the Small Business Administration (SBA) to annually report specified information related to cybersecurity awareness.</p> <p>Such reports must provide (1) an assessment of the SBA's information technology (IT) and cybersecurity infrastructure, (2) a strategy to increase such infrastructure, (3) a detailed account of the SBA's IT equipment that is manufactured by an entity that has its principal place of business in China, and (4) any SBA cybersecurity risk or incident that occurred during the two years prior to the report (including the SBA's action to respond to or remediate it).</p>]]></summary-text>
        </summary>
        <summary summary-id="id117hr3462v00" currentChamber="HOUSE" update-date="2021-11-05">
            <action-date>2021-05-21</action-date>
            <action-desc>Introduced in House</action-desc>
            <summary-text><![CDATA[ <p><b>SBA Cyber Awareness Act</b></p> <p>This bill requires the Small Business Administration (SBA) to annually report specified information related to cybersecurity awareness.</p> <p>Such reports must provide (1) an assessment of the SBA's information technology (IT) and cybersecurity infrastructure, (2) a strategy to increase such infrastructure, (3) a detailed account of the SBA's IT equipment that is manufactured by an entity that has its principal place of business in China, and (4) any SBA cybersecurity risk or incident that occurred during the two years prior to the report (including the SBA's action to respond to or remediate it).</p>]]></summary-text>
        </summary>
    </item>
    <dublinCore xmlns:dc="http://purl.org/dc/elements/1.1/">
        <dc:format>text/xml</dc:format>
        <dc:language>EN</dc:language>
        <dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
        <dc:contributor>Congressional Research Service, Library of Congress</dc:contributor>
        <dc:description>This file contains bill summaries for federal legislation. A bill summary describes the most significant provisions of a piece of legislation and details the effects the legislative text may have on current law and federal programs. Bill summaries are authored by the Congressional Research Service (CRS) of the Library of Congress. As stated in Public Law 91-510 (2 USC 166 (d)(6)), one of the duties of CRS is "to prepare summaries and digests of bills and resolutions of a public general nature introduced in the Senate or House of Representatives". For more information, refer to the User Guide that accompanies this file.</dc:description>
    </dublinCore>
</BillSummaries>
