<?xml version="1.0" encoding="UTF-8" standalone="no"?><?xml-stylesheet type="text/css" href="uslm.css"?><pLaw xmlns="http://schemas.gpo.gov/xml/uslm" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xml:lang="en" xsi:schemaLocation="http://schemas.gpo.gov/xml/uslm https://www.govinfo.gov/schemas/xml/uslm/uslm-2.0.17.xsd">

<?I97 136 STAT. ?>
<?I98 136 STAT. ?>
<?I99 136 STAT. ?>
<?I50 PUBLIC LAW 117–259—DEC. 21, 2022?>
<?I51 PUBLIC LAW 117–259—DEC. 21, 2022?>
<?I52 PUBLIC LAW 117–259—DEC. 21, 2022?>


<!--Disclaimer: Legislative measures that include compacts or other non-standard data structures will require additional modeling and may contain inconsistencies in the converted USLM XML.-->
<meta><dc:title>Public Law 117–259: To require an annual report on the cybersecurity of the Small Business Administration, and for other purposes.</dc:title>
<dc:type>Public Law</dc:type><docNumber>259</docNumber>
<citableAs>Public Law 117–259</citableAs><citableAs>136 Stat. 2387</citableAs>
<approvedDate>2022-12-21</approvedDate>
<dc:date>2022-12-21</dc:date>
<dc:publisher>United States Government Publishing Office</dc:publisher><dc:creator>National Archives and Records Administration</dc:creator><dc:creator>Office of the Federal Register</dc:creator><dc:format>text/xml</dc:format><dc:language>EN</dc:language><dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
<processedBy>GPO Locator to USLM Converter 4.15.31;Stage2.20250702</processedBy><processedDate>2026-01-02</processedDate>
<congress>117</congress><publicPrivate>public</publicPrivate>
</meta>
<preface><centerRunningHead>PUBLIC LAW 117–259—DEC. 21, 2022</centerRunningHead>
<page identifier="/us/stat/136/2387">136 STAT. 2387</page>
<dc:type>Public Law</dc:type><docNumber>117–259</docNumber>
<congress value="117">117th Congress</congress>
</preface>
<main>
<longTitle>
<docTitle class="centered fontsize12" style="-uslm-lc:I658005">An Act</docTitle>
<officialTitle class="indentUp0 firstIndent1 fontsize8" style="-uslm-lc:I658011">To require an annual report on the cybersecurity of the Small Business Administration, and for other purposes.<sidenote><p class="centered fontsize8" id="xbf6f0031-e817-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658076"><approvedDate date="2022-12-21">Dec. 21, 2022</approvedDate></p><p class="centered fontsize8" id="xbf6f0032-e817-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658076">[<ref href="/us/bill/117/hr/3462">H.R. 3462</ref>]<?GPOvSpace 08?></p></sidenote></officialTitle>
</longTitle>
<enactingFormula style="-uslm-lc:I658120"><i>  Be it enacted by the Senate and House of Representa­tives of the United States of America in Congress assembled,</i></enactingFormula><sidenote><p class="leftAlign firstIndent0 fontsize8" id="xbf6f2743-e817-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">SBA Cyber Awareness Act.</p><p class="leftAlign firstIndent0 fontsize8" id="xbf6f2744-e817-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180"><ref href="/us/usc/t15/s631">15 USC 631 note</ref>.</p></sidenote>
<section id="d63068e92" identifier="/us/pl/117/259/s1" style="-uslm-lc:I658146"><num class="bold" value="1">SECTION 1. </num><heading>SHORT TITLE.</heading><content style="-uslm-lc:I658120">  This Act may be cited as the “<shortTitle role="act">SBA Cyber Awareness Act</shortTitle>”.</content></section>
<section id="d63068e102" identifier="/us/pl/117/259/s2" style="-uslm-lc:I658141"><num class="fontsize12" value="2">SEC. 2. </num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="xbf6f2745-e817-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">China.</p></sidenote><heading>CYBERSECURITY AWARENESS REPORTING.</heading><subsection class="firstIndent0 fontsize10" id="ybf6f7566-e817-11f0-a1e4-69761a48a15a" identifier="/us/pl/117/259/s2/a" role="instruction" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="a">(a) </num><heading class="fontsize10"><inline class="smallCaps">In General</inline>.—</heading><content>Section 10 of the Small Business Act (<ref href="/us/usc/t15/s639">15 U.S.C. 639</ref>) <amendingAction type="amend">is amended</amendingAction> by <amendingAction type="insert">inserting</amendingAction> after subsection (a) the following:<quotedContent><subsection class="firstIndent0 fontsize10" id="ybf6fea97-e817-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="b">“(b) </num><heading class="fontsize10"><inline class="smallCaps">Cybersecurity Reports</inline>.—</heading><paragraph class="fontsize10" id="ybf6fea98-e817-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="1">“(1) </num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="xbf6fea99-e817-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Strategies.</p></sidenote><heading class="fontsize10"><inline class="smallCaps">Annual report</inline>.—</heading><chapeau>Not later than 180 days after the date of enactment of this subsection, and every year thereafter, the Administrator shall submit a report to the appropriate congressional committees that includes—</chapeau><subparagraph class="fontsize10" id="ybf6fea9a-e817-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">“(A) </num><content>a strategy to increase the cybersecurity of information technology infrastructure of the Administration;</content></subparagraph>
<subparagraph class="fontsize10" id="ybf6fea9b-e817-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">“(B) </num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="xbf6fea9c-e817-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Plan.</p></sidenote><content>a supply chain risk management strategy and an implementation plan to address the risks of foreign manufactured information technology equipment utilized by the Administration, including specific risk mitigation activities for components originating from entities with principal places of business located in the People’s Republic of China; and</content></subparagraph>
<subparagraph class="fontsize10" id="ybf6fea9d-e817-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="C">“(C) </num><chapeau>an account of—</chapeau><clause class="fontsize10" id="ybf6fea9e-e817-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658126"><num class="fontsize10" style="-uslm-lc:emspace2" value="i">“(i) </num><sidenote><p class="leftAlign firstIndent0 fontsize8" id="xbf6fea9f-e817-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658180">Time periods.</p></sidenote><content>any incident that occurred at the Administration during the 2-year period preceding the date on which the first report is submitted, and, for subsequent reports, the 1-year period preceding the date of submission; and</content></clause>
<clause class="fontsize10" id="ybf6feaa0-e817-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658126"><num class="fontsize10" style="-uslm-lc:emspace2" value="ii">“(ii) </num><content>any action taken by the Administrator to respond to or remediate any such incident.</content></clause>
</subparagraph>
</paragraph>
<paragraph class="fontsize10" id="ybf6feaa1-e817-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="2">“(2) </num><heading class="fontsize10"><inline class="smallCaps">FISMA reports</inline>.—</heading><content>Each report required under paragraph (1) may be submitted as part of the report required under <ref href="/us/usc/t44/s3554">section 3554 of title 44, United States Code</ref>.</content></paragraph>
<paragraph class="fontsize10" id="ybf6feaa2-e817-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="3">“(3) </num><heading class="fontsize10"><inline class="smallCaps">Rule of construction</inline>.—</heading><content>Nothing in this subsection shall be construed to affect the reporting requirements of the Administrator under <ref href="/us/usc/t44/ch35">chapter 35 of title 44, United States Code</ref>, in particular the requirement to notify the Federal information security incident center under section 3554(b)(7)(C)(ii) of such title, any guidance issued by the Office of Management and Budget, or any other provision of law or Federal policy.<page identifier="/us/stat/136/2388">136 STAT. 2388</page></content></paragraph>
<paragraph class="fontsize10" id="ybf6feaa3-e817-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658122"><num class="fontsize10" style="-uslm-lc:emspace2" value="4">“(4) </num><heading class="fontsize10"><inline class="smallCaps">Definitions</inline>.—</heading><chapeau>In this subsection:</chapeau><subparagraph class="fontsize10" id="ybf6feaa4-e817-11f0-a1e4-69761a48a15a" role="definitions" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="A">“(A) </num><heading class="fontsize10"><inline class="smallCaps">Appropriate congressional committees</inline>.—</heading><chapeau>The term ‘<term>appropriate congressional committees</term>’ means—</chapeau><clause class="fontsize10" id="ybf6feaa5-e817-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658126"><num class="fontsize10" style="-uslm-lc:emspace2" value="i">“(i) </num><content>the Committee on Small Business and Entrepreneurship of the Senate;</content></clause>
<clause class="fontsize10" id="ybf6feaa6-e817-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658126"><num class="fontsize10" style="-uslm-lc:emspace2" value="ii">“(ii) </num><content>the Committee on Homeland Security and Governmental Affairs of the Senate;</content></clause>
<clause class="fontsize10" id="ybf6feaa7-e817-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658126"><num class="fontsize10" style="-uslm-lc:emspace2" value="iii">“(iii) </num><content>the Committee on Small Business of the House of Representatives; and</content></clause>
<clause class="fontsize10" id="ybf6feaa8-e817-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658126"><num class="fontsize10" style="-uslm-lc:emspace2" value="iv">“(iv) </num><content>the Committee on Oversight and Reform of the House of Representatives.</content></clause>
</subparagraph>
<subparagraph class="fontsize10" id="ybf6feaa9-e817-11f0-a1e4-69761a48a15a" role="definitions" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="B">“(B) </num><heading class="fontsize10"><inline class="smallCaps">Incident</inline>.—</heading><content>The term ‘<term>incident</term>’ has the meaning given the term in <ref href="/us/usc/t44/s3552">section 3552 of title 44, United States Code</ref>.</content></subparagraph>
<subparagraph class="fontsize10" id="ybf6feaaa-e817-11f0-a1e4-69761a48a15a" role="definitions" style="-uslm-lc:I658124"><num class="fontsize10" style="-uslm-lc:emspace2" value="C">“(C) </num><heading class="fontsize10"><inline class="smallCaps">Information technology</inline>.—</heading><content>The term ‘<term>information technology</term>’ has the meaning given the term in <ref href="/us/usc/t44/s3502">section 3502 of title 44, United States Code</ref>.”</content></subparagraph>
</paragraph>
</subsection>
</quotedContent>.</content></subsection>
<subsection class="firstIndent0 fontsize10" id="ybf6feaab-e817-11f0-a1e4-69761a48a15a" identifier="/us/pl/117/259/s2/b" style="-uslm-lc:I658120"><num class="fontsize10" style="-uslm-lc:emspace2" value="b">(b) </num><heading class="fontsize10"><inline class="smallCaps">Report</inline>.—</heading><content>Not later than 1 year after the date of enactment of this Act, the Administrator of the Small Business Administration shall, to the greatest extent practicable, provide to the Committee on Small Business and Entrepreneurship of the Senate, the Committee on Homeland Security and Governmental Affairs of the Senate, the Committee on Small Business of the House of Representatives, and the Committee on Oversight and Reform of the House of Representatives a detailed account of information technology (as defined in <ref href="/us/usc/t44/s3502">section 3502 of title 44, United States Code</ref>) of the Small Business Administration that was manufactured by an entity that has its principal place of business located in the People’s Republic of China.</content></subsection>
</section>
<action>
<actionDescription style="-uslm-lc:I658030">Approved</actionDescription> <date date="2022-12-21">December 21, 2022</date>.</action>
</main>
<legislativeHistory>
<heading style="-uslm-lc:I658031"><inline class="underline">LEGISLATIVE HISTORY</inline>—<ref href="/us/bill/117/hr/3462">H.R. 3462</ref>:</heading>
<note>
<headingText style="-uslm-lc:I658032">HOUSE REPORTS:</headingText> ┐No. <ref href="/us/hrpt/117/138">117–138</ref> (<committee>Comm. on Small Business</committee>).
</note>
<note>
<headingText style="-uslm-lc:I658032">SENATE   REPORTS:</headingText> ┐No.  <ref href="/us//117/102">117–102</ref>   (<committee>Comm.   on   Small   Business   and   Entrepreneurship</committee>).
</note>
<note>
<heading style="-uslm-lc:I658032">CONGRESSIONAL RECORD:</heading>
<subheading style="-uslm-lc:I658033">Vol. 167 (2021):</subheading>
<p class="indentUp2 firstIndent-1" id="xbf7011bc-e817-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658034">Nov. 2, considered and passed House.</p><subheading style="-uslm-lc:I658033">Vol. 168 (2022):</subheading>
<p class="indentUp2 firstIndent-1" id="xbf7011bd-e817-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658034">Sept. 28, considered and passed Senate, amended.</p><p class="indentUp2 firstIndent-1" id="xbf7011be-e817-11f0-a1e4-69761a48a15a" style="-uslm-lc:I658034">Dec. 5, 6, House considered and concurred in Senate amendment.</p></note>
</legislativeHistory>
<endMarker>○</endMarker>
</pLaw>