<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" bill-type="olc" dms-id="H3881976DC4DE44A68255D1ED56D291F3" key="H" public-private="public"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>116 HR 1648 IH: Small Business Advanced Cybersecurity Enhancements Act of 2019</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2019-03-08</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress display="yes">116th CONGRESS</congress><session display="yes">1st Session</session><legis-num display="yes">H. R. 1648</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20190308">March 8, 2019</action-date><action-desc><sponsor name-id="C000266">Mr. Chabot</sponsor> (for himself and <cosponsor name-id="V000081">Ms. Velázquez</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HSM00">Committee on Small Business</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To amend the Small Business Act to provide for the establishment of an enhanced cybersecurity
			 assistance and protections for small businesses, and for other purposes.</official-title></form>
	<legis-body id="HA8C698F31AE94F5EA7EED9DBD8D4D04E" style="OLC">
 <section id="H4F66895430AB471DB5F4FD533A08B828" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Small Business Advanced Cybersecurity Enhancements Act of 2019</short-title></quote>.</text> </section><section id="HFC982EB175C5445BB3F37351838C442C"><enum>2.</enum><header>Findings</header><text display-inline="no-display-inline">Congress finds the following:</text>
 <paragraph id="HC9A53197095C4C0F873DA5DD6C49D4DD"><enum>(1)</enum><text display-inline="yes-display-inline">Small businesses represent more than 97 percent of total businesses in the United States and make up an essential part of the supply chain to some of the largest companies, many of which are in critical infrastructure sectors, from financial and transportation organizations to power, water, and healthcare suppliers.</text>
 </paragraph><paragraph id="H82BAB3BCF3C4450ABFC170D5E7AEA818"><enum>(2)</enum><text>Many small businesses do not have dedicated information technology (<quote>IT</quote>) departments and must outsource IT functions or assign these duties to an employee as a secondary function.</text>
 </paragraph><paragraph id="H9251BAE9A5FA4B75AEF9D7CAFC816E04"><enum>(3)</enum><text>The Internet Crime Complaint Center within the United States Department of Justice recorded 298,728 cybersecurity-related complaints in its 2016 report.</text>
 </paragraph><paragraph id="H03DE17719F4C4C5C8759908F2550FAF8"><enum>(4)</enum><text>There has been steady increases of cybersecurity-related complaints year over year since the year 2000, totaling 3,762,348.</text>
 </paragraph><paragraph id="H585F2548889348F396AF0CBAFECBD246"><enum>(5)</enum><text>Seventy-one percent of cyber attacks occurred in businesses with fewer than 100 employees.</text> </paragraph><paragraph id="HAB62FD3EF8E04AE5BFDEA20428698E21"><enum>(6)</enum><text>Only 14 percent of small- and medium-sized businesses believe they have the ability to effectively mitigate cyber risks and vulnerabilities.</text>
 </paragraph><paragraph id="HDED47B1A982A480DAB3EF60AA514594E"><enum>(7)</enum><text>Small businesses risk theft and manipulation of sensitive data if they lack adequate cybersecurity measures.</text>
 </paragraph><paragraph id="H52C14483E5A14CF98DB2A8C4444BCF55"><enum>(8)</enum><text>The Better Business Bureau found that half of small businesses could remain profitable for only one month if they lost essential data.</text>
 </paragraph><paragraph id="H21B12BB311324EAE8D30C57882CF23C9"><enum>(9)</enum><text>Cyber crime is growing rapidly and the annual costs to the global economy are estimated to reach over $2,000,000,000,000 by 2019.</text>
 </paragraph><paragraph id="H1EDB827A24FA44A88E348686CE93C9DB"><enum>(10)</enum><text>Cybersecurity is a global challenge where the security threat, attacks, and techniques continually evolve and no company, individual, or Federal agency is immune from these threats.</text>
 </paragraph><paragraph id="H8A843A23EA2E49F7910D488066863646"><enum>(11)</enum><text>Strong collaboration between the public and private sector is essential in the fight against cyber crime.</text>
 </paragraph><paragraph id="H1A2B1990C4604BFA85B7E4DD31EBDFB2"><enum>(12)</enum><text>There is a reluctance among small businesses to voluntarily share information with government entities, and the Federal Government should work proactively to incentivize and encourage voluntary information sharing to improve the Nation’s cybersecurity posture.</text>
 </paragraph></section><section id="H94D6D9A49BE54F319774A6D9942E60DD"><enum>3.</enum><header>Enhanced cybersecurity assistance and protections for small businesses</header><text display-inline="no-display-inline">Section 21(a) of the Small Business Act (<external-xref legal-doc="usc" parsable-cite="usc/15/648">15 U.S.C. 648(a)</external-xref>) is amended by adding at the end the following new paragraph:</text>
			<quoted-block id="H728057EAD80743E5905710CED8352909" style="OLC">
				<paragraph id="HC56F423CE1F14AA3A2C32BC816879DA5"><enum>(9)</enum><header>Small business cybersecurity assistance and protections</header>
 <subparagraph id="HD8791B00788740BCA27F1CB452C57967"><enum>(A)</enum><header>Establishment of small business cybersecurity assistance units</header><text>The Administrator of the Small Business Administration, in coordination with the Secretary of Commerce, and in consultation with the Secretary of Homeland Security and the Attorney General, shall establish—</text>
 <clause id="HCB35771B29E24ACE87329ADF444428C5"><enum>(i)</enum><text>in the Administration, a central small business cybersecurity assistance unit; and</text> </clause><clause id="HD53C7AD9C5384B2BB89402038BEF6909"><enum>(ii)</enum><text>within each small business development center, a regional small business cybersecurity assistance unit.</text>
						</clause></subparagraph><subparagraph id="H8DD1310742244CC5881682E27DEF2D2F"><enum>(B)</enum><header>Duties of the central small business cybersecurity assistance unit</header>
 <clause id="H08476D831DAB492882A5D5E60FF085FF"><enum>(i)</enum><header>In general</header><text display-inline="yes-display-inline">The central small business cybersecurity assistance unit established under subparagraph (A)(i) shall serve as the primary interface for small business concerns to receive and share cyber threat indicators and defensive measures with the Federal Government.</text>
 </clause><clause id="HA81D40E6E95648F8BC04D459886B02E4"><enum>(ii)</enum><header>Use of capability and processes</header><text display-inline="yes-display-inline">The central small business cybersecurity assistance unit shall use the capability and process certified pursuant to section 105(c)(2)(A) of the Cybersecurity Information Sharing Act of 2015 (<external-xref legal-doc="usc" parsable-cite="usc/6/1504">6 U.S.C. 1504(c)(2)(A)</external-xref>) to receive cyber threat indicators or defensive measures from small business concerns.</text>
 </clause><clause id="H76D1806A1625460A8931374829937BF5"><enum>(iii)</enum><header>Application of CISA</header><text display-inline="yes-display-inline">A small business concern that receives or shares cyber threat indicators and defensive measures with the Federal Government through the central small business cybersecurity assistance unit established under subparagraph (A)(i), or with any appropriate entity pursuant to section 103(c) of the Cybersecurity Information Sharing Act of 2015 (<external-xref legal-doc="usc" parsable-cite="usc/6/1503">6 U.S.C. 1503(c)</external-xref>), shall receive the protections and exemptions provided in such Act and this paragraph.</text>
						</clause></subparagraph><subparagraph id="HB022808170CF40CB9F29BBB3B817E5AD"><enum>(C)</enum><header>Relation to NCCIC</header>
 <clause id="HE721ABFF665E4FA4B19CED4EF585290E"><enum>(i)</enum><header>Central small business cybersecurity assistance unit</header><text display-inline="yes-display-inline">The central small business cybersecurity assistance unit established under subparagraph (A)(i) shall be collocated with the national cybersecurity and communications integration center.</text>
 </clause><clause id="HFB5F920DE75B40C79BC32A9B7923BB3E"><enum>(ii)</enum><header>Access to information</header><text display-inline="yes-display-inline">The national cybersecurity and communications integration center shall have access to all cyber threat indicators or defensive measures shared with the central small cybersecurity assistance unit established under subparagraph (A)(i) through the use of the capability and process described in subparagraph (B)(ii).</text>
 </clause></subparagraph><subparagraph id="H9370C5C79BBA481EA5FBDC80E0DF1E19"><enum>(D)</enum><header>Cybersecurity assistance for small businesses</header><text display-inline="yes-display-inline">The central small business cybersecurity assistance unit established under subparagraph (A)(i) shall—</text>
 <clause id="HA57A10B33785465880A7B11FB1F87819"><enum>(i)</enum><text display-inline="yes-display-inline">work with each regional small business cybersecurity assistance unit established under subparagraph (A)(ii) to provide cybersecurity assistance to small business concerns;</text>
 </clause><clause id="H9486766A482D4D7BB6AD9C0AD0E03605"><enum>(ii)</enum><text>leverage resources from the Administration, the Department of Commerce, the Department of Homeland Security, the Department of Justice, the Department of the Treasury, the Department of State, and any other Federal department or agency the Administrator determines appropriate, in order to help improve the cybersecurity posture of small business concerns;</text>
 </clause><clause id="H0D110FC9C20948CE8A6A09C92B58FB8C"><enum>(iii)</enum><text display-inline="yes-display-inline">coordinate with the Department of Homeland Security to identify and disseminate information to small business concerns in a form that is accessible and actionable by small business concerns;</text>
 </clause><clause id="HF19EB83B8D614EF3B3150DEB06DFE951"><enum>(iv)</enum><text display-inline="yes-display-inline">coordinate with the National Institute of Standards and Technology to identify and disseminate information to small business concerns on the most cost-effective methods for implementing elements of the cybersecurity framework of the National Institute of Standards and Technology applicable to improving the cybersecurity posture of small business concerns;</text>
 </clause><clause id="H9845E2DF0E4748FFB57B2B782B0567FB"><enum>(v)</enum><text display-inline="yes-display-inline">seek input from the Office of Advocacy of the Administration to ensure that any policies or procedures adopted by any department, agency, or instrumentality of the Federal Government do not unduly add regulatory burdens to small business concerns in a manner that will hamper the improvement of the cybersecurity posture of such small business concerns; and</text>
 </clause><clause id="H60F4031E49154248B3989F003969781E"><enum>(vi)</enum><text display-inline="yes-display-inline">leverage resources and relationships with representatives and entities involved in the national cybersecurity and communications integration center to publicize the capacity of the Federal Government to assist small business concerns in improving cybersecurity practices.</text>
						</clause></subparagraph><subparagraph id="H865E79C14BD64D8EB3EAFA0AB017E22F"><enum>(E)</enum><header>Enhanced cybersecurity protections for small businesses</header>
 <clause id="HECC46695440D4339875F06F0C25E973B"><enum>(i)</enum><header>In general</header><text display-inline="yes-display-inline">Notwithstanding any other provision of law, no cause of action shall lie or be maintained in any court against any small business concern, and such action shall be promptly dismissed, if such action related to or arises out of—</text>
 <subclause id="HBC8B9E9E29224C16A3F062ED8950E6F7"><enum>(I)</enum><text display-inline="yes-display-inline">any activity authorized under this paragraph or the Cybersecurity Information Sharing Act of 2015 (<external-xref legal-doc="usc" parsable-cite="usc/6/1501">6 U.S.C. 1501</external-xref> et seq.); or</text>
 </subclause><subclause id="H4788C066FC224AAAA7D46ABD1F937179"><enum>(II)</enum><text>any action or inaction in response to any cyber threat indicator, defensive measure, or other information shared or received pursuant to this paragraph or the Cybersecurity Information Sharing Act of 2015 (<external-xref legal-doc="usc" parsable-cite="usc/6/1501">6 U.S.C. 1501</external-xref> et seq.).</text>
 </subclause></clause><clause id="HF8FF9D92540E4D9ABFAC6DDAD864A4FC"><enum>(ii)</enum><header>Application</header><text display-inline="yes-display-inline">The exception provided in section 105(d)(5)(D)(ii)(I) of the Cybersecurity Information Sharing Act of 2015 (<external-xref legal-doc="usc" parsable-cite="usc/6/1504">6 U.S.C. 1504(d)(5)(D)(ii)(I)</external-xref>) shall not apply to any cyber threat indicator or defensive measure shared or received by small business concerns pursuant to this paragraph or the Cybersecurity Information Sharing Act of 2015 (<external-xref legal-doc="usc" parsable-cite="usc/6/1501">6 U.S.C. 1501</external-xref> et seq.).</text>
 </clause><clause id="H5E0FD4C111D54E7F83EDEC8B3BBB3219"><enum>(iii)</enum><header>Rule of construction</header><text display-inline="yes-display-inline">Nothing in this subparagraph shall be construed to affect the applicability or merits of any defense, motion, or argument in any cause of action in a court brought against an entity that is not a small business concern.</text>
 </clause></subparagraph><subparagraph id="HD90FFD7138AE4F6FB7DD4CFCD25634CE"><enum>(F)</enum><header>Definitions</header><text>In this paragraph:</text> <clause id="H7C7E86473A5341828B0031DB5A4A8BB9"><enum>(i)</enum><header>CISA definitions</header><text>The terms <term>cyber threat indicator</term> and <term>defensive measure</term> have the meanings given such terms in section 102 of the Cybersecurity Information Sharing Act of 2015 (<external-xref legal-doc="usc" parsable-cite="usc/6/1501">6 U.S.C. 1501</external-xref>).</text>
 </clause><clause id="H3F09326CE11D42E6B5C08B9CF8E97E75"><enum>(ii)</enum><header>National cybersecurity and communications integration center</header><text display-inline="yes-display-inline">The term <term>national cybersecurity and communications integration center</term> means the national cybersecurity and communications integration center established under section 227 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/148">6 U.S.C. 148</external-xref>).</text></clause></subparagraph></paragraph><after-quoted-block>.</after-quoted-block></quoted-block>
		</section><section id="HCCA4F49538B74D45A2D7C76464A90A17"><enum>4.</enum><header>Prohibition on new appropriations</header>
 <subsection id="H3359459EB51E433AAC9D507B56F421E5"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">No additional funds are authorized to be appropriated to carry out this Act and the amendments made by this Act.</text>
 </subsection><subsection id="H85F2678E3FF5497082F5D71278E8CD25"><enum>(b)</enum><header>Existing funding</header><text display-inline="yes-display-inline">This Act and the amendments made by this Act shall be carried out using amounts made available under section 21(a)(4)(C)(viii) of the Small Business Act (<external-xref legal-doc="usc" parsable-cite="usc/15/648">15 U.S.C. 648(a)(4)(viii)</external-xref>).</text>
 </subsection><subsection id="HC52494A8BE71412DA8D56318343F5B14"><enum>(c)</enum><header>Technical and conforming amendment</header><text>Section 21(a)(4)(C)(viii) of the Small Business Act (15 U.S.C.648(a)(4)(C)(viii)) is amended to read as follows:</text>
				<quoted-block display-inline="no-display-inline" id="H42CD083611FC494DA9C4688ADD2809BD" style="OLC">
					<clause id="H94477EF859CE40AAA0E9E1A165AEE11C"><enum>(viii)</enum><header>Limitation</header>
 <subclause id="HFD48F5C0F5EC451D9777D5C600F66301"><enum>(I)</enum><header>Cybersecurity assistance</header><text>From the funds appropriated pursuant to clause (vii), the Administration shall reserve not less than $1,000,000 in each fiscal year to develop cybersecurity assistance units at small business development centers under paragraph (9).</text>
						</subclause><subclause id="H8F5F54BD9AA745CE9EAF3DA94773AEC3"><enum>(II)</enum><header>Portable assistance</header>
 <item id="H0573443AD69048009866EEABD0570865"><enum>(aa)</enum><header>In general</header><text>Any funds appropriated pursuant to clause (vii) that are remaining after reserving amounts under subclause (I) may be used for portable assistance for startup and sustainability non-matching grant programs to be conducted by eligible small business development centers in communities that are economically challenged as a result of a business or government facility down sizing or closing, which has resulted in the loss of jobs or small business instability.</text>
 </item><item id="H883B44FC1C1D4C8DA0F6DF574A2389E4"><enum>(bb)</enum><header>Grant amount and use</header><text>A non-matching grant under this subclause shall not exceed $100,000, and shall be used for small business development center personnel expenses and related small business programs and services.</text></item></subclause></clause><after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection></section></legis-body></bill>


