<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Reported-in-House" dms-id="HA7FBD7E37E5C44BD932DF814E08EB1AD" public-private="public" key="H" bill-type="olc"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>117 HR 3462 RH: SBA Cyber Awareness Act</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2021-10-12</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">IB</distribution-code><calendar display="yes">Union Calendar No. 98</calendar><congress display="yes">117th CONGRESS</congress><session display="yes">1st Session</session><legis-num display="yes">H. R. 3462</legis-num><associated-doc role="report" display="yes">[Report No. 117–138]</associated-doc><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20210521">May 21, 2021</action-date><action-desc><sponsor name-id="C001121">Mr. Crow</sponsor> (for himself and <cosponsor name-id="K000397">Mrs. Kim of California</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HSM00">Committee on Small Business</committee-name></action-desc></action><action display="yes"><action-date date="20211012">October 12, 2021</action-date><action-desc>Reported from the <committee-name committee-id="HSM00">Committee on Small Business</committee-name>; committed to the Committee of the Whole House on the State of the Union and ordered to be printed</action-desc></action><action><action-desc><pagebreak></pagebreak></action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To require an annual report on the cybersecurity of the Small Business Administration, and for other purposes.<pagebreak></pagebreak></official-title></form><legis-body id="H81783DF833924D0B99A7B2EB13319CBE" style="OLC"><section id="H9900F8D8B5FE4B30A13BD4A1E534BF35" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>SBA Cyber Awareness Act</short-title></quote>.</text></section><section id="H08197DDA09A04050B276377BFF72F365"><enum>2.</enum><header>Cybersecurity awareness reporting</header><text display-inline="no-display-inline">Section 10 of the Small Business Act (<external-xref legal-doc="usc" parsable-cite="usc/15/639">15 U.S.C. 639</external-xref>) is amended by inserting after subsection (a) the following:</text><quoted-block display-inline="no-display-inline" id="H4BE68B161E8E46C6B25CBC3651FCA2FE" style="OLC"><subsection id="HF0A4E430D68C4796BE4BBED8969D4D08"><enum>(b)</enum><header>Cybersecurity reports</header><paragraph id="HBB951CCCDC4348728980B5663E0F4138"><enum>(1)</enum><header>Annual report</header><text>Not later than 180 days after the date of enactment of this subsection, and every year thereafter, the Administrator shall submit a report to the appropriate congressional committees that includes—</text><subparagraph id="H3E4F01F2CC7A43D9AFCF35881FA12A97"><enum>(A)</enum><text>an assessment of the information technology (as defined in section 11101 of title 40, United States Code) and cybersecurity infrastructure of the Administration;</text></subparagraph><subparagraph id="HC39A09005F224AF9BE5A75139705A039"><enum>(B)</enum><text display-inline="yes-display-inline">a strategy to increase the cybersecurity infrastructure of the Administration;</text></subparagraph><subparagraph id="H439C7FC2157742F99D721A59B2C1FFB5"><enum>(C)</enum><text display-inline="yes-display-inline">a detailed account of any information technology equipment or interconnected system or subsystem of equipment of the Administration that was manufactured by an entity that has its principal place of business located in the People’s Republic of China; and</text></subparagraph><subparagraph id="HFC86B65A35944369B97002F3EA2DDC75"><enum>(D)</enum><text display-inline="yes-display-inline">an account of any cybersecurity risk or incident that occurred at the Administration during the 2-year period preceding the date on which the report is submitted, and any action taken by the Administrator to respond to or remediate any such cybersecurity risk or incident.</text></subparagraph></paragraph><paragraph id="HFBC35EC3617246EB9971500829B2BBA4"><enum>(2)</enum><header>Additional reports</header><text display-inline="yes-display-inline">If the Administrator determines that there is a reasonable basis to conclude that a cybersecurity risk or incident occurred at the Administration, the Administrator shall—</text><subparagraph id="H2E5B69F144C943EF965A657BB5C15AF0"><enum>(A)</enum><text display-inline="yes-display-inline">not later than 7 days after the date on which the Administrator makes that determination, notify the appropriate congressional committees of the cybersecurity risk or incident; and</text></subparagraph><subparagraph id="HA7FD07C50DC344C4ADE9C487868D1646"><enum>(B)</enum><text display-inline="yes-display-inline">not later than 30 days after the date on which the Administrator makes a determination under subparagraph (A)—</text><clause id="H81DD6969C7274C2784D9A7E1CE302CF0"><enum>(i)</enum><text display-inline="yes-display-inline">provide notice to individuals and small business concerns affected by the cybersecurity risk or incident; and</text></clause><clause id="HF5C622D2327F4FC08102F9DB4354A3B3"><enum>(ii)</enum><text>submit to the appropriate congressional committees a report, based on information available to the Administrator as of the date which the Administrator submits the report, that includes—</text><subclause id="HAE674C63AC44437CBCC712432BB15752"><enum>(I)</enum><text display-inline="yes-display-inline">a summary of information about the cybersecurity risk or incident, including how the cybersecurity risk or incident occurred; and</text></subclause><subclause id="HC6B61A398FA24CC988C721D0C70A63D0"><enum>(II)</enum><text display-inline="yes-display-inline">an estimate of the number of individuals and small business concerns affected by the cybersecurity risk or incident, including an assessment of the risk of harm to affected individuals and small business concerns.</text></subclause></clause></subparagraph></paragraph><paragraph id="H2C09409E62EC490997528430C5AAE391"><enum>(3)</enum><header>Rule of construction</header><text>Nothing in this subsection shall be construed to affect the reporting requirements of the Administrator under <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/35">chapter 35</external-xref> of title 44, United States Code, in particular the requirement to notify the Federal information security incident center under section 3554(b)(7)(C)(ii) of such title, or any other provision of law.</text></paragraph><paragraph id="H20A8C0DB37144772A86296A06F5F6C2C"><enum>(4)</enum><header>Definitions</header><text>In this subsection:</text><subparagraph id="H965ED790A5854C1AA639F31FD0372A64"><enum>(A)</enum><header>Appropriate congressional committees</header><text>The term <term>appropriate congressional committees</term> means—</text><clause id="HEE60528888B54831B64EC916E7C0441E"><enum>(i)</enum><text>the Committee on Small Business and Entrepreneurship of the Senate; and</text></clause><clause id="H8A8DE95275604607B910E51CFD522B78"><enum>(ii)</enum><text>the Committee on Small Business of the House of Representatives.</text></clause></subparagraph><subparagraph id="HCBCFB34FF4DB45CFBC920B539F095B93"><enum>(B)</enum><header>Cybersecurity risk; incident</header><text display-inline="yes-display-inline">The terms <term>cybersecurity risk</term> and <term>incident</term> have the meanings given such terms, respectively, under section 2209(a) of the Homeland Security Act of 2002.</text></subparagraph></paragraph></subsection><after-quoted-block>.</after-quoted-block></quoted-block></section></legis-body><endorsement display="yes"><action-date date="20211012">October 12, 2021</action-date><action-desc>Committed to the Committee of the Whole House on the State of the Union and ordered to be printed</action-desc></endorsement></bill> 

