<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" dms-id="HE275B4AB00784E1FA21AF8ACA0BDB488" public-private="public" key="H" bill-type="olc"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>115 HR 6541 IH: Improving Cybersecurity of Small Businesses, Nonprofits, and Local Governments Act</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2022-02-01</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress display="yes">117th CONGRESS</congress><session display="yes">2d Session</session><legis-num display="yes">H. R. 6541</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20220201">February 1, 2022</action-date><action-desc><sponsor name-id="E000215">Ms. Eshoo</sponsor> (for herself, <cosponsor name-id="T000480">Mr. Timmons</cosponsor>, <cosponsor name-id="R000606">Mr. Raskin</cosponsor>, and <cosponsor name-id="C001055">Mr. Case</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HSM00">Committee on Small Business</committee-name>, and in addition to the Committee on <committee-name committee-id="HHM00">Homeland Security</committee-name>, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned</action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To require the Director of the Cybersecurity and Infrastructure Security Agency to establish cybersecurity guidance for small organizations, and for other purposes.</official-title></form><legis-body id="HE4CFB43FBCCD4264B710ACAA36801AA1" style="OLC"><section id="H7E791F1D827D4253914389AE3DDED18E" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Improving Cybersecurity of Small Businesses, Nonprofits, and Local Governments Act</short-title></quote>.</text></section><section id="H016C7919A7B2463BA0DE26B4B0B6A0C0"><enum>2.</enum><header>Improving cybersecurity of small entities</header><subsection id="H9E6BBCE63A89418880A1EF4FAA7932B6"><enum>(a)</enum><header>Definitions</header><text>In this section:</text><paragraph id="HC4270D12F8554ACE9B643833F6CA6994"><enum>(1)</enum><header>Administrator</header><text>The term <term>Administrator</term> means the Administrator of the Small Business Administration.</text></paragraph><paragraph id="H0093EEDE154B481EAA938022260888A8"><enum>(2)</enum><header>Annual cybersecurity report; small business; small entity; small governmental jurisdiction; small organization</header><text>The terms <term>annual cybersecurity report</term>, <term>small business</term>, <term>small entity</term>, <term>small governmental jurisdiction</term>, and <term>small organization</term> have the meanings given those terms in section 2220D of the Homeland Security Act of 2002, as added by subsection (b). </text></paragraph><paragraph id="HDC49DBAB47F543A4A7AFEB1361356F94"><enum>(3)</enum><header>CISA</header><text>The term <term>CISA</term> means the Cybersecurity and Infrastructure Security Agency.</text></paragraph><paragraph id="H4514A202E8734F4495034BCFDF789DEC"><enum>(4)</enum><header>Commission</header><text>The term <term>Commission</term> means the Federal Trade Commission.</text></paragraph><paragraph id="H569ACECF1D654650B145D78536B19F7D"><enum>(5)</enum><header>Secretary</header><text>The term <term>Secretary</term> means the Secretary of Commerce.</text></paragraph></subsection><subsection id="HD22E9E05F6034C508F9A4E7FE0575506"><enum>(b)</enum><header>Annual report</header><paragraph id="H8FCF34ECAFE24664AF4B22748299D222"><enum>(1)</enum><header>Amendment</header><text>Subtitle A of title XXII of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/651">6 U.S.C. 651 et seq.</external-xref>) is amended by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="HB6C1BB8E767F41CA9A633A0B83C41083"><section id="H62E47225FCFC4C41B21B0AA11391CB8D"><enum>2220D.</enum><header>Annual cybersecurity report for small entities</header><subsection id="HD7FEFBB92E8B445C9B522B5D01EB163C"><enum>(a)</enum><header>Definitions</header><paragraph id="H9FFACE08D6A74F9FA2D093CB1964E956"><enum>(1)</enum><header>Administration</header><text>The term <term>Administration</term> means the Small Business Administration.</text></paragraph><paragraph id="HD32CA1A87B3D4A78AC827079F08D266F"><enum>(2)</enum><header>Administrator</header><text>The term <term>Administrator</term> means the Administrator of the Administration.</text></paragraph><paragraph id="HBFCCB70B6098443DA000D8E261D2B429"><enum>(3)</enum><header>Annual cybersecurity report</header><text>The term <term>annual cybersecurity report</term> means the annual cybersecurity report published and promoted under subsections (b) and (c), respectively. </text></paragraph><paragraph id="H89DB3A3BADCC4F0EAC04DA0CB515432C"><enum>(4)</enum><header>Commission</header><text>The term <term>Commission</term> means the Federal Trade Commission.</text></paragraph><paragraph id="HB3D6D3DE99ED41068934C3FF42089E46"><enum>(5)</enum><header>Electronic device</header><text>The term <term>electronic device</term> means any electronic equipment that is—</text><subparagraph id="H7E529EAFB1B3400CBBE533E17348D869"><enum>(A)</enum><text>used by an employee or contractor of a small entity for the purpose of performing work for the small entity;</text></subparagraph><subparagraph id="H3CC1E6084FCE4668A48D5EDF86C37B5C"><enum>(B)</enum><text>capable of connecting to the internet or another communication network; and</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="HE43A5CDD69EE4FCAA6979E9D8B10DF22"><enum>(C)</enum><text>capable of sending, receiving, or processing personal information. </text></subparagraph></paragraph><paragraph id="HD46179C36710454C903CBA100D843BBA"><enum>(6)</enum><header>NIST</header><text>The term <term>NIST</term> means the National Institute of Standards and Technology.</text></paragraph><paragraph id="H20D7B951B7EB4F21897C10F48DE2CCEA"><enum>(7)</enum><header>Small business</header><text>The term <term>small business</term> has the meaning given the term <term>small business concern</term> under section 3 of the Small Business Act (<external-xref legal-doc="usc" parsable-cite="usc/15/632">15 U.S.C. 632</external-xref>). </text></paragraph><paragraph id="H21B40DC9187841239292FFC352854982"><enum>(8)</enum><header>Small entity</header><text>The term <term>small entity</term> means—</text><subparagraph id="H5355F6C3E1C84272AB5EC087495C2950"><enum>(A)</enum><text>a small business;</text></subparagraph><subparagraph id="HC4470F1E5F574663B4169AE3CFD91D3D"><enum>(B)</enum><text>a small governmental jurisdiction; and</text></subparagraph><subparagraph id="H7FF25F94696842178EC8333C0E985C9C"><enum>(C)</enum><text>a small organization.</text></subparagraph></paragraph><paragraph id="H72DDF19A488A459C9FC2DF858A472EFA"><enum>(9)</enum><header>Small governmental jurisdiction</header><text>The term <term>small governmental jurisdiction</term> means governments of cities, counties, towns, townships, villages, school districts, or special districts with a population of less than 50,000. </text></paragraph><paragraph id="H9AD236779AF44C4D826E588443E22355"><enum>(10)</enum><header>Small organization</header><text>The term <term>small organization</term> means any not-for-profit enterprise that is independently owned and operated and is not dominant in its field. </text></paragraph></subsection><subsection id="H8DDBE2EE046841B28CD49808664D7411"><enum>(b)</enum><header>Annual cybersecurity report</header><paragraph id="H0D739B7F0FDA4B719D9650B600F015C3"><enum>(1)</enum><header>In general</header><text>Not later than 180 days after the date of enactment of this section, and not less frequently than annually thereafter, the Director shall publish a report for small entities that documents and promotes evidence-based cybersecurity policies and controls for use by small entities, which shall—</text><subparagraph id="H615222773E9A44C8B6DF5DCE200838FD"><enum>(A)</enum><text>include basic controls that have the most impact in protecting small entities against common cybersecurity threats and risks;</text></subparagraph><subparagraph id="H342A52BEB44E49EB820F7A98E6888E7B"><enum>(B)</enum><text>include protocols and policies to address common cybersecurity threats and risks posed by electronic devices, regardless of whether the electronic devices are—</text><clause id="H3BC7CBCB8CEF454182E6D38BCD1055F3"><enum>(i)</enum><text>issued by the small entity to employees and contractors of the small entity; or </text></clause><clause id="H3DC8D37EF08E47D186BE43330714D243"><enum>(ii)</enum><text>personal to the employees and contractors of the small entity; and</text></clause></subparagraph><subparagraph id="H5D19AEBAB9A94A91B274DF5C28370FD3"><enum>(C)</enum><text>recommend, as practicable—</text><clause id="H3D86A21048BB4E69AED04CCB6AD8F7C0"><enum>(i)</enum><text>measures to improve the cybersecurity of small entities; and</text></clause><clause id="H17C51C86BF9D443AA6F52B049D2818B3"><enum>(ii)</enum><text>configurations and settings for some of the most commonly used software that can improve the cybersecurity of small entities.</text></clause></subparagraph></paragraph><paragraph id="HCABBFC91EFBE472189EB062BCA3039F7"><enum>(2)</enum><header>Existing recommendations</header><text>The Director shall ensure that each annual cybersecurity report published under paragraph (1) incorporates—</text><subparagraph id="H11455566817B4885861847FA57C39CBB"><enum>(A)</enum><text>cybersecurity resources developed by NIST, as required by the NIST Small Business Cybersecurity Act (<external-xref legal-doc="public-law" parsable-cite="pl/115/236">Public Law 115–236</external-xref>); and</text></subparagraph><subparagraph id="H1CF5A82382214A67BBEB575B63F200D7"><enum>(B)</enum><text>the most recent version of the Cybersecurity Framework, or successor resource, maintained by NIST.</text></subparagraph></paragraph><paragraph id="H8855FFF2D00E4AA9A15C7D74AE1C4CE0"><enum>(3)</enum><header>Consideration for specific types of small entities</header><text>The Director may include and prioritize the development of cybersecurity recommendations, as required under paragraph (1), appropriate for specific types of small entities in addition to recommendations applicable for all small entities.</text></paragraph><paragraph id="H4F4DE7AFDA4248109E74D2D1CBF72482"><enum>(4)</enum><header>Consultation</header><text>In publishing the annual cybersecurity report under paragraph (1), the Director shall, to the degree practicable and as appropriate, consult with—</text><subparagraph id="HD841157A89C4443BA06466134ADCA97B"><enum>(A)</enum><text>the Administrator, the Secretary of Commerce, the Commission, and the Director of NIST;</text></subparagraph><subparagraph id="H725132D96EB64D539A87725E96CC4EDD"><enum>(B)</enum><text>small entities, insurers, State governments, companies that work with small entities, and academic and Federal and non-Federal experts in cybersecurity; and</text></subparagraph><subparagraph id="H945D4F3DE73841B89F489A87C2AD7F16"><enum>(C)</enum><text>any other entity as determined appropriate by the Director.</text></subparagraph></paragraph></subsection><subsection id="H8CC324C6115445349A0DB80802CABD81"><enum>(c)</enum><header>Promotion of annual cybersecurity report for small businesses</header><paragraph id="H2C5A293BB67B41BE83A029B37D6B6371"><enum>(1)</enum><header>Publication</header><text>The annual cybersecurity report, and previous versions of the report as appropriate, published under subsection (b)(1) shall be—</text><subparagraph id="HA165D5B733244D7AA62FD90BC300AB9F"><enum>(A)</enum><text>made available, prominently and free of charge, on the public website of the Agency; and</text></subparagraph><subparagraph id="HA1245B5CD192413BA06670C14C5E9E04"><enum>(B)</enum><text>linked to from relevant portions of the websites of the Administration and the Minority Business Development Agency, as determined by the Administrator and the Director of the Minority Business Development Agency, respectively.</text></subparagraph></paragraph><paragraph id="H3E4EA8B16CD64761A86476FA9087AB46"><enum>(2)</enum><header>Promotion generally</header><text>The Director, the Administrator, and the Secretary of Commerce shall, to the degree practicable, promote the annual cybersecurity report through relevant resources that are intended for or known to be regularly used by small entities, including agency documents, websites, and events.</text></paragraph></subsection><subsection id="H9DEE9027091D4322896D769E7E93327C"><enum>(d)</enum><header>Training and technical assistance</header><text>The Director, the Administrator, and the Director of the Minority Business Development Agency shall make available to employees of small entities voluntary training and technical assistance on how to implement the recommendations of the annual cybersecurity report.</text></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block></paragraph><paragraph id="HB73E171E4E06462495EEE7980AE32A56"><enum>(2)</enum><header>Technical and conforming amendment</header><text>The table of contents in section 1(b) of the Homeland Security Act of 2002 (Public 107–296; 116 Stat. 2135) is amended by inserting after the item relating to section 2220C the following:</text><quoted-block style="OLC" id="HCD6F0DE0D90F45A298C2F5CAC533AFFA"><toc><toc-entry level="section" idref="H62E47225FCFC4C41B21B0AA11391CB8D">Sec. 2220D. Annual cybersecurity report for small entities.</toc-entry></toc><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></subsection><subsection id="HECB9942639B2444687CD0DE863EEFDA6"><enum>(c)</enum><header>Report to Congress</header><paragraph id="HB490CE9EF3F644C2A57156F9433F32C4"><enum>(1)</enum><header>In general</header><text>Not later than 1 year after the date of enactment of this Act, and annually thereafter for 10 years, the Secretary shall submit to Congress a report describing methods to improve the cybersecurity of small entities, including through the adoption of policies, controls, and classes of products and services that have been demonstrated to reduce cybersecurity risk.</text></paragraph><paragraph id="HB6010E037B3A4761A1D97E343DD69C34"><enum>(2)</enum><header>Matters to be included</header><text>The report required under paragraph (1) shall—</text><subparagraph id="HA10479C464B04106915C29EEEA858D89"><enum>(A)</enum><text>identify barriers or challenges for small entities in purchasing or acquiring classes of products and services that promote the cybersecurity of small entities;</text></subparagraph><subparagraph id="H594AD0A11C70488791B7E1A5AC2370F8"><enum>(B)</enum><text>assess market availability, market pricing, and affordability of classes of products and services that promote the cybersecurity of small entities, with particular attention to identifying high-risk and underserved sectors or regions;</text></subparagraph><subparagraph id="HF97BF172E2B74B4F997C1CDA3D428D4F"><enum>(C)</enum><text>estimate the costs and benefits of policies that promote the cybersecurity of small entities, including—</text><clause id="HC19C743B61F846E5B04E6A9331A9A8B5"><enum>(i)</enum><text>tax breaks;</text></clause><clause id="H82198BEC33824E8F95D41D38E51BE7B6"><enum>(ii)</enum><text>grants and subsidies; and</text></clause><clause id="H2DBA7DE416A9428EA801E1F6B1C5ED42"><enum>(iii)</enum><text>other incentives as determined appropriate by the Secretary;</text></clause></subparagraph><subparagraph id="H9DE95EA995C74CA69927830F42ABEB2C"><enum>(D)</enum><text>describe evidence-based cybersecurity controls and policies that improve the cybersecurity of small entities;</text></subparagraph><subparagraph id="HD329470E661C4324AE0C43728B29C451"><enum>(E)</enum><text>with respect to the incentives described in subparagraph (C), recommend measures that can effectively improve cybersecurity at scale for small entities; and</text></subparagraph><subparagraph id="HE4F6B7AAD4034AF6BA25B0452CBB7127"><enum>(F)</enum><text>include any other matters as the Secretary determines relevant.</text></subparagraph></paragraph><paragraph id="HFDD0BC0CD197431BA079C8A53F137CAB"><enum>(3)</enum><header>Specific sectors of small entities</header><text>In preparing the report required under paragraph (1), the Secretary may include matters applicable for specific sectors of small entities in addition to matters applicable to all small entities.</text></paragraph><paragraph id="H95C391C2E2D14130B2FFB860BCA32D2E"><enum>(4)</enum><header>Consultation</header><text>In preparing the report required under paragraph (1), the Secretary shall consult with—</text><subparagraph id="HE9C3F0F65A3B4C8DB07BBA9A71AB9B14"><enum>(A)</enum><text>the Administrator, the Director of CISA, and the Commission; and</text></subparagraph><subparagraph id="H7B1FC7C233AA494886F51F2D008F7847"><enum>(B)</enum><text>small entities, insurers of risks related to cybersecurity, State governments, cybersecurity and information technology companies that work with small entities, and academic and Federal and non-Federal experts in cybersecurity.</text></subparagraph></paragraph></subsection><subsection id="H558BF87E0AC94EADA2DFC61D79B3085F"><enum>(d)</enum><header>Periodic census on state of cybersecurity of small businesses</header><paragraph id="HF7C0082C288742DFBACA5792177ADEC2"><enum>(1)</enum><header>In general</header><text>Not later than 1 year after the date of enactment of this Act, and not less frequently than every 24 months thereafter for 10 years, the Administrator shall submit to Congress and make publicly available data on the state of cybersecurity of small businesses, including, to the extent practicable—</text><subparagraph id="H449E937F4F664C76A3D0A2CF7AB3C699"><enum>(A)</enum><text>adoption of the cybersecurity recommendations from the annual cybersecurity report among small businesses;</text></subparagraph><subparagraph id="H5DA1BA9DD0924DA0A87B5588491E9D4B"><enum>(B)</enum><text>the most significant and widespread cybersecurity threats facing small businesses;</text></subparagraph><subparagraph id="H405C34EC97D946A9915C9765C3091E14"><enum>(C)</enum><text>the amount small businesses spend on cybersecurity products and services; and</text></subparagraph><subparagraph id="H0C1F650547624B2A84585C27253542B1"><enum>(D)</enum><text>the personnel small businesses dedicate to cybersecurity, including the amount of total personnel time, whether by employees or contractors, dedicated to cybersecurity efforts.</text></subparagraph></paragraph><paragraph id="H3D8E8D91FDD54178A9B8C475F055A8A7"><enum>(2)</enum><header>Voluntary participation</header><text>In carrying out paragraph (1), the Administrator shall collect data from small businesses that participate on a voluntary basis. </text></paragraph><paragraph id="HD4C09393EE6848568969D86635466DC6"><enum>(3)</enum><header>Form</header><text>The data required under paragraph (1) shall be produced in unclassified form but may contain a classified annex.</text></paragraph><paragraph id="H1CA887FD1D01430AA97F1CF1CA76ED30"><enum>(4)</enum><header>Consultation</header><text>In preparing to collect the data required under paragraph (1), the Administrator shall consult with—</text><subparagraph id="HB4C479CEB2B04FFFB7B6ACD5D074E356"><enum>(A)</enum><text>the Secretary, the Director of CISA, and the Commission; and</text></subparagraph><subparagraph id="H6E8E626CCCB3496795A273D6BFD341D8"><enum>(B)</enum><text>small businesses, insurers of risks related to cybersecurity, cybersecurity and information technology companies that work with small businesses, and academic and Federal and non-Federal experts in cybersecurity. </text></subparagraph></paragraph><paragraph id="H21FB3E9917A94809B7989A1CB447E442"><enum>(5)</enum><header>Privacy</header><text>In carrying out this subsection, the Administrator shall ensure that any publicly available data is anonymized and does not reveal personally identifiable information. </text></paragraph></subsection><subsection id="H01AA686B062340158CA6B0A6086636EF"><enum>(e)</enum><header>Rule of construction</header><text>Nothing in this section or the amendments made by this section shall be construed to provide any additional regulatory authority to CISA.</text></subsection></section></legis-body></bill> 

