|
119th CONGRESS
2d Session |
To require the Administrator of the Small Business Administration to disseminate to small business concerns certain information and resources relating to cybersecurity matters, and for other purposes.
Mr. Wied (for himself, Ms. King-Hinds, and Ms. Van Duyne) introduced the following bill; which was referred to the Committee on Small Business
To require the Administrator of the Small Business Administration to disseminate to small business concerns certain information and resources relating to cybersecurity matters, and for other purposes.
Be it enacted by the Senate and House of Representatives of the United States of America in Congress assembled,
This Act may be cited as the “Cybersecurity for Small Businesses Act of 2026”.
SEC. 2. Information and resources relating to cybersecurity matters for small business concerns.
The Administrator of the Small Business Administration, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, shall develop and disseminate information and resources to assist small business concerns in strengthening the cybersecurity infrastructure of such concerns and implementing cybersecurity best practices.
SEC. 3. Cybersecurity compliance information.
(a) Cybersecurity compliance resources.—The Administrator of the Small Business Administration, in coordination with the Secretary of Defense and other appropriate Federal agencies, shall disseminate information to a small business concern seeking to enter into a contract with the Federal Government, or seeking to be a subcontractor on a Federal contract, regarding the Cybersecurity Maturity Model Certification program (or successor program), including information necessary to facilitate compliance with such requirements, through small business development centers (as defined in section 3 of the Small Business Act (15 U.S.C. 632)) and district offices of the Administration.
(b) Publication.—The Administrator shall include the information described in subsection (a) in outreach and communications of the Small Business Administration, including through publication on a website of the Administration.
(c) Best practices.—The Administrator shall annually consult with the Chief Counsel for Advocacy of the Office of Advocacy of the Administration to determine best practices for the dissemination of other information relating to cybersecurity matters to small business concerns.
(d) Annual report.—Not later than 90 days after the date of the enactment of this Act, and annually thereafter, the Chief Counsel for Advocacy shall submit to Congress a report that includes the number and a description of small business concerns that contacted the Chief Counsel for Advocacy during the year covered by the report with matters relating to cybersecurity of such concerns.