<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" dms-id="H56CD459F878D4E668C4B97BDD0276A32" public-private="public" key="H" bill-type="olc"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>119 HR 10238 IH: Cybersecurity for Small Businesses Act of 2026</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2026-09-02</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress display="yes">119th CONGRESS</congress><session display="yes">2d Session</session><legis-num display="yes">H. R. 10238</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20260902">September 2, 2026</action-date><action-desc><sponsor name-id="W000829">Mr. Wied</sponsor> (for himself, <cosponsor name-id="K000404">Ms. King-Hinds</cosponsor>, and <cosponsor name-id="V000134">Ms. Van Duyne</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HSM00">Committee on Small Business</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To require the Administrator of the Small Business Administration to disseminate to small business concerns certain information and resources relating to cybersecurity matters, and for other purposes.</official-title></form><legis-body id="H446ACA80229947F48D839743FC048953" style="OLC"> 
<section id="H32795CC54BE9413CBF00AA5A80DE664B" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Cybersecurity for Small Businesses Act of 2026</short-title></quote>.</text></section> <section id="H619AA0C462ED4040AEE5879DDA66BDDA" section-type="subsequent-section"><enum>2.</enum><header>Information and resources relating to cybersecurity matters for small business concerns</header> <text display-inline="no-display-inline">The Administrator of the Small Business Administration, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, shall develop and disseminate information and resources to assist small business concerns in strengthening the cybersecurity infrastructure of such concerns and implementing cybersecurity best practices.</text></section> 
<section id="H22EC1050A1824C84A0FF6D4B601CCACF"><enum>3.</enum><header>Cybersecurity compliance information</header> 
<subsection id="HC51B85A31EAC4B23BB0DA4E1EF9EB240"><enum>(a)</enum><header>Cybersecurity compliance resources</header><text display-inline="yes-display-inline">The Administrator of the Small Business Administration, in coordination with the Secretary of Defense and other appropriate Federal agencies, shall disseminate information to a small business concern seeking to enter into a contract with the Federal Government, or seeking to be a subcontractor on a Federal contract, regarding the Cybersecurity Maturity Model Certification program (or successor program), including information necessary to facilitate compliance with such requirements, through small business development centers (as defined in section 3 of the Small Business Act (<external-xref legal-doc="usc" parsable-cite="usc/15/632">15 U.S.C. 632</external-xref>)) and district offices of the Administration.</text></subsection> <subsection id="H263660D2911B4DA19DF8E274340BFA2A"><enum>(b)</enum><header>Publication</header><text display-inline="yes-display-inline">The Administrator shall include the information described in subsection (a) in outreach and communications of the Small Business Administration, including through publication on a website of the Administration.</text> </subsection> 
<subsection id="H08168266E63A4EE58D431B2DA7669904"><enum>(c)</enum><header>Best practices</header><text display-inline="yes-display-inline">The Administrator shall annually consult with the Chief Counsel for Advocacy of the Office of Advocacy of the Administration to determine best practices for the dissemination of other information relating to cybersecurity matters to small business concerns.</text></subsection> <subsection id="H515C527661154025B829C52198895B20"><enum>(d)</enum><header>Annual report</header><text display-inline="yes-display-inline">Not later than 90 days after the date of the enactment of this Act, and annually thereafter, the Chief Counsel for Advocacy shall submit to Congress a report that includes the number and a description of small business concerns that contacted the Chief Counsel for Advocacy during the year covered by the report with matters relating to cybersecurity of such concerns.</text></subsection></section> 
</legis-body></bill>

