<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" dms-id="H64BB0B8D556C48E89CB71E9476498E7D" public-private="public" key="H" bill-type="olc"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>119 HR 8880 IH: Small Business Cybersecurity Assistance Evaluation Act of 2026</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2026-05-19</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress display="yes">119th CONGRESS</congress><session display="yes">2d Session</session><legis-num display="yes">H. R. 8880</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20260519">May 19, 2026</action-date><action-desc><sponsor name-id="S001231">Ms. Simon</sponsor> (for herself and <cosponsor name-id="B001327">Mr. Bresnahan</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HSM00">Committee on Small Business</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To require the Comptroller General to evaluate Federal cybersecurity assistance to small business concerns, and for other purposes.</official-title></form><legis-body id="H8259ADE537044C3AA08E36AD80DCD110" style="OLC"> 
<section id="HB9E7E29543C743EA81651317EA82E2AF" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Small Business Cybersecurity Assistance Evaluation Act of 2026</short-title></quote>.</text></section> <section id="H1599092523444E49B476F5FB3D53A73F"><enum>2.</enum><header>GAO study on small business cybersecurity assistance</header> <subsection id="HDE77FED5CE444DCD9D825E86317BB3A8"><enum>(a)</enum><header>Study</header><text display-inline="yes-display-inline">The Comptroller General of the United States shall conduct a study of current Federal cybersecurity initiatives, programs, resources, tools, and services intended to assist owners of small business concerns (as defined under section 3 of the Small Business Act (<external-xref legal-doc="usc" parsable-cite="usc/15/632">15 U.S.C. 632</external-xref>)) with—</text> 
<paragraph id="HA1671D477EE24E2CBB9C0FA04C62E941"><enum>(1)</enum><text>identifying cyber risks, cyber threats, and cybersecurity vulnerabilities relating to such concerns;</text></paragraph> <paragraph id="H9A1C623958A44A6CA8BED6316004637E"><enum>(2)</enum><text>assessing the preparedness of such concerns for such risks, threats, and vulnerabilities;</text></paragraph> 
<paragraph id="H27443A0EB8614831A74597A2800EC7DF"><enum>(3)</enum><text>planning for, mitigating, and recovering from cyberattacks and incidents of social engineering, scams, and fraud (including developing, adopting, and implementing cybersecurity measures, training, protocols, tools, and infrastructure); and</text></paragraph> <paragraph id="HEED829EA617D48A6BE1485F9409E415F"><enum>(4)</enum><text>identifying sources of capital, or obtaining capital, to carry out the activities specified in paragraphs (1), (2), and (3).</text> </paragraph></subsection> 
<subsection id="H70E1C4A60DFD4F8CBA8DE3837D33060A"><enum>(b)</enum><header>Required content</header><text>The study required by subsection (a) shall include—</text> <paragraph id="H4F20A7BDF6CE448093FCBFFF3DAB61B6"><enum>(1)</enum><text>information on the most common cyberattacks affecting small business concerns;</text></paragraph> 
<paragraph id="HC97B78010BEC44F098912FFAD9329C75" commented="no"><enum>(2)</enum><text>an identification and description of the Federal cybersecurity initiatives, programs, resources, tools, and services included in the study described in subsection (a);</text></paragraph> <paragraph id="HE62D4127195F4697A2E5022F13696842"><enum>(3)</enum><text>an assessment of the awareness and use of such Federal cybersecurity initiatives, programs, resources, tools, and services by small business concerns and reasons for differences in levels of such awareness and use;</text></paragraph> 
<paragraph id="HDE3A24390FC94FDCA3517438BF9EDCE8"><enum>(4)</enum><text display-inline="yes-display-inline">an assessment of the coordination and integration among such Federal cybersecurity initiatives, programs, resources, tools, and services;</text></paragraph> <paragraph id="HB07172E91743468D90788B3E20837476"><enum>(5)</enum><text display-inline="yes-display-inline">an assessment of the effectiveness of such Federal cybersecurity initiatives, programs, resources, tools, and services in assisting small business concerns with the activities listed in paragraphs (1) through (4) of subsection (a);</text></paragraph> 
<paragraph id="H42FA6E1587BE447196AC7224C5F52D41"><enum>(6)</enum><text display-inline="yes-display-inline">an identification of any foundational cybersecurity concepts absent from such Federal cybersecurity initiatives, programs, resources, tools, and services; and</text></paragraph> <paragraph id="H1FC611766486496E8141B0008B92EF55"><enum>(7)</enum><text>recommendations on how to improve the effectiveness, awareness, and coordination of such Federal cybersecurity initiatives, programs, resources, tools, and services for small business concerns.</text></paragraph></subsection> 
<subsection id="HBF215C2A35244951B30D0C7EE3AF3492"><enum>(c)</enum><header>Report</header><text display-inline="yes-display-inline">The Comptroller General shall submit to the Committee on Small Business of the House of Representatives and the Committee on Small Business and Entrepreneurship of the Senate a report containing all findings and determinations made in carrying out the study required under subsection (a).</text></subsection> </section> <section id="H618C4EE8D392410CAD5AA1DAB3D9F893"><enum>3.</enum><header>Compliance with CUTGO</header><text display-inline="no-display-inline">No additional amounts are authorized to carry out this Act.</text></section> 
</legis-body></bill>

