<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-type="olc" bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-ELL26461-6SF-3M-9DN"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>119 S4948 IS: SBA IT Modernization Reporting Act</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2026-07-13</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>119th CONGRESS</congress><session>2d Session</session><legis-num>S. 4948</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20260713">July 13, 2026</action-date><action-desc><sponsor name-id="S427">Mr. Schiff</sponsor> (for himself and <cosponsor name-id="S431">Mr. Curtis</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSSB00">Committee on Small Business and Entrepreneurship</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To require the Administrator of the Small Business Administration to implement certain recommendations relating to information technology modernization, and for other purposes.</official-title></form><legis-body style="OLC" display-enacting-clause="yes-display-enacting-clause" id="HB8EDD8E53937433D99CAABD2423AD8D4"><section section-type="section-one" id="H762B2375504544DC99BB0E80CD075C6E"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>SBA IT Modernization Reporting Act</short-title></quote>.</text></section><section commented="no" display-inline="no-display-inline" id="id00203e4b1cb14689b07bd395c2bf70ee"><enum>2.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act, the terms <term>Administration</term> and <term>Administrator</term> mean the Small Business Administration and the Administrator thereof, respectively.</text></section><section id="HA3C1084836FB45558B56FEF3FA6CD686"><enum>3.</enum><header>Implementation of recommendations relating to information technology modernization for the Small Business Administration</header><subsection id="H85567B6B590B4CF19558FC8C2BDD330D"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">The Administrator, acting through the Chief Information Officer of the Administration, shall take such actions as may be necessary to implement the recommendations contained in the report of the Comptroller General of the United States titled <quote>IT MODERNIZATION: SBA Urgently Needs to Address Risks on Newly Deployed System</quote> (GAO–25–106963; published November 6, 2024).</text></subsection><subsection id="H4F23229008F84A92914027F68AB0BA01"><enum>(b)</enum><header>Implementation plan</header><text display-inline="yes-display-inline">Not later than 180 days after the date of enactment of this Act, the Administrator shall submit to the Committee on Small Business and Entrepreneurship of the Senate and the Committee on Small Business of the House of Representatives an implementation plan detailing the actions the Administration will undertake to establish and implement policies and procedures to govern information technology modernization projects of the Administration, which policies and procedures shall, with respect to each project—</text><paragraph id="H20F4C072AC604CE0B2BAF1DECF8471FE"><enum>(1)</enum><text display-inline="yes-display-inline">for each risk identified, explicitly state the source of such risk in the relevant risk documentation;</text></paragraph><paragraph id="HAFB02653FBBB43A58859D616D9C0DCF6"><enum>(2)</enum><text display-inline="yes-display-inline">clearly define risk parameters;</text></paragraph><paragraph id="HFB05E083B2784AC088AAD07BC0619971"><enum>(3)</enum><text>establish and maintain risk management strategies;</text></paragraph><paragraph commented="no" id="H18FE4EFCF3464EDFBB7BD2B539C46106"><enum>(4)</enum><text>identify and document risks for all phases of the life cycle;</text></paragraph><paragraph id="H0D74BAA99288421694E5C02E3A226EEC"><enum>(5)</enum><text>evaluate, categorize, and prioritize risks based on defined risk parameters and develop project risk management plans;</text></paragraph><paragraph commented="no" id="H0BAD671D288A49828534761CAD152C19"><enum>(6)</enum><text>connect measures to mitigate risk to risk mitigation plans;</text></paragraph><paragraph commented="no" id="H7669569D28244E2FAAA205317D10E5B5"><enum>(7)</enum><text>require that any information technology acquisition plan and any strategic plan contains information needed to manage cyber risks;</text></paragraph><paragraph commented="no" id="HC2D4E04E05A644E1A8752CC633550A6B"><enum>(8)</enum><text>require that a traceability analysis is performed and documented;</text></paragraph><paragraph commented="no" id="HDFB8C95553D54E8DB1B776B868C822A1"><enum>(9)</enum><text>require that security-related subject matter experts are involved in selection process for contractors for a project;</text></paragraph><paragraph id="H4220FDCF2A394DBE952C29F830A40A5F"><enum>(10)</enum><text>develop master schedules using the guidelines contained in the publication of the Comptroller General of the United States titled <quote>GAO Schedule Assessment Guide: Best Practices for Project Schedules</quote> (GAO–16–89G; published December 22, 2015); and</text></paragraph><paragraph id="HACC0041AE2794CC2AF1FE59FD7F13959"><enum>(11)</enum><text>develop cost estimates using the guidelines contained in the publication of the Comptroller General of the United States titled <quote>Cost Estimating and Assessment Guide: Best Practices for Developing and Managing Program Costs</quote> (GAO–20–195G; published March 12, 2020).</text></paragraph></subsection><subsection id="HD72B70B32924408D97A8C41C78F662E8"><enum>(c)</enum><header>Additional requirements</header><text display-inline="yes-display-inline">The implementation plan required under this section shall include the actions required to carry out the requirements listed in paragraphs (1) through (11) of subsection (b), an identification of the office of the Administration responsible for implementation, and the timelines for completion of each action.</text></subsection><subsection id="HEF60D65A91DF4EB592E2619552D29DD4"><enum>(d)</enum><header>Briefing required</header><text display-inline="yes-display-inline">Not later than 30 days after the submission of the implementation plan required under this section, the Administrator shall provide to the Committee on Small Business and Entrepreneurship of the Senate and the Committee on Small Business of the House of Representatives a briefing on the plan.</text></subsection></section></legis-body></bill>

