|
119th CONGRESS
2d Session |
To require the Comptroller General to evaluate Federal cybersecurity assistance to small business concerns, and for other purposes.
Mr. Schiff (for himself and Mr. Young) introduced the following bill; which was read twice and referred to the Committee on Small Business and Entrepreneurship
To require the Comptroller General to evaluate Federal cybersecurity assistance to small business concerns, and for other purposes.
Be it enacted by the Senate and House of Representatives of the United States of America in Congress assembled,
This Act may be cited as the “Small Business Cybersecurity Assistance Evaluation Act of 2026”.
SEC. 2. GAO study on small business cybersecurity assistance.
(a) Small business concern defined.—In this section, the term “small business concern” has the meaning given the term in section 3 of the Small Business Act (15 U.S.C. 632).
(b) Study.—The Comptroller General of the United States shall conduct a study of available Federal cybersecurity initiatives, programs, resources, tools, and services intended to assist owners of small business concerns with—
(1) identifying cyber risks, cyber threats, and cybersecurity vulnerabilities relating to small business concerns;
(2) assessing the preparedness of small business concerns for the risks, threats, and vulnerabilities described in paragraph (1);
(3) planning for, mitigating, and recovering from cyber attacks and incidents of social engineering, scams, and fraud, including developing, adopting, and implementing cybersecurity measures, training, protocols, tools, and infrastructure; and
(4) identifying sources of capital, or obtaining capital, to carry out the activities described in paragraphs (1), (2), and (3).
(c) Required content.—The study required under subsection (b) shall include—
(1) information on the most common cyberattacks affecting small business concerns;
(2) an identification and description of the Federal cybersecurity initiatives, programs, resources, tools, and services included in the study;
(3) an assessment of the awareness and use of those Federal cybersecurity initiatives, programs, resources, tools, and services by small business concerns and reasons for differences in levels of such awareness and use;
(4) an assessment of the coordination and integration among those Federal cybersecurity initiatives, programs, resources, tools, and services;
(5) an assessment of the effectiveness of those Federal cybersecurity initiatives, programs, resources, tools, and services in assisting small business concerns with the activities described in paragraphs (1) through (4) of subsection (b);
(6) an identification of any foundational cybersecurity concepts absent from those Federal cybersecurity initiatives, programs, resources, tools, and services; and
(7) recommendations on how to improve the effectiveness, awareness, and coordination of those Federal cybersecurity initiatives, programs, resources, tools, and services for small business concerns.
(d) Report.—The Comptroller General of the United States shall submit to the Committee on Small Business and Entrepreneurship of the Senate and the Committee on Small Business of the House of Representatives a report containing all findings and determinations made in carrying out the study required under subsection (b).
(e) No additional funds.—No additional amounts are authorized to carry out this Act.