<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-type="olc" bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-MIR26739-C73-D6-NJW"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>119 S5291 IS: Small Business Cybersecurity Assistance Evaluation Act of 2026</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2026-08-06</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>119th CONGRESS</congress><session>2d Session</session><legis-num>S. 5291</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20260806">August 6, 2026</action-date><action-desc><sponsor name-id="S427">Mr. Schiff</sponsor> (for himself and <cosponsor name-id="S391">Mr. Young</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSSB00">Committee on Small Business and Entrepreneurship</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To require the Comptroller General to evaluate Federal cybersecurity assistance to small business concerns, and for other purposes.</official-title></form><legis-body style="OLC" display-enacting-clause="yes-display-enacting-clause" id="H8259ADE537044C3AA08E36AD80DCD110"><section section-type="section-one" id="HB9E7E29543C743EA81651317EA82E2AF"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Small Business Cybersecurity Assistance Evaluation Act of 2026</short-title></quote>.</text></section><section id="H1599092523444E49B476F5FB3D53A73F"><enum>2.</enum><header>GAO study on small business cybersecurity assistance</header><subsection commented="no" display-inline="no-display-inline" id="id421f58c2e2b44c47af395a4a80dff73a"><enum>(a)</enum><header display-inline="yes-display-inline">Small business concern defined</header><text>In this section, the term <term>small business concern</term> has the meaning given the term in section 3 of the Small Business Act (<external-xref legal-doc="usc" parsable-cite="usc/15/632">15 U.S.C. 632</external-xref>).</text></subsection><subsection id="HDE77FED5CE444DCD9D825E86317BB3A8"><enum>(b)</enum><header>Study</header><text display-inline="yes-display-inline">The Comptroller General of the United States shall conduct a study of available Federal cybersecurity initiatives, programs, resources, tools, and services intended to assist owners of small business concerns with—</text><paragraph id="HA1671D477EE24E2CBB9C0FA04C62E941"><enum>(1)</enum><text>identifying cyber risks, cyber threats, and cybersecurity vulnerabilities relating to small business concerns;</text></paragraph><paragraph id="H9A1C623958A44A6CA8BED6316004637E"><enum>(2)</enum><text>assessing the preparedness of small business concerns for the risks, threats, and vulnerabilities described in paragraph (1);</text></paragraph><paragraph id="H27443A0EB8614831A74597A2800EC7DF"><enum>(3)</enum><text>planning for, mitigating, and recovering from cyber attacks and incidents of social engineering, scams, and fraud, including developing, adopting, and implementing cybersecurity measures, training, protocols, tools, and infrastructure; and</text></paragraph><paragraph id="HEED829EA617D48A6BE1485F9409E415F"><enum>(4)</enum><text>identifying sources of capital, or obtaining capital, to carry out the activities described in paragraphs (1), (2), and (3).</text></paragraph></subsection><subsection id="H70E1C4A60DFD4F8CBA8DE3837D33060A"><enum>(c)</enum><header>Required content</header><text>The study required under subsection (b) shall include—</text><paragraph id="H4F20A7BDF6CE448093FCBFFF3DAB61B6"><enum>(1)</enum><text>information on the most common cyberattacks affecting small business concerns;</text></paragraph><paragraph commented="no" id="HC97B78010BEC44F098912FFAD9329C75"><enum>(2)</enum><text>an identification and description of the Federal cybersecurity initiatives, programs, resources, tools, and services included in the study;</text></paragraph><paragraph id="HE62D4127195F4697A2E5022F13696842"><enum>(3)</enum><text>an assessment of the awareness and use of those Federal cybersecurity initiatives, programs, resources, tools, and services by small business concerns and reasons for differences in levels of such awareness and use;</text></paragraph><paragraph id="HDE3A24390FC94FDCA3517438BF9EDCE8"><enum>(4)</enum><text display-inline="yes-display-inline">an assessment of the coordination and integration among those Federal cybersecurity initiatives, programs, resources, tools, and services;</text></paragraph><paragraph id="HB07172E91743468D90788B3E20837476"><enum>(5)</enum><text display-inline="yes-display-inline">an assessment of the effectiveness of those Federal cybersecurity initiatives, programs, resources, tools, and services in assisting small business concerns with the activities described in paragraphs (1) through (4) of subsection (b);</text></paragraph><paragraph id="H42FA6E1587BE447196AC7224C5F52D41"><enum>(6)</enum><text display-inline="yes-display-inline">an identification of any foundational cybersecurity concepts absent from those Federal cybersecurity initiatives, programs, resources, tools, and services; and</text></paragraph><paragraph id="H1FC611766486496E8141B0008B92EF55"><enum>(7)</enum><text>recommendations on how to improve the effectiveness, awareness, and coordination of those Federal cybersecurity initiatives, programs, resources, tools, and services for small business concerns.</text></paragraph></subsection><subsection id="HBF215C2A35244951B30D0C7EE3AF3492"><enum>(d)</enum><header>Report</header><text display-inline="yes-display-inline">The Comptroller General of the United States shall submit to the Committee on Small Business and Entrepreneurship of the Senate and the Committee on Small Business of the House of Representatives a report containing all findings and determinations made in carrying out the study required under subsection (b).</text></subsection><subsection id="H618C4EE8D392410CAD5AA1DAB3D9F893"><enum>(e)</enum><header>No additional funds</header><text display-inline="yes-display-inline">No additional amounts are authorized to carry out this Act.</text></subsection></section></legis-body></bill>

