[Congressional Record Volume 171, Number 200 (Monday, December 1, 2025)]
[House]
[Pages H4913-H4914]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]




                   SBA IT MODERNIZATION REPORTING ACT

  Mr. WILLIAMS of Texas. Mr. Speaker, I move to suspend the rules and 
pass the bill (H.R. 4491) to require the Administrator of the Small 
Business Administration to implement certain recommendations relating 
to information technology modernization, and for other purposes.
  The Clerk read the title of the bill.
  The text of the bill is as follows:

                               H.R. 4491

       Be it enacted by the Senate and House of Representatives of 
     the United States of America in Congress assembled,

     SECTION 1. SHORT TITLE.

       This Act may be cited as the ``SBA IT Modernization 
     Reporting Act''.

     SEC. 2. IMPLEMENTATION OF RECOMMENDATIONS RELATING TO 
                   INFORMATION TECHNOLOGY MODERNIZATION FOR THE 
                   SMALL BUSINESS ADMINISTRATION.

       (a) In General.--The Administrator of the Small Business 
     Administration, acting through the Chief Information Officer 
     of the Administration, shall take such actions as may be 
     necessary to implement the recommendations contained in the 
     report of the Comptroller General of the United States titled 
     ``IT MODERNIZATION: SBA Urgently

[[Page H4914]]

     Needs to Address Risks on Newly Deployed System'' (GAO-25-
     106963; published November 6, 2024).
       (b) Implementation Plan.--Not later than 180 days after the 
     date of the enactment of this Act, the Administrator shall 
     submit to the Committee on Small Business of the House of 
     Representatives and the Committee on Small Business and 
     Entrepreneurship of the Senate an implementation plan 
     detailing the actions the Small Business Administration will 
     undertake to establish and implement policies and procedures 
     to govern information technology modernization projects of 
     the Administration. Such policies and procedures shall, with 
     respect to each project--
       (1) for each risk identified, explicitly state the source 
     of such risk in the relevant risk documentation;
       (2) clearly define risk parameters;
       (3) establish and maintain risk management strategies;
       (4) identify and document risks for all phases of the life 
     cycle;
       (5) evaluate, categorize, and prioritize risks based on 
     defined risk parameters and develop project risk management 
     plans;
       (6) connect measures to mitigate risk to risk mitigation 
     plans;
       (7) require that any information technology acquisition 
     plan and any strategic plan contains information needed to 
     manage cyber risks;
       (8) require that a traceability analysis is performed and 
     documented;
       (9) require that security-related subject matter experts 
     are involved in selection process for contractors for a 
     project;
       (10) develop master schedules using the guidelines 
     contained in the publication of the Comptroller General 
     titled ``GAO Schedule Assessment Guide: Best Practices for 
     Project Schedules'' (GAO-16-89G; published December 22, 
     2015); and
       (11) develop cost estimates using the guidelines contained 
     in the publication of the Comptroller General titled ``Cost 
     Estimating and Assessment Guide: Best Practices for 
     Developing and Managing Program Costs'' (GAO-20-195G; 
     published March 12, 2020).
       (c) Additional Requirements.--The implementation plan 
     required by this section shall include the actions required 
     to carry out the requirements listed in paragraphs (1) 
     through (11) of subsection (b), an identification of the 
     office of the Administration responsible for implementation, 
     and the timelines for completion of each action.
       (d) Briefing Required.--Not later than 30 days after the 
     submission of the implementation plan required under this 
     section, the Administrator shall provide to the Committee on 
     Small Business of the House of Representatives and the 
     Committee on Small Business and Entrepreneurship of the 
     Senate a briefing on the plan.

  The SPEAKER pro tempore. Pursuant to the rule, the gentleman from 
Texas (Mr. Williams) and the gentleman from California (Mr. Cisneros) 
each will control 20 minutes.
  The Chair recognizes the gentleman from Texas.


                             General Leave

  Mr. WILLIAMS of Texas. Mr. Speaker, I ask unanimous consent that all 
Members may have 5 legislative days in which to revise and extend their 
remarks and include extraneous material on the bill.
  The SPEAKER pro tempore. Is there objection to the request of the 
gentleman from Texas?
  There was no objection.
  Mr. WILLIAMS of Texas. Mr. Speaker, I yield myself such time as I may 
consume.
  Mr. Speaker, I rise today in support of H.R. 4491, the SBA IT 
Modernization Reporting Act, introduced by Representative Cisneros from 
the great State of California and Representative Jack from the great 
State of Georgia.
  The SBA is charged with certifying small businesses to participate in 
certain government contract opportunities.

                              {time}  1420

  Last year, the Biden-Harris SBA sought to implement a new 
certification portal. Unfortunately, this portal's lackluster planning, 
creation, and rollout left the SBA with a ticking time bomb.
  The Biden administration's failed Unified Certification Portal 
rollout resulted in delays, errors, and cybersecurity risks, shutting 
out small businesses from vital government contracting opportunities.
  While this committee shared bipartisan concerns with the Biden-Harris 
SBA over its rollout plan, or lack thereof, former Administrator Guzman 
failed to listen, and the results were damaging. Small businesses were 
delayed for months, sometimes longer, to get approval from the SBA to 
compete for governmental contracts.
  To make matters worse, the SBA allowed small businesses to use the 
new portal without conducting minimum cyber threat assessments. 
Entrepreneurs didn't just face delays, but their sensitive personal and 
business information was put at risk of cybercrime.
  The SBA IT Modernization Reporting Act ensures that this will not 
happen at the SBA again. This bill requires the SBA to implement the 
GAO's recommendations to establish stronger safeguards and improve 
oversight of IT initiatives so small businesses can rely on an 
efficient contract certification system.
  Small businesses should not be held back by government mismanagement. 
This bipartisan, commonsense bill restores accountability and helps 
Main Street focus on what it does best--innovate.
  Mr. Speaker, I urge my colleagues to support this bill, and I reserve 
the balance of my time.
  Mr. CISNEROS. Mr. Speaker, I yield myself such time as I may consume.
  I rise today in support of my bill, the SBA IT Modernization 
Reporting Act, and I thank the chairman for his support. I also thank 
Representative Jack for joining me in introducing this bill, which will 
go a long way to help SBA modernize its IT infrastructure and improve 
its services to small businesses.
  Billions of dollars in Federal contracts are awarded to small 
businesses every year, and the SBA plays a vital role in promoting 
small business participation; however, over the years the SBA's 
outdated and inefficient IT systems have made it harder for 
entrepreneurs to access the resources they need.
  After repeated unsuccessful attempts to develop and deploy a platform 
that would be a one-stop-shop for contracting certifications, the 
committee requested the GAO review the SBA's efforts to figure out why 
they failed. The report identified the critical gaps in the SBA's 
modernization efforts from risk management to cybersecurity and 
budgeting.
  My bill directly addresses these issues by requiring the SBA 
administrator to implement the 11 recommendations in the GAO report, 
mandating a clear plan of action and ensuring Congress is kept in the 
loop. This means better oversight, better execution, and most 
importantly, better services by the SBA for all small businesses.
  An efficient and fully operational IT platform is critical for the 
SBA to conduct the certifications that allow for so many small 
businesses to participate in the Federal marketplace. The SBA IT 
Modernization Reporting Act will ensure that the SBA addresses the root 
causes that lead IT projects to fall behind schedule, increasing costs, 
or outright fail.
  I am grateful for the partnership of Representative Jack to introduce 
this commonsense, bipartisan legislation which shows that modernizing 
how the SBA works is not a partisan issue. Together, we can ensure that 
the SBA is prepared to meet the evolving needs of small businesses.
  Mr. Speaker, I urge my colleagues to support this bill to ensure we 
give the SBA the modern tools it needs to support the success of 
America's small businesses.
  Mr. Speaker, I close by once again thanking my colleague 
Representative Jack for partnering with me on this important 
legislation.
  By bolstering SBA's IT infrastructure, we can improve services to 
small businesses and open up doors to thousands of new entrants in the 
Federal marketplace. I encourage my colleagues to support this 
legislation, and I yield back the balance of my time.
  Mr. WILLIAMS of Texas. Mr. Speaker, I urge my colleagues to support 
this commonsense legislation to protect both the SBA and small 
businesses alike. I yield back the balance of my time.
  The SPEAKER pro tempore. The question is on the motion offered by the 
gentleman from Texas (Mr. Williams) that the House suspend the rules 
and pass the bill, H.R. 4491.
  The question was taken; and (two-thirds being in the affirmative) the 
rules were suspended and the bill was passed.
  A motion to reconsider was laid on the table.

                          ____________________