[House Report 119-679]
[From the U.S. Government Publishing Office]
119th Congress } { Report
HOUSE OF REPRESENTATIVES
2d Session } { 119-679
======================================================================
SMALL BUSINESS CYBERSECURITY ASSISTANCE EVALUATION ACT OF 2026
_______
June 3, 2026.--Committed to the Committee of the Whole House on the
State of the Union and ordered to be printed
_______
Mr. Williams of Texas, from the Committee on Small Business, submitted
the following
R E P O R T
together with
MINORITY VIEWS
[To accompany H.R. 8880]
The Committee on Small Business, to whom was referred the
bill (H.R. 8880) to require the Comptroller General to evaluate
Federal cybersecurity assistance to small business concerns,
and for other purposes, having considered the same, reports
favorably thereon without amendment and recommends that the
bill do pass.
CONTENTS
Page
I. Purpose and Bill Summary........................................ 2
II. Need for Legislation............................................ 2
III. Hearings........................................................ 2
IV. Committee Consideration......................................... 2
V. Committee Votes................................................. 2
VI. Section-by-Section of H.R. 8880................................. 4
VII. Congressional Budget Office Cost Estimate....................... 4
VIII. New Budget Authority, Entitlement Authority, and Tax Expenditure 4
IX. Oversight Findings & Recommendations............................ 5
X. Performance Goals and Objectives................................ 5
XI. Statement of Duplication of Federal Programs.................... 5
XII. Congressional Earmarks, Limited Tax Benefits, and Limited Tariff
Benefits........................................................ 5
XIII. Federal Mandates Statement...................................... 5
XIV. Federal Advisory Committee Statement............................ 5
XV. Applicability to Legislative Branch............................. 5
XVI. Statement of Constitutional Authority........................... 5
XVII. Minority Views.................................................. 6
I. PURPOSE AND BILL SUMMARY
On May 19, 2026, Rep. Lateefah Simon (D-CA) and Rep. Robert
Bresnahan (R-PA), introduced H.R. 8880, the Small Business
Cybersecurity Assistance Evaluation Act of 2026. This bill
directs the Government Accountability Office (GAO) to conduct a
study evaluating cybersecurity risks to small businesses, as
well as existing federal cybersecurity programs and resources
available to them.
II. NEED FOR LEGISLATION
The Small Business Cybersecurity Assistance Evaluation Act
of 2026 requires the GAO to conduct a study on existing federal
government cybersecurity assistance available to small
businesses, including programs, tools, resources, and services
intended to help small business owners identify and respond to
cyber threats. It also requires GAO to identify cyber risks,
assess preparedness for these threats, and develop plans to
mitigate and recover from cyberattacks on small businesses.
Small businesses are increasingly targeted by
cybercriminals, ransomware attacks, scams, and fraud schemes,
yet many lack the financial resources, personnel, or technical
expertise necessary to defend against evolving cybersecurity
threats. While multiple federal agencies offer cybersecurity
assistance, these efforts are often hard to navigate or are
underutilized.
By identifying weaknesses and room for improvement in
current federal cybersecurity assistance resources, this
legislation will ensure small businesses have better access to
tools and training to protect themselves from cyberattacks.
III. HEARINGS
The Committee on Small Business held the following hearings
examining matters related to H.R. 8880:
On February 5, 2025, the Committee held a
hearing titled ``Hope on the Horizon: Prioritizing
Small Business Growth in the 119th Congress.''
On December 2, 2025, the Committee held a
hearing titled ``Main Street Under Attack: The Cost of
Crime on Small Businesses''
IV. COMMITTEE CONSIDERATION
The Committee on Small Business met in open session, with a
quorum being present, on May 20, 2026, and ordered H.R. 8880 to
be reported favorably to the House of Representatives by a roll
call vote of 23 ayes to 0 nos.
V. COMMITTEE VOTES
Clause 3(b) of rule XIII of the Rules of the House of
Representatives requires the Committee to list the recorded
votes on the motion to report legislation and amendments
thereto. The Committee voted to favorably report H.R. 8880 to
the House of Representatives at 4:13 PM.
[GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]
VI. SECTION-BY-SECTION OF H.R. 8880
Section 1--Short title
This Act may be cited as the ``Small Business Cybersecurity
Assistance Evaluation Act of 2026.''
Section 2--GAO Study on Small Business Cybersecurity Assistance
This section requires GAO to conduct a study of existing
federal cybersecurity initiatives, programs, resources, tools,
and services intended to assist small business concerns.
The study examines federal efforts to help small businesses
identify cybersecurity risks and vulnerabilities, assess
preparedness, plan for and recover from cyberattacks and fraud,
and access capital needed to implement cybersecurity measures
and infrastructure.
This section requires GAO to evaluate the awareness, use,
coordination, and effectiveness of existing federal
cybersecurity assistance available to small businesses. The
study must also identify any gaps in foundational cybersecurity
concepts within current federal programs and provide
recommendations to improve the effectiveness, awareness, and
coordination of such initiatives.
This section requires GAO to submit a report containing its
findings and recommendations to the House Committee on Small
Business and the Senate Committee on Small Business and
Entrepreneurship.
Section 3--Compliance with CUTGO
This section states that no additional amounts are
authorized to carry out this Act.
VII. CONGRESSIONAL BUDGET OFFICE COST ESTIMATE
Pursuant to 3(c)(3) of rule XIII of the Rules of the House
of Representatives, the Committee adopts as its own the cost
estimate prepared by the Director of the Congressional Budget
Office pursuant to section 402 of the Congressional Budget Act
of 1974. At the time this report was filed, the Committee has
requested but not received a cost estimate from the Director of
the Congressional Budget Office.
VIII. NEW BUDGET AUTHORITY, ENTITLEMENT AUTHORITY, AND TAX EXPENDITURES
Pursuant to clause 3(c)(2) of rule XIII of the Rules of the
House of Representatives and section 308(a)(I) of the
Congressional Budget Act of 1974, the Committee provides the
following opinion and estimate with respect to new budget
authority, entitlement authority, and tax expenditures. While
the Committee has not received an estimate of new budget
authority contained in the cost estimate prepared by the
Director of the Congressional Budget Office pursuant to section
402 of the Congressional Budget Act of 1974, the Committee does
not believe that there will be any new or increased costs
attributable to this legislation.
IX. OVERSIGHT FINDINGS & RECOMMENDATIONS
In accordance with clause 3(c)(1) of rule XIII and clause
2(b)(1) of rule X of the Rules of the House of Representatives,
the oversight findings and recommendations of the Committee on
Small Business with respect to the subject matter contained in
H.R. 8880 are incorporated into the descriptive portions of
this report.
X. PERFORMANCE GOALS AND OBJECTIVES
With respect to the requirements of clause 3(c)(4) of rule
XIII of the Rules of the House of Representatives, the goal of
H.R. 8880 is to strengthen cybersecurity support and
preparedness for small businesses.
XI. STATEMENT OF DUPLICATION OF FEDERAL PROGRAMS
Pursuant to clause 3(c)(5) of rule XIII of the Rules of the
House of Representatives, no provision of H.R. 8880 is known to
be duplicative of another Federal program, including any
program that was included in a report to Congress pursuant to
section 21 of Public Law 111-139 or the most recent Catalog of
Federal Domestic Assistance.
XII. CONGRESSIONAL EARMARKS, LIMITED TAX BENEFITS, AND LIMITED TARIFF
BENEFITS
With respect to clause 9 of rule XXI of the Rules of the
House of Representatives, the Committee finds that the bill
does not contain any congressional earmarks, limited tax
benefits, or limited tariff benefits as defined in clause 9(e),
9(f), or 9(g) of rule XXI of the Rules of the House of
Representatives.
XIII. FEDERAL MANDATES STATEMENT
The Committee will adopt as its own the estimate of the
Federal mandates prepared by the Director of the Congressional
Budget Office pursuant to section 423 of the Unfunded Mandates
Reform Act.
XIV. FEDERAL ADVISORY COMMITTEE STATEMENT
No advisory committees within the meaning of section 5(b)
of the Federal Advisory Committee Act were created by this
legislation.
XV. APPLICABILITY TO LEGISLATIVE BRANCH
The Committee finds that the legislation does not relate to
the terms and conditions of employment or access to public
services or accommodations within the meaning of section
102(b)(3) of the Congressional Accountability Act.
XVI. STATEMENT OF CONSTITUTIONAL AUTHORITY
Pursuant to clause 7 of rule XII of the Rules of the House,
the Committee finds that the authority for this legislation in
Art. I, Sec. 8, cl.1 of the Constitution of the United States.
XVII. MINORITY VIEWS
Digital tools and the Internet are critical for small
businesses. During the COVID-19 pandemic, firms of all sizes
increasingly adopted technology as work shifted to virtual
environments. Today, according to the U.S. Chamber of Commerce
(Chamber), 99 percent of small businesses use at least one
technology platform, with 58 percent using at least four
platforms.\1\ However, only 25 percent of small businesses use
cybersecurity and malware detection tools.\2\ This lack of
investment often occurs because unlike larger corporations,
entrepreneurs and their staff lack the time, skills, and money
to adopt effective cybersecurity measures. Cybercriminals are
well aware of these vulnerabilities and exploit them at small
businesses' expense.
---------------------------------------------------------------------------
\1\U.S. Chamber of Com., Empowering Small Business: The Impact of
Technology on U.S. Small Business, 4-6 (Aug. 18, 2025).
\2\Id., at 5.
---------------------------------------------------------------------------
Multiple federal entities have developed and provided
cybersecurity resources for small businesses. However, the
Committee has heard feedback that awareness of these resources
varies, partly because they are not provided by the U.S. Small
Business Administration (SBA). While agencies certainly have
the expertise to create cybersecurity resources, it can be
difficult for them to have an impact on small businesses simply
because those agencies lack a distribution network and
experience to perform effective small business outreach. The
SBA, in consultation with other relevant federal entities, is
uniquely equipped to help small businesses on technical
matters.
In 2015, the U.S. Government Accountability Office (GAO)
conducted a study examining cybersecurity resources for small
businesses in the defense industrial base, and the Defense
Department's Office of Small Business Programs implemented its
recommendation to ``identify and disseminate cybersecurity
resources to defense small businesses.''\3\
---------------------------------------------------------------------------
\3\U.S. Gov't Accountability Off., GAO-15-777, Defense
Cybersecurity: Opportunities Exist for DOD to Share Cybersecurity
Resources with Small Businesses (Sept. 24, 2015).
---------------------------------------------------------------------------
In 2016, then-Representative Richard Hanna (R-NY), a
Committee Member, introduced the bipartisan Improving Small
Business Cyber Security Act of 2016,\4\ components of which
were incorporated into the National Defense Authorization Act
(NDAA) for Fiscal Year (FY) 2017. The FY 2017 NDAA directed the
SBA and Homeland Security Department (DHS) to develop a Small
Business Development Center (SBDC) Cyber Strategy, and for
SBDCs to provide cybersecurity counseling to small
businesses.\5\
---------------------------------------------------------------------------
\4\Improving Small Business Cyber Security Act of 2016, H.R. 5064,
114th Cong. (2016); 162 Cong. Rec. H5776-H5779 (daily ed. Sep. 21,
2016).
\5\National Defense Authorization Act for Fiscal Year 2017, Pub. L.
No. 114-328, 130 Stat. 2000 (2016).
---------------------------------------------------------------------------
Under my leadership, the Committee approved the Small
Business Cyber Training Act of 2022, which was enacted into law
on December 27, 2022. The Act requires the SBA to establish a
program to certify at least 5 or 10 percent of employees in
each lead SBDC to provide cybersecurity assistance to small
businesses.\6\
---------------------------------------------------------------------------
\6\Small Business Cyber Training Act of 2022, Pub. L. No. 117-319,
136 Stat. 4424 (codified at 15 U.S.C. 648 (2022)).
---------------------------------------------------------------------------
The SBDCs are currently implementing the SBDC Cyber
Strategy and beginning to provide cybersecurity counseling to
small businesses.\7\ The Delaware SBDC launched the North Star
program to certify SBDC staff nationwide to provide this
counseling. Its offerings include both in-person and virtual
training, and certifications must be renewed annually, to
ensure staff are updated on new developments in cybersecurity.
Since Fiscal Year 2024, North Star has certified 291
employees.\8\
---------------------------------------------------------------------------
\7\Cong. Research Serv., IF12732, The Cybersecurity for Small
Business Pilot Program 1 (Aug. 7, 2024).
\8\Del. Small Bus. Dev. Ctr., Cyber Award Q3 Narrative Report:
April 2025 Through June 2025 (2025) (on file with the H. Comm. on Small
Bus.).
---------------------------------------------------------------------------
Nydia M. Velazquez,
Ranking Member.
[all]