[House Report 119-679]
[From the U.S. Government Publishing Office]


119th Congress   }                                       {      Report
                        HOUSE OF REPRESENTATIVES
 2d Session      }                                       {     119-679

======================================================================



 
     SMALL BUSINESS CYBERSECURITY ASSISTANCE EVALUATION ACT OF 2026

                                _______
                                

  June 3, 2026.--Committed to the Committee of the Whole House on the 
              State of the Union and ordered to be printed

                                _______
                                

Mr. Williams of Texas, from the Committee on Small Business, submitted 
                             the following

                              R E P O R T

                             together with

                             MINORITY VIEWS

                        [To accompany H.R. 8880]

    The Committee on Small Business, to whom was referred the 
bill (H.R. 8880) to require the Comptroller General to evaluate 
Federal cybersecurity assistance to small business concerns, 
and for other purposes, having considered the same, reports 
favorably thereon without amendment and recommends that the 
bill do pass.

                                CONTENTS
 
                                                                     Page
   I. Purpose and Bill Summary........................................  2
  II. Need for Legislation............................................  2
 III. Hearings........................................................  2
  IV. Committee Consideration.........................................  2
   V. Committee Votes.................................................  2
  VI. Section-by-Section of H.R. 8880.................................  4
 VII. Congressional Budget Office Cost Estimate.......................  4
VIII. New Budget Authority, Entitlement Authority, and Tax Expenditure  4
  IX. Oversight Findings & Recommendations............................  5
   X. Performance Goals and Objectives................................  5
  XI. Statement of Duplication of Federal Programs....................  5
 XII. Congressional Earmarks, Limited Tax Benefits, and Limited Tariff   
      Benefits........................................................  5
XIII. Federal Mandates Statement......................................  5
 XIV. Federal Advisory Committee Statement............................  5
  XV. Applicability to Legislative Branch.............................  5
 XVI. Statement of Constitutional Authority...........................  5
XVII. Minority Views..................................................  6

                      I. PURPOSE AND BILL SUMMARY

    On May 19, 2026, Rep. Lateefah Simon (D-CA) and Rep. Robert 
Bresnahan (R-PA), introduced H.R. 8880, the Small Business 
Cybersecurity Assistance Evaluation Act of 2026. This bill 
directs the Government Accountability Office (GAO) to conduct a 
study evaluating cybersecurity risks to small businesses, as 
well as existing federal cybersecurity programs and resources 
available to them.

                        II. NEED FOR LEGISLATION

    The Small Business Cybersecurity Assistance Evaluation Act 
of 2026 requires the GAO to conduct a study on existing federal 
government cybersecurity assistance available to small 
businesses, including programs, tools, resources, and services 
intended to help small business owners identify and respond to 
cyber threats. It also requires GAO to identify cyber risks, 
assess preparedness for these threats, and develop plans to 
mitigate and recover from cyberattacks on small businesses.
    Small businesses are increasingly targeted by 
cybercriminals, ransomware attacks, scams, and fraud schemes, 
yet many lack the financial resources, personnel, or technical 
expertise necessary to defend against evolving cybersecurity 
threats. While multiple federal agencies offer cybersecurity 
assistance, these efforts are often hard to navigate or are 
underutilized.
    By identifying weaknesses and room for improvement in 
current federal cybersecurity assistance resources, this 
legislation will ensure small businesses have better access to 
tools and training to protect themselves from cyberattacks.

                             III. HEARINGS

    The Committee on Small Business held the following hearings 
examining matters related to H.R. 8880:
           On February 5, 2025, the Committee held a 
        hearing titled ``Hope on the Horizon: Prioritizing 
        Small Business Growth in the 119th Congress.''
           On December 2, 2025, the Committee held a 
        hearing titled ``Main Street Under Attack: The Cost of 
        Crime on Small Businesses''

                      IV. COMMITTEE CONSIDERATION

    The Committee on Small Business met in open session, with a 
quorum being present, on May 20, 2026, and ordered H.R. 8880 to 
be reported favorably to the House of Representatives by a roll 
call vote of 23 ayes to 0 nos.

                           V. COMMITTEE VOTES

    Clause 3(b) of rule XIII of the Rules of the House of 
Representatives requires the Committee to list the recorded 
votes on the motion to report legislation and amendments 
thereto. The Committee voted to favorably report H.R. 8880 to 
the House of Representatives at 4:13 PM.


    [GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]

                  VI. SECTION-BY-SECTION OF H.R. 8880

Section 1--Short title

    This Act may be cited as the ``Small Business Cybersecurity 
Assistance Evaluation Act of 2026.''

Section 2--GAO Study on Small Business Cybersecurity Assistance

    This section requires GAO to conduct a study of existing 
federal cybersecurity initiatives, programs, resources, tools, 
and services intended to assist small business concerns.
    The study examines federal efforts to help small businesses 
identify cybersecurity risks and vulnerabilities, assess 
preparedness, plan for and recover from cyberattacks and fraud, 
and access capital needed to implement cybersecurity measures 
and infrastructure.
    This section requires GAO to evaluate the awareness, use, 
coordination, and effectiveness of existing federal 
cybersecurity assistance available to small businesses. The 
study must also identify any gaps in foundational cybersecurity 
concepts within current federal programs and provide 
recommendations to improve the effectiveness, awareness, and 
coordination of such initiatives.
    This section requires GAO to submit a report containing its 
findings and recommendations to the House Committee on Small 
Business and the Senate Committee on Small Business and 
Entrepreneurship.

Section 3--Compliance with CUTGO

    This section states that no additional amounts are 
authorized to carry out this Act.

             VII. CONGRESSIONAL BUDGET OFFICE COST ESTIMATE

    Pursuant to 3(c)(3) of rule XIII of the Rules of the House 
of Representatives, the Committee adopts as its own the cost 
estimate prepared by the Director of the Congressional Budget 
Office pursuant to section 402 of the Congressional Budget Act 
of 1974. At the time this report was filed, the Committee has 
requested but not received a cost estimate from the Director of 
the Congressional Budget Office.

VIII. NEW BUDGET AUTHORITY, ENTITLEMENT AUTHORITY, AND TAX EXPENDITURES

    Pursuant to clause 3(c)(2) of rule XIII of the Rules of the 
House of Representatives and section 308(a)(I) of the 
Congressional Budget Act of 1974, the Committee provides the 
following opinion and estimate with respect to new budget 
authority, entitlement authority, and tax expenditures. While 
the Committee has not received an estimate of new budget 
authority contained in the cost estimate prepared by the 
Director of the Congressional Budget Office pursuant to section 
402 of the Congressional Budget Act of 1974, the Committee does 
not believe that there will be any new or increased costs 
attributable to this legislation.

                IX. OVERSIGHT FINDINGS & RECOMMENDATIONS

    In accordance with clause 3(c)(1) of rule XIII and clause 
2(b)(1) of rule X of the Rules of the House of Representatives, 
the oversight findings and recommendations of the Committee on 
Small Business with respect to the subject matter contained in 
H.R. 8880 are incorporated into the descriptive portions of 
this report.

                  X. PERFORMANCE GOALS AND OBJECTIVES

    With respect to the requirements of clause 3(c)(4) of rule 
XIII of the Rules of the House of Representatives, the goal of 
H.R. 8880 is to strengthen cybersecurity support and 
preparedness for small businesses.

            XI. STATEMENT OF DUPLICATION OF FEDERAL PROGRAMS

    Pursuant to clause 3(c)(5) of rule XIII of the Rules of the 
House of Representatives, no provision of H.R. 8880 is known to 
be duplicative of another Federal program, including any 
program that was included in a report to Congress pursuant to 
section 21 of Public Law 111-139 or the most recent Catalog of 
Federal Domestic Assistance.

 XII. CONGRESSIONAL EARMARKS, LIMITED TAX BENEFITS, AND LIMITED TARIFF 
                                BENEFITS

    With respect to clause 9 of rule XXI of the Rules of the 
House of Representatives, the Committee finds that the bill 
does not contain any congressional earmarks, limited tax 
benefits, or limited tariff benefits as defined in clause 9(e), 
9(f), or 9(g) of rule XXI of the Rules of the House of 
Representatives.

                    XIII. FEDERAL MANDATES STATEMENT

    The Committee will adopt as its own the estimate of the 
Federal mandates prepared by the Director of the Congressional 
Budget Office pursuant to section 423 of the Unfunded Mandates 
Reform Act.

               XIV. FEDERAL ADVISORY COMMITTEE STATEMENT

    No advisory committees within the meaning of section 5(b) 
of the Federal Advisory Committee Act were created by this 
legislation.

                XV. APPLICABILITY TO LEGISLATIVE BRANCH

    The Committee finds that the legislation does not relate to 
the terms and conditions of employment or access to public 
services or accommodations within the meaning of section 
102(b)(3) of the Congressional Accountability Act.

               XVI. STATEMENT OF CONSTITUTIONAL AUTHORITY

    Pursuant to clause 7 of rule XII of the Rules of the House, 
the Committee finds that the authority for this legislation in 
Art. I, Sec. 8, cl.1 of the Constitution of the United States.

                          XVII. MINORITY VIEWS

    Digital tools and the Internet are critical for small 
businesses. During the COVID-19 pandemic, firms of all sizes 
increasingly adopted technology as work shifted to virtual 
environments. Today, according to the U.S. Chamber of Commerce 
(Chamber), 99 percent of small businesses use at least one 
technology platform, with 58 percent using at least four 
platforms.\1\ However, only 25 percent of small businesses use 
cybersecurity and malware detection tools.\2\ This lack of 
investment often occurs because unlike larger corporations, 
entrepreneurs and their staff lack the time, skills, and money 
to adopt effective cybersecurity measures. Cybercriminals are 
well aware of these vulnerabilities and exploit them at small 
businesses' expense.
---------------------------------------------------------------------------
    \1\U.S. Chamber of Com., Empowering Small Business: The Impact of 
Technology on U.S. Small Business, 4-6 (Aug. 18, 2025).
    \2\Id., at 5.
---------------------------------------------------------------------------
    Multiple federal entities have developed and provided 
cybersecurity resources for small businesses. However, the 
Committee has heard feedback that awareness of these resources 
varies, partly because they are not provided by the U.S. Small 
Business Administration (SBA). While agencies certainly have 
the expertise to create cybersecurity resources, it can be 
difficult for them to have an impact on small businesses simply 
because those agencies lack a distribution network and 
experience to perform effective small business outreach. The 
SBA, in consultation with other relevant federal entities, is 
uniquely equipped to help small businesses on technical 
matters.
    In 2015, the U.S. Government Accountability Office (GAO) 
conducted a study examining cybersecurity resources for small 
businesses in the defense industrial base, and the Defense 
Department's Office of Small Business Programs implemented its 
recommendation to ``identify and disseminate cybersecurity 
resources to defense small businesses.''\3\
---------------------------------------------------------------------------
    \3\U.S. Gov't Accountability Off., GAO-15-777, Defense 
Cybersecurity: Opportunities Exist for DOD to Share Cybersecurity 
Resources with Small Businesses (Sept. 24, 2015).
---------------------------------------------------------------------------
    In 2016, then-Representative Richard Hanna (R-NY), a 
Committee Member, introduced the bipartisan Improving Small 
Business Cyber Security Act of 2016,\4\ components of which 
were incorporated into the National Defense Authorization Act 
(NDAA) for Fiscal Year (FY) 2017. The FY 2017 NDAA directed the 
SBA and Homeland Security Department (DHS) to develop a Small 
Business Development Center (SBDC) Cyber Strategy, and for 
SBDCs to provide cybersecurity counseling to small 
businesses.\5\
---------------------------------------------------------------------------
    \4\Improving Small Business Cyber Security Act of 2016, H.R. 5064, 
114th Cong. (2016); 162 Cong. Rec. H5776-H5779 (daily ed. Sep. 21, 
2016).
    \5\National Defense Authorization Act for Fiscal Year 2017, Pub. L. 
No. 114-328, 130 Stat. 2000 (2016).
---------------------------------------------------------------------------
    Under my leadership, the Committee approved the Small 
Business Cyber Training Act of 2022, which was enacted into law 
on December 27, 2022. The Act requires the SBA to establish a 
program to certify at least 5 or 10 percent of employees in 
each lead SBDC to provide cybersecurity assistance to small 
businesses.\6\
---------------------------------------------------------------------------
    \6\Small Business Cyber Training Act of 2022, Pub. L. No. 117-319, 
136 Stat. 4424 (codified at 15 U.S.C. 648 (2022)).
---------------------------------------------------------------------------
    The SBDCs are currently implementing the SBDC Cyber 
Strategy and beginning to provide cybersecurity counseling to 
small businesses.\7\ The Delaware SBDC launched the North Star 
program to certify SBDC staff nationwide to provide this 
counseling. Its offerings include both in-person and virtual 
training, and certifications must be renewed annually, to 
ensure staff are updated on new developments in cybersecurity. 
Since Fiscal Year 2024, North Star has certified 291 
employees.\8\
---------------------------------------------------------------------------
    \7\Cong. Research Serv., IF12732, The Cybersecurity for Small 
Business Pilot Program 1 (Aug. 7, 2024).
    \8\Del. Small Bus. Dev. Ctr., Cyber Award Q3 Narrative Report: 
April 2025 Through June 2025 (2025) (on file with the H. Comm. on Small 
Bus.).
---------------------------------------------------------------------------
                                        Nydia M. Velazquez,
                                                    Ranking Member.

                                  [all]