govt.fyi
US Congress · H.R. 4491 · Passed the House

SBA IT Modernization Reporting Act

Introduced
Moved
Reached a final decision
Introduced 2025-07-17
Derived from the official record below.

Officially: “SBA IT Modernization Reporting Act Read the full text

Commerce

What it does

SBA IT Modernization Reporting Act This bill requires the Small Business Administration (SBA) to implement the recommendations from a Government Accountability Office (GAO) report published on November 6, 2024, related to modernizing the SBA's information technology systems. Specifically, the SBA must address risks related to its certification project that allows small businesses to apply for and manage government contracting certifications. The GAO recommendations include developing a project risk management strategy and risk mitigation plan and managing cybersecurity vulnerabilities. The SBA
Summary by the Congressional Research Service, from the official record. Plain-language version below. Not legal advice.

Read it in plain language

AI plain language2 sections
Written by AI from the complete official bill text and independently fact-checked against it. Not legal advice.
1Short title

This section would give the Act the short title "SBA IT Modernization Reporting Act."

Show official text
Official text, verbatim from the record

1. Short title This Act may be cited as the SBA IT Modernization Reporting Act .

2Implementation of recommendations relating to information technology modernization for the Small Business Administration

This section would require the Administrator of the Small Business Administration, acting through the Administration's Chief Information Officer, to take the actions necessary to carry out the recommendations in the Comptroller General's report titled "IT Modernization: SBA Urgently Needs to Address Risks on Newly Deployed System" (GAO-25-106963, published November 6, 2024). Not later than 180 days after the Act becomes law, the Administrator would have to submit an implementation plan to the House Committee on Small Business and the Senate Committee on Small Business and Entrepreneurship detailing the actions the Administration will take to establish and carry out policies and procedures governing its information technology modernization projects. For each project, those policies and procedures would have to, for every risk identified, state the source of the risk in the risk documentation; clearly define risk parameters; establish and maintain risk management strategies; identify and document risks for all phases of the project life cycle; evaluate, categorize, and prioritize risks based on the defined risk parameters and develop project risk management plans; connect risk mitigation measures to the risk mitigation plans; require that any information technology acquisition plan and any strategic plan contain the information needed to manage cyber risks; require that a traceability analysis be performed and documented; require that security-related subject matter experts be involved in the process of selecting contractors for a project; require that master schedules be developed using the guidelines in the Comptroller General's "GAO Schedule Assessment Guide: Best Practices for Project Schedules" (GAO-16-89G, published December 22, 2015); and require that cost estimates be developed using the guidelines in the Comptroller General's "Cost Estimating and Assessment Guide: Best Practices for Developing and Managing Program Costs" (GAO-20-195G, published March 12, 2020). The implementation plan would also have to include the actions needed to carry out each of those 11 requirements, identify the office of the Administration responsible for carrying out each action, and give the timelines for completing each action. Not later than 30 days after the implementation plan is submitted, the Administrator would have to give the House Committee on Small Business and the Senate Committee on Small Business and Entrepreneurship a briefing on the plan.

Show official text
Official text, verbatim from the record

2. Implementation of recommendations relating to information technology modernization for the Small Business Administration (a) In general The Administrator of the Small Business Administration, acting through the Chief Information Officer of the Administration, shall take such actions as may be necessary to implement the recommendations contained in the report of the Comptroller General of the United States titled IT MODERNIZATION: SBA Urgently Needs to Address Risks on Newly Deployed System (GAO–25–106963; published November 6, 2024). (b) Implementation plan Not later than 180 days after the date of the enactment of this Act, the Administrator shall submit to the Committee on Small Business of the House of Representatives and the Committee on Small Business and Entrepreneurship of the Senate an implementation plan detailing the actions the Small Business Administration will undertake to establish and implement policies and procedures to govern information technology modernization projects of the Administration. Such policies and procedures shall, with respect to each project— (1) for each risk identified, explicitly state the source of such risk in the relevant risk documentation; (2) clearly define risk parameters; (3) establish and maintain risk management strategies; (4) identify and document risks for all phases of the life cycle; (5) evaluate, categorize, and prioritize risks based on defined risk parameters and develop project risk management plans; (6) connect measures to mitigate risk to risk mitigation plans; (7) require that any information technology acquisition plan and any strategic plan contains information needed to manage cyber risks; (8) require that a traceability analysis is performed and documented; (9) require that security-related subject matter experts are involved in selection process for contractors for a project; (10) develop master schedules using the guidelines contained in the publication of the Comptroller General titled GAO Schedule Assessment Guide: Best Practices for Project Schedules (GAO–16–89G; published December 22, 2015); and (11) develop cost estimates using the guidelines contained in the publication of the Comptroller General titled Cost Estimating and Assessment Guide: Best Practices for Developing and Managing Program Costs (GAO–20–195G; published March 12, 2020). (c) Additional requirements The implementation plan required by this section shall include the actions required to carry out the requirements listed in paragraphs (1) through (11) of subsection (b), an identification of the office of the Administration responsible for implementation, and the timelines for completion of each action. (d) Briefing required Not later than 30 days after the submission of the implementation plan required under this section, the Administrator shall provide to the Committee on Small Business of the House of Representatives and the Committee on Small Business and Entrepreneurship of the Senate a briefing on the plan.

AI plain languageRead the whole bill in plain language, 2 sections

Where it is

Introduced · 2025-07-17

In the House.

Passed the House · 2025-12-01
Senate floor vote · next · the next step

Official documents

The on-site text is shown verbatim from the GovInfo publication, captured 2026-07-23. The same version at GovInfo.

The numbers

29%
of bills that passed one chamber became law in the 118th Congress, 2023 to 2024 (n=939)
2
sponsors, out of 218 needed to pass
Every fact on this page links to its source, starting with the official bill record. Last action: Received in the Senate and Read twice and referred to the Committee on Small Business and Entrepreneurship. (2025-12-02).