govt.fyi
US Congress · H.R. 8880 · Passed the House

Small Business Cybersecurity Assistance Evaluation Act of 2026

Introduced
Moved
Reached a final decision
Introduced 2026-05-19
Derived from the official record below.

Officially: “Small Business Cybersecurity Assistance Evaluation Act of 2026 Read the full text

Commerce

What it does

Small Business Cybersecurity Assistance Evaluation Act of 2026 This bill requires the Government Accountability Office to study current federal cybersecurity initiatives, programs, resources, tools, and services that assist small businesses to identify and prepare for cybersecurity threats and vulnerabilities. The study must include information about the most common cyberattacks affecting small businesses and recommendations for improving the effectiveness, awareness, and coordination of federal cybersecurity initiatives and programs.
Summary by the Congressional Research Service, from the official record. Plain-language version below. Not legal advice.

Read it in plain language

AI plain language3 sections
Written by AI from the complete official bill text and independently fact-checked against it. Not legal advice.
1Short title

This section states that the Act may be cited as the Small Business Cybersecurity Assistance Evaluation Act of 2026.

Show official text
Official text, verbatim from the record

1. Short title This Act may be cited as the Small Business Cybersecurity Assistance Evaluation Act of 2026 .

2GAO study on small business cybersecurity assistance

This section would require the Comptroller General of the United States to study current federal cybersecurity initiatives, programs, resources, tools, and services intended to assist owners of small business concerns (as defined under section 3 of the Small Business Act) with identifying cyber risks, cyber threats, and cybersecurity vulnerabilities relating to their businesses; assessing how prepared their businesses are for those risks, threats, and vulnerabilities; planning for, mitigating, and recovering from cyberattacks and incidents of social engineering, scams, and fraud, including developing, adopting, and implementing cybersecurity measures, training, protocols, tools, and infrastructure; and identifying sources of capital, or obtaining capital, to carry out those three activities. The study would have to include information on the most common cyberattacks affecting small business concerns; an identification and description of the federal cybersecurity initiatives, programs, resources, tools, and services covered by the study; an assessment of small business concerns' awareness and use of those programs and the reasons for differences in levels of that awareness and use; an assessment of the coordination and integration among those programs; an assessment of how effective those programs are in assisting small business concerns with the four activities listed above; an identification of any foundational cybersecurity concepts absent from those programs; and recommendations on how to improve the effectiveness, awareness, and coordination of those programs for small business concerns. The Comptroller General would have to submit a report containing all findings and determinations from the study to the House Committee on Small Business and the Senate Committee on Small Business and Entrepreneurship.

Show official text
Official text, verbatim from the record

2. GAO study on small business cybersecurity assistance (a) Study The Comptroller General of the United States shall conduct a study of current Federal cybersecurity initiatives, programs, resources, tools, and services intended to assist owners of small business concerns (as defined under section 3 of the Small Business Act ( 15 U.S.C. 632 )) with— (1) identifying cyber risks, cyber threats, and cybersecurity vulnerabilities relating to such concerns; (2) assessing the preparedness of such concerns for such risks, threats, and vulnerabilities; (3) planning for, mitigating, and recovering from cyberattacks and incidents of social engineering, scams, and fraud (including developing, adopting, and implementing cybersecurity measures, training, protocols, tools, and infrastructure); and (4) identifying sources of capital, or obtaining capital, to carry out the activities specified in paragraphs (1), (2), and (3). (b) Required content The study required by subsection (a) shall include— (1) information on the most common cyberattacks affecting small business concerns; (2) an identification and description of the Federal cybersecurity initiatives, programs, resources, tools, and services included in the study described in subsection (a); (3) an assessment of the awareness and use of such Federal cybersecurity initiatives, programs, resources, tools, and services by small business concerns and reasons for differences in levels of such awareness and use; (4) an assessment of the coordination and integration among such Federal cybersecurity initiatives, programs, resources, tools, and services; (5) an assessment of the effectiveness of such Federal cybersecurity initiatives, programs, resources, tools, and services in assisting small business concerns with the activities listed in paragraphs (1) through (4) of subsection (a); (6) an identification of any foundational cybersecurity concepts absent from such Federal cybersecurity initiatives, programs, resources, tools, and services; and (7) recommendations on how to improve the effectiveness, awareness, and coordination of such Federal cybersecurity initiatives, programs, resources, tools, and services for small business concerns. (c) Report The Comptroller General shall submit to the Committee on Small Business of the House of Representatives and the Committee on Small Business and Entrepreneurship of the Senate a report containing all findings and determinations made in carrying out the study required under subsection (a).

3Compliance with CUTGO

This section would state that no additional amounts are authorized to carry out this Act, meaning the Act would not authorize any new federal spending.

Show official text
Official text, verbatim from the record

3. Compliance with CUTGO No additional amounts are authorized to carry out this Act.

AI plain languageRead the whole bill in plain language, 3 sections

Where it is

Introduced · 2026-05-19

In the House.

Passed the House · 2026-06-23
Senate floor vote · next · the next step

Official documents

The on-site text is shown verbatim from the GovInfo publication, captured 2026-07-23. The same version at GovInfo.

The numbers

29%
of bills that passed one chamber became law in the 118th Congress, 2023 to 2024 (n=939)
2
sponsors, out of 218 needed to pass

Who is lobbying on this

MICROSOFT CORPORATIONvia MICROSOFT CORPORATION
1 filing
From 1 filing in federal lobbying disclosures (LDA), via lda.gov, naming this bill (2026). Filings are self-reported by lobbying firms and show who is paid to influence this bill. They do not say which side, or whether it worked.
Every fact on this page links to its source, starting with the official bill record. Last action: Received in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs. (2026-06-24).