Small Business Cybersecurity Assistance Evaluation Act of 2026
Officially: “Small Business Cybersecurity Assistance Evaluation Act of 2026” Read the full text
What it does
Read it in plain language
1Short title
This section states that the Act may be cited as the Small Business Cybersecurity Assistance Evaluation Act of 2026.
Show official text
1. Short title This Act may be cited as the Small Business Cybersecurity Assistance Evaluation Act of 2026 .
2GAO study on small business cybersecurity assistance
This section would require the Comptroller General of the United States to study current federal cybersecurity initiatives, programs, resources, tools, and services intended to assist owners of small business concerns (as defined under section 3 of the Small Business Act) with identifying cyber risks, cyber threats, and cybersecurity vulnerabilities relating to their businesses; assessing how prepared their businesses are for those risks, threats, and vulnerabilities; planning for, mitigating, and recovering from cyberattacks and incidents of social engineering, scams, and fraud, including developing, adopting, and implementing cybersecurity measures, training, protocols, tools, and infrastructure; and identifying sources of capital, or obtaining capital, to carry out those three activities. The study would have to include information on the most common cyberattacks affecting small business concerns; an identification and description of the federal cybersecurity initiatives, programs, resources, tools, and services covered by the study; an assessment of small business concerns' awareness and use of those programs and the reasons for differences in levels of that awareness and use; an assessment of the coordination and integration among those programs; an assessment of how effective those programs are in assisting small business concerns with the four activities listed above; an identification of any foundational cybersecurity concepts absent from those programs; and recommendations on how to improve the effectiveness, awareness, and coordination of those programs for small business concerns. The Comptroller General would have to submit a report containing all findings and determinations from the study to the House Committee on Small Business and the Senate Committee on Small Business and Entrepreneurship.
Show official text
2. GAO study on small business cybersecurity assistance (a) Study The Comptroller General of the United States shall conduct a study of current Federal cybersecurity initiatives, programs, resources, tools, and services intended to assist owners of small business concerns (as defined under section 3 of the Small Business Act ( 15 U.S.C. 632 )) with— (1) identifying cyber risks, cyber threats, and cybersecurity vulnerabilities relating to such concerns; (2) assessing the preparedness of such concerns for such risks, threats, and vulnerabilities; (3) planning for, mitigating, and recovering from cyberattacks and incidents of social engineering, scams, and fraud (including developing, adopting, and implementing cybersecurity measures, training, protocols, tools, and infrastructure); and (4) identifying sources of capital, or obtaining capital, to carry out the activities specified in paragraphs (1), (2), and (3). (b) Required content The study required by subsection (a) shall include— (1) information on the most common cyberattacks affecting small business concerns; (2) an identification and description of the Federal cybersecurity initiatives, programs, resources, tools, and services included in the study described in subsection (a); (3) an assessment of the awareness and use of such Federal cybersecurity initiatives, programs, resources, tools, and services by small business concerns and reasons for differences in levels of such awareness and use; (4) an assessment of the coordination and integration among such Federal cybersecurity initiatives, programs, resources, tools, and services; (5) an assessment of the effectiveness of such Federal cybersecurity initiatives, programs, resources, tools, and services in assisting small business concerns with the activities listed in paragraphs (1) through (4) of subsection (a); (6) an identification of any foundational cybersecurity concepts absent from such Federal cybersecurity initiatives, programs, resources, tools, and services; and (7) recommendations on how to improve the effectiveness, awareness, and coordination of such Federal cybersecurity initiatives, programs, resources, tools, and services for small business concerns. (c) Report The Comptroller General shall submit to the Committee on Small Business of the House of Representatives and the Committee on Small Business and Entrepreneurship of the Senate a report containing all findings and determinations made in carrying out the study required under subsection (a).
3Compliance with CUTGO
This section would state that no additional amounts are authorized to carry out this Act, meaning the Act would not authorize any new federal spending.
Show official text
3. Compliance with CUTGO No additional amounts are authorized to carry out this Act.
Where it is
In the House.