H.R. 2105House115th Congress (2017-2019)Passed House

NIST Small Business Cybersecurity Act

Introduced April 20, 2017

AI-Generated Summary

Updated April 15, 2026 at 2:56 PM UTC

The NIST Small Business Cybersecurity Act directs the director of the National Institute of Standards and Technology (NIST) to develop and share clear, practical guidance that helps small businesses identify, assess, and reduce cyber‑security risks. The guidance must be usable by a wide range of small firms, adaptable to different sizes and data sensitivities, and include basic controls, cultural tips, case studies, and technology‑neutral recommendations. The resources are voluntary, will be posted publicly, and are to be created using existing NIST funding.

Key Provisions

  • Amends the NIST Act to require NIST to consider small business concerns when developing cybersecurity guidance.
  • Within one year, NIST must produce and disseminate concise resources (guidelines, tools, best practices) tailored to small businesses.
  • The resources must be broadly applicable, scalable to business size and data sensitivity, promote basic security controls and a security‑aware culture, include case studies, be technology‑neutral, and align with international standards where possible.
  • Guidance must be consistent with existing NIST cybersecurity education programs and, when feasible, incorporate methods from the Small Business Development Center Cyber Strategy.
  • The resources are voluntary, must be updated as needed, and made prominently available on agency websites.

Legislative Activity

Stay on top of the latest movement without scrolling through every action

10 earlier actions
SenateIntro Referral Latest Action

Received in the Senate and Read twice and referred to the Committee on Commerce, Science, and Transportation.

October 16, 2017

View full timeline
HouseIntro Referral

Introduced in House

April 20, 2017

HouseIntro Referral

Referred to the House Committee on Science, Space, and Technology.

April 20, 2017

HouseCommittee

Committee Consideration and Mark-up Session Held.

May 2, 2017

HouseCommittee

Ordered to be Reported (Amended) by Voice Vote.

May 2, 2017

HouseFloor

Mr. Webster (FL) moved to suspend the rules and pass the bill, as amended.

October 11, 2017 • 1:55 PM

HouseFloor

Considered under suspension of the rules. (consideration: CR H7936-7939)

October 11, 2017 • 1:56 PM

HouseFloor

DEBATE - The House proceeded with forty minutes of debate on H.R. 2105.

October 11, 2017 • 1:56 PM

HouseFloor

Passed/agreed to in House: On motion to suspend the rules and pass the bill, as amended Agreed to by voice vote.(text: CR H7936-7937)

October 11, 2017 • 2:20 PM

HouseFloor

On motion to suspend the rules and pass the bill, as amended Agreed to by voice vote. (text: CR H7936-7937)

October 11, 2017 • 2:20 PM

HouseFloor

Motion to reconsider laid on the table Agreed to without objection.

October 11, 2017 • 2:20 PM

SenateIntro Referral

Received in the Senate and Read twice and referred to the Committee on Commerce, Science, and Transportation.

October 16, 2017

Floor Debate

8 members

What members said about H.R. 2105 on the floor

6 Republicans2 Democrats
Daniel Webster
Rep. Daniel WebsterR-FL-11 · Oct 11, 2017

Mr. Speaker, I move to suspend the rules and pass the bill (H.R. 2105) to require the Director of the National Institute of Standards and Technology to disseminate guidance to help reduce small…

Daniel Lipinski
Rep. Daniel LipinskiD-IL-3 · Oct 11, 2017

Mr. Speaker, I yield myself such time as I may consume. Mr. Speaker, I rise in support of H.R. 2105, the NIST Small Business Cybersecurity Act of 2017, a bipartisan effort to help small businesses…

Eddie Bernice Johnson
Rep. Eddie Bernice JohnsonD-TX-30 · Oct 11, 2017

Mr. Speaker, I rise in support of H.R. 2105, the NIST Small Business Cybersecurity Act of 2017, which directs the National Institute of Standards and Technology to provide more guidance, resources,…

Lamar Smith
Rep. Lamar SmithR-TX-21 · Oct 11, 2017

Mr. Speaker, I thank the gentleman from Florida (Mr. Webster) for yielding me time and for introducing H.R. 2105, the NIST Small Business Cybersecurity Act. This important and timely bipartisan bill,…

Barbara Comstock
Rep. Barbara ComstockR-VA-10 · Oct 11, 2017

Mr. Speaker, I rise in support of H.R. 2105. When I travel around my district, which is rich with technology workers, the thing that I hear repeated concern about is the increasing need for…

Show 3 more
Neal P. Dunn
Rep. Neal P. DunnR-FL-2 · Oct 11, 2017

Mr. Speaker, today I rise in support of H.R. 2105, the National Institute of Standards and Technology Small Business Cybersecurity Act. This bipartisan legislation instructs the Director of NIST, in…

Don Bacon
Rep. Don BaconR-NE-2 · Oct 11, 2017

Mr. Speaker, I rise in support of the National Institute of Standards and Technology Small Business Cybersecurity Act, a bill that I am proud to cosponsor. This legislation will help promote stronger…

Ralph Norman
Rep. Ralph NormanR-SC-5 · Oct 11, 2017

Mr. Speaker, I rise today in support of H.R. 2105, the National Institute of Standards and Technology Small Business Cybersecurity Act. This bill directs the National Institute of Standards and…

Bill Text

3 versions available

Reading Mode
Latest
Referred in SenateIssued October 16, 2017

IIB

115th CONGRESS

1st Session

H. R. 2105

IN THE SENATE OF THE UNITED STATES

October 16, 2017

Received; read twice and referred to the Committee on Commerce, Science, and Transportation

AN ACT

To require the Director of the National Institute of Standards and Technology to disseminate guidance to help reduce small business cybersecurity risks, and for other purposes.

1.

Short title

This Act may be cited as the NIST Small Business Cybersecurity Act.

2.

Improving cybersecurity of small businesses

(a)

Definitions

In this section:

(1)

Director

The term Director means the Director of the National Institute of Standards and Technology.

(2)

Resources

The term resources means guidelines, tools, best practices, standards, methodologies, and other ways of providing information.

(3)

Small business concern

The term small business concern has the meaning given such term in section 3 of the Small Business Act (15 U.S.C. 632).

(b)

Small business cybersecurity

Section 2(e)(1)(A) of the National Institute of Standards and Technology Act (15 U.S.C. 272(e)(1)(A)) is amended—

(1)

in clause (vii), by striking and at the end;

(2)

by redesignating clause (viii) as clause (ix); and

(3)

by inserting after clause (vii) the following:

(viii)

consider small business concerns (as defined in section 3 of the Small Business Act (15 U.S.C. 632)); and

.

(c)

Dissemination of resources for small businesses

(1)

In general

Not later than one year after the date of the enactment of this Act, the Director, in carrying out section 2(e)(1)(A)(viii) of the National Institute of Standards and Technology Act, as added by subsection (b) of this Act, in consultation with the heads of other appropriate Federal agencies, shall disseminate clear and concise resources to help small business concerns identify, assess, manage, and reduce their cybersecurity risks.

(2)

Requirements

The Director shall ensure that the resources disseminated pursuant to paragraph (1)—

(A)

are generally applicable and usable by a wide range of small business concerns;

(B)

vary with the nature and size of the implementing small business concern, and the nature and sensitivity of the data collected or stored on the information systems or devices of the implementing small business concern;

(C)

include elements, that promote awareness of simple, basic controls, a workplace cybersecurity culture, and third-party stakeholder relationships, to assist small business concerns in mitigating common cybersecurity risks;

(D)

include case studies of practical application;

(E)

are technology-neutral and can be implemented using technologies that are commercial and off-the-shelf; and

(F)

are based on international standards to the extent possible, and are consistent with the Stevenson-Wydler Technology Innovation Act of 1980 (15 U.S.C. 3701 et seq.).

(3)

National cybersecurity awareness and education program

The Director shall ensure that the resources disseminated under paragraph (1) are consistent with the efforts of the Director under section 401 of the Cybersecurity Enhancement Act of 2014 (15 U.S.C. 7451).

(4)

Small Business Development Center Cyber Strategy

In carrying out paragraph (1), the Director, to the extent practicable, shall consider any methods included in the Small Business Development Center Cyber Strategy developed under section 1841(a)(3)(B) of the National Defense Authorization Act for Fiscal Year 2017 (Public Law 114–328).

(5)

Voluntary resources

The use of the resources disseminated under paragraph (1) shall be considered voluntary.

(6)

Updates

The Director shall review and, if necessary, update the resources disseminated under paragraph (1) in accordance with the requirements under paragraph (2).

(7)

Public availability

The Director and the head of each Federal agency that so elects shall make prominently available on the respective agency’s public Internet website information about the resources and updates to the resources disseminated under paragraph (1). The Director and the heads shall each ensure that the information they respectively make prominently available is consistent, clear, and concise.

(d)

Other Federal cybersecurity requirements

Nothing in this section may be construed to supersede, alter, or otherwise affect any cybersecurity requirements applicable to Federal agencies.

(e)

Funding

This Act shall be carried out using funds otherwise authorized to be appropriated or made available to the National Institute of Standards and Technology.

Passed the House of Representatives October 11, 2017.

Karen L. Haas,

Clerk