H.R. 2331House116th Congress (2019-2021)Passed House

SBA Cyber Awareness Act

Sponsored by Jason CrowRep. Jason Crow (D-CO)
Introduced April 18, 2019

AI-Generated Summary

Updated April 14, 2026 at 4:25 AM UTC

The SBA Cyber Awareness Act requires the Small Business Administration to report each year on its information‑technology and cybersecurity infrastructure, a plan to improve that infrastructure, any use of equipment made by companies based in China, and any cybersecurity incidents from the prior two years. It also obligates the SBA to quickly inform Congress and affected small businesses and individuals when a new cyber risk or incident is identified.

Key Provisions

  • The SBA Administrator must submit an annual report to the Senate Small Business and House Small Business committees within 180 days of the law’s enactment and each year thereafter.
  • The report must include an assessment of SBA IT and cybersecurity, a strategy for improvement, a list of any equipment sourced from China, and a summary of any cyber incidents in the past two years with actions taken.
  • If the Administrator determines a cyber risk or incident has occurred, they must notify the appropriate congressional committees within 7 days.
  • Within 30 days, the Administrator must notify affected individuals and small businesses and provide a detailed incident report estimating the number affected and potential harm.

Legislative Activity

Stay on top of the latest movement without scrolling through every action

10 earlier actions
SenateCalendars Latest Action

Received in the Senate. Read twice. Placed on Senate Legislative Calendar under General Orders. Calendar No. 151.

July 16, 2019

View full timeline
HouseIntro Referral

Introduced in House

April 18, 2019

HouseIntro Referral

Referred to the House Committee on Small Business.

April 18, 2019

HouseCommittee

Reported by the Committee on Small Business. H. Rept. 116-114.

June 13, 2019

HouseCalendars

Placed on the Union Calendar, Calendar No. 83.

June 13, 2019

HouseFloor

Mr. Delgado moved to suspend the rules and pass the bill.

July 15, 2019 • 4:52 PM

HouseFloor

Considered under suspension of the rules. (consideration: CR H5807-5809)

July 15, 2019 • 4:52 PM

HouseFloor

DEBATE - The House proceeded with forty minutes of debate on H.R. 2331.

July 15, 2019 • 4:52 PM

HouseFloor

Passed/agreed to in House: On motion to suspend the rules and pass the bill Agreed to by voice vote.(text: CR H5807)

July 15, 2019 • 5:02 PM

HouseFloor

On motion to suspend the rules and pass the bill Agreed to by voice vote. (text: CR H5807)

July 15, 2019 • 5:02 PM

HouseFloor

Motion to reconsider laid on the table Agreed to without objection.

July 15, 2019 • 5:02 PM

SenateCalendars

Received in the Senate. Read twice. Placed on Senate Legislative Calendar under General Orders. Calendar No. 151.

July 16, 2019

Floor Debate

4 members

What members said about H.R. 2331 on the floor

2 Republicans2 Democrats
Antonio Delgado
Rep. Antonio DelgadoD-NY-19 · Jul 15, 2019

Mr. Speaker, I move to suspend the rules and pass the bill (H.R. 2331) to require an annual report on the cybersecurity of the Small Business Administration, and for other purposes. Mr. Speaker, I…

Jason Crow
Rep. Jason CrowD-CO-6 · Jul 15, 2019

Mr. Speaker, I want to thank the gentleman from New York (Mr. Delgado) for yielding, and I want to thank Chairwoman Velazquez for prioritizing this critical issue and bringing our bill to the floor.…

Steve Chabot
Rep. Steve ChabotR-OH-1 · Jul 15, 2019

Mr. Speaker, I yield myself such time as I may consume. Mr. Speaker, I rise in support of H.R. 2331, the SBA Cyber Awareness Act. In June 2015, the Office of Personnel Management, or OPM, discovered…

Troy Balderson
Rep. Troy BaldersonR-OH-12 · Jul 15, 2019

Mr. Speaker, I rise today in support of H.R. 2331, the SBA Cyber Awareness Act of 2019. This bill has had my full support since its introduction and I am happy to support its passage today. I want to…

Bill Text

4 versions available

Reading Mode
Latest
Placed on Calendar SenateIssued July 16, 2019

II

Calendar No. 151

116th CONGRESS

1st Session

H. R. 2331

IN THE SENATE OF THE UNITED STATES

July 16, 2019

Received; read twice and placed on the calendar

AN ACT

To require an annual report on the cybersecurity of the Small Business Administration, and for other purposes.

1.

Short title

This Act may be cited as the SBA Cyber Awareness Act.

2.

Cybersecurity awareness reporting

Section 10 of the Small Business Act (15 U.S.C. 639) is amended by inserting after subsection (a) the following:

(b)

Cybersecurity reports

(1)

Annual report

Not later than 180 days after the date of enactment of this subsection, and every year thereafter, the Administrator shall submit a report to the appropriate congressional committees that includes—

(A)

an assessment of the information technology (as defined in section 11101 of title 40, United States Code) and cybersecurity infrastructure of the Administration;

(B)

a strategy to increase the cy­ber­se­cu­ri­ty infrastructure of the Administration;

(C)

a detailed account of any information technology equipment or interconnected system or subsystem of equipment of the Administration that was manufactured by an entity that has its principal place of business located in the People’s Republic of China; and

(D)

an account of any cybersecurity risk or incident that occurred at the Administration during the 2-year period preceding the date on which the report is submitted, and any action taken by the Administrator to respond to or remediate any such cybersecurity risk or incident.

(2)

Additional reports

If the Administrator determines that there is a reasonable basis to conclude that a cybersecurity risk or incident occurred at the Administration, the Administrator shall—

(A)

not later than 7 days after the date on which the Administrator makes that determination, notify the appropriate congressional committees of the cybersecurity risk or incident; and

(B)

not later than 30 days after the date on which the Administrator makes a determination under subparagraph (A)—

(i)

provide notice to individuals and small business concerns affected by the cybersecurity risk or incident; and

(ii)

submit to the appropriate congressional committees a report, based on information available to the Administrator as of the date which the Administrator submits the report, that includes—

(I)

a summary of information about the cybersecurity risk or incident, including how the cybersecurity risk or incident occurred; and

(II)

an estimate of the number of individuals and small business concerns affected by the cybersecurity risk or incident, including an assessment of the risk of harm to affected individuals and small business concerns.

(3)

Rule of construction

Nothing in this subsection shall be construed to affect the reporting requirements of the Administrator under chapter 35 of title 44, United States Code, in particular the requirement to notify the Federal information security incident center under section 3554(b)(7)(C)(ii) of such title, or any other provision of law.

(4)

Definitions

In this subsection:

(A)

Appropriate congressional committees

The term appropriate congressional committees means—

(i)

the Committee on Small Business and Entrepreneurship of the Senate; and

(ii)

the Committee on Small Business of the House of Representatives.

(B)

Cybersecurity risk; incident

The terms cybersecurity risk and incident have the meanings given such terms, respectively, under section 2209(a) of the Homeland Security Act of 2002.

.

Passed the House of Representatives July 15, 2019.

Cheryl L. Johnson,

Clerk

July 16, 2019

Received; read twice and placed on the calendar