H.R. 10238House119th Congress (2025-2027)In Committee

Cybersecurity for Small Businesses Act of 2026

Sponsored by Tony WiedRep. Tony Wied (R-WI)
Introduced September 2, 2026

AI-Generated Summary

Updated September 3, 2026 at 11:51 AM UTC

The Cybersecurity for Small Businesses Act of 2026 directs the Small Business Administration (SBA) to create and share cybersecurity guidance and resources with small businesses. It focuses on helping firms, especially those pursuing federal contracts or subcontracts, improve their cyber defenses and meet government security requirements.

Key Provisions

  • The SBA Administrator, working with the Cybersecurity and Infrastructure Security Agency, must develop and distribute information to help small businesses strengthen their cybersecurity and adopt best practices.
  • The SBA, in coordination with the Department of Defense and other federal agencies, must provide guidance on the Cybersecurity Maturity Model Certification (or any successor program) to small businesses seeking federal contracts, using Small Business Development Centers and SBA district offices.
  • The SBA must publish this cybersecurity information on its website and include it in its outreach communications.
  • The SBA’s Chief Counsel for Advocacy must consult annually on best ways to share cybersecurity information and must submit a report to Congress each year (first due within 90 days of enactment) detailing how many small businesses sought cybersecurity assistance.

Legislative Activity

Stay on top of the latest movement without scrolling through every action

3 earlier actions
HouseCommittee Latest Action

Ordered to be Reported in the Nature of a Substitute by the Yeas and Nays: 23 - 0.

September 16, 2026

View full timeline
HouseIntro Referral

Introduced in House

September 2, 2026

HouseIntro Referral

Referred to the House Committee on Small Business.

September 2, 2026

HouseCommittee

Committee Consideration and Mark-up Session Held

September 16, 2026

HouseCommittee

Ordered to be Reported in the Nature of a Substitute by the Yeas and Nays: 23 - 0.

September 16, 2026

Bill Text

Latest available legislative text

Reading Mode
Latest
Introduced in HouseIssued September 2, 2026

I

119th CONGRESS

2d Session

H. R. 10238

IN THE HOUSE OF REPRESENTATIVES

September 2, 2026

Mr. Wied (for himself, Ms. King-Hinds, and Ms. Van Duyne) introduced the following bill; which was referred to the Committee on Small Business

A BILL

To require the Administrator of the Small Business Administration to disseminate to small business concerns certain information and resources relating to cybersecurity matters, and for other purposes.

1.

Short title

This Act may be cited as the Cybersecurity for Small Businesses Act of 2026.

2.

Information and resources relating to cybersecurity matters for small business concerns

The Administrator of the Small Business Administration, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, shall develop and disseminate information and resources to assist small business concerns in strengthening the cybersecurity infrastructure of such concerns and implementing cybersecurity best practices.

3.

Cybersecurity compliance information

(a)

Cybersecurity compliance resources

The Administrator of the Small Business Administration, in coordination with the Secretary of Defense and other appropriate Federal agencies, shall disseminate information to a small business concern seeking to enter into a contract with the Federal Government, or seeking to be a subcontractor on a Federal contract, regarding the Cybersecurity Maturity Model Certification program (or successor program), including information necessary to facilitate compliance with such requirements, through small business development centers (as defined in section 3 of the Small Business Act (15 U.S.C. 632)) and district offices of the Administration.

(b)

Publication

The Administrator shall include the information described in subsection (a) in outreach and communications of the Small Business Administration, including through publication on a website of the Administration.

(c)

Best practices

The Administrator shall annually consult with the Chief Counsel for Advocacy of the Office of Advocacy of the Administration to determine best practices for the dissemination of other information relating to cybersecurity matters to small business concerns.

(d)

Annual report

Not later than 90 days after the date of the enactment of this Act, and annually thereafter, the Chief Counsel for Advocacy shall submit to Congress a report that includes the number and a description of small business concerns that contacted the Chief Counsel for Advocacy during the year covered by the report with matters relating to cybersecurity of such concerns.