S. 770Senate115th Congress (2017-2019)Enacted

NIST Small Business Cybersecurity Act

Introduced March 29, 2017

AI-Generated Summary

Updated April 15, 2026 at 2:27 PM UTC

The NIST Small Business Cybersecurity Act requires the directorof the National Institute of Standards and Technology to create and share easy‑to‑use guidance that helps small businesses identify, assess, and reduce cyber risks. The guidance must be tailored to different sizes and data sensitivities, be technology‑neutral, and align with existing cybersecurity programs. The law affects small business concerns nationwide and the NIST agency that will develop and update the resources.

Key Provisions

  • Adds a new clause to the NIST Act directing the agency to consider small business concerns when setting its cybersecurity priorities.
  • Mandates that within one year the NIST director, in consultation with other federal agencies, disseminates clear, concise resources for small businesses to manage cyber risks.
  • Specifies that the resources must be broadly applicable, adaptable to business size and data sensitivity, promote basic controls and a cybersecurity culture, include case studies, be technology‑neutral, and follow international standards where possible.
  • Requires the resources to be consistent with the Cybersecurity Enhancement Act’s awareness and education efforts and to consider the Small Business Development Center cyber strategy.
  • States that use of the resources is voluntary for small businesses.
  • Requires periodic review, updates, and public posting of the resources and any changes on agency websites.
  • Clarifies that the act does not change any existing federal agency cybersecurity requirements and is funded from NIST’s existing appropriations.

Legislative Activity

Stay on top of the latest movement without scrolling through every action

24 earlier actions
Became Law Latest Action

Became Public Law No: 115-236.

August 14, 2018

View full timeline
SenateIntro Referral

Introduced in Senate

March 29, 2017

SenateIntro Referral

Read twice and referred to the Committee on Commerce, Science, and Transportation.

March 29, 2017

SenateCommittee

Committee on Commerce, Science, and Transportation. Ordered to be reported with an amendment in the nature of a substitute favorably.

April 5, 2017

SenateCommittee

Committee on Commerce, Science, and Transportation. Reported by Senator Thune with an amendment in the nature of a substitute. With written report No. 115-153.

September 11, 2017

SenateCalendars

Placed on Senate Legislative Calendar under General Orders. Calendar No. 217.

September 11, 2017

SenateFloor

Measure laid before Senate by unanimous consent. (consideration: CR S6232-6233)

September 28, 2017

SenateFloor

The committee substitute as amended agreed to by Unanimous Consent.

September 28, 2017

SenateFloor

Passed Senate with an amendment by Unanimous Consent. (text: CR S6233)

September 28, 2017

SenateFloor

Message on Senate action sent to the House.

September 29, 2017

HouseFloor

Received in the House.

October 2, 2017 • 2:04 PM

HouseFloor

Held at the desk.

October 2, 2017 • 4:51 PM

SenateCommittee

Committee on Small Business and Entrepreneurship. Hearings held. Hearings printed: S.Hrg. 115-300.

April 25, 2018

HouseFloor

Mr. Webster (FL) asked unanimous consent to take from the Speaker's table and consider.

July 25, 2018 • 2:23 PM

HouseFloor

Considered by unanimous consent. (consideration: CR H7201-7202)

July 25, 2018 • 2:24 PM

SenateFloor

Passed/agreed to in House: On passage Passed without objection.(text: CR H7201)

July 25, 2018 • 2:25 PM

HouseFloor

On passage Passed without objection. (text: CR H7201)

July 25, 2018 • 2:25 PM

HouseFloor

Motion to reconsider laid on the table Agreed to without objection.

July 25, 2018 • 2:25 PM

HouseFloor

The title of the measure was amended. Agreed to without objection.

July 25, 2018 • 2:25 PM

SenateFloor

Message on House action received in Senate and at desk: House amendments to Senate bill.

July 26, 2018

SenateNot Used

Resolving differences -- Senate actions: Senate agreed to the House amendments to S. 770 by Unanimous Consent.(text as Senate agree to the House amendment: CR S5561)

August 1, 2018

SenateResolving Differences

Senate agreed to the House amendments to S. 770 by Unanimous Consent. (text as Senate agree to the House amendment: CR S5561)

August 1, 2018

SenateFloor

Message on Senate action sent to the House.

August 2, 2018

President

Presented to President.

August 3, 2018

Became Law

Signed by President.

August 14, 2018

Became Law

Became Public Law No: 115-236.

August 14, 2018

Floor Debate

9 members

What members said about S. 770 on the floor

7 Republicans2 Democrats
Daniel Webster
Rep. Daniel WebsterR-FL-11 · Oct 11, 2017

Mr. Speaker, I move to suspend the rules and pass the bill (H.R. 2105) to require the Director of the National Institute of Standards and Technology to disseminate guidance to help reduce small…

Daniel Lipinski
Rep. Daniel LipinskiD-IL-3 · Oct 11, 2017

Mr. Speaker, I yield myself such time as I may consume. Mr. Speaker, I rise in support of H.R. 2105, the NIST Small Business Cybersecurity Act of 2017, a bipartisan effort to help small businesses…

Eddie Bernice Johnson
Rep. Eddie Bernice JohnsonD-TX-30 · Oct 11, 2017

Mr. Speaker, I rise in support of H.R. 2105, the NIST Small Business Cybersecurity Act of 2017, which directs the National Institute of Standards and Technology to provide more guidance, resources,…

Lamar Smith
Rep. Lamar SmithR-TX-21 · Oct 11, 2017

Mr. Speaker, I thank the gentleman from Florida (Mr. Webster) for yielding me time and for introducing H.R. 2105, the NIST Small Business Cybersecurity Act. This important and timely bipartisan bill,…

Barbara Comstock
Rep. Barbara ComstockR-VA-10 · Oct 11, 2017

Mr. Speaker, I rise in support of H.R. 2105. When I travel around my district, which is rich with technology workers, the thing that I hear repeated concern about is the increasing need for…

Show 6 more
Neal P. Dunn
Rep. Neal P. DunnR-FL-2 · Oct 11, 2017

Mr. Speaker, today I rise in support of H.R. 2105, the National Institute of Standards and Technology Small Business Cybersecurity Act. This bipartisan legislation instructs the Director of NIST, in…

Don Bacon
Rep. Don BaconR-NE-2 · Oct 11, 2017

Mr. Speaker, I rise in support of the National Institute of Standards and Technology Small Business Cybersecurity Act, a bill that I am proud to cosponsor. This legislation will help promote stronger…

Ralph Norman
Rep. Ralph NormanR-SC-5 · Oct 11, 2017

Mr. Speaker, I rise today in support of H.R. 2105, the National Institute of Standards and Technology Small Business Cybersecurity Act. This bill directs the National Institute of Standards and…

Mitch McConnell
Sen. Mitch McConnellR-KY · Aug 1, 2018

Mr. President, I ask that the Chair lay before the Senate the House message to accompany S. 770. The Presiding Officer laid before the Senate the following message from the House of Representatives:…

Mitch McConnell
Sen. Mitch McConnellR-KY · Sep 28, 2017

Mr. President, I ask unanimous consent that the Senate proceed to the immediate consideration of Calendar No. 217, S. 770. I ask unanimous consent that the committee-reported substitute amendment be…

Daniel Webster
Rep. Daniel WebsterR-FL-11 · Jul 25, 2018

Mr. Speaker, I ask unanimous consent to take from the Speaker's table the bill (S. 770) to require the Director of the National Institute of Standards and Technology to disseminate resources to help…

Bill Text

6 versions available

Reading Mode
Latest
Enrolled BillPublication date not provided

One Hundred Fifteenth Congress of the United States of America

2d Session

Begun and held at the City of Washington on Wednesday, the third day of January, two thousand and eighteen

S. 770

AN ACT

To require the Director of the National Institute of Standards and Technology to disseminate guidance to help reduce small business cybersecurity risks, and for other purposes.

1.

Short title

This Act may be cited as the NIST Small Business Cybersecurity Act.

2.

Improving cybersecurity of small businesses

(a)

Definitions

In this section:

(1)

Director

The term Director means the Director of the National Institute of Standards and Technology.

(2)

Resources

The term resources means guidelines, tools, best practices, standards, methodologies, and other ways of providing information.

(3)

Small business concern

The term small business concern has the meaning given such term in section 3 of the Small Business Act (15 U.S.C. 632).

(b)

Small business cybersecurity

Section 2(e)(1)(A) of the National Institute of Standards and Technology Act (15 U.S.C. 272(e)(1)(A)) is amended—

(1)

in clause (vii), by striking and at the end;

(2)

by redesignating clause (viii) as clause (ix); and

(3)

by inserting after clause (vii) the following:

(viii)

consider small business concerns (as defined in section 3 of the Small Business Act (15 U.S.C. 632)); and

.

(c)

Dissemination of resources for small businesses

(1)

In general

Not later than one year after the date of the enactment of this Act, the Director, in carrying out section 2(e)(1)(A)(viii) of the National Institute of Standards and Technology Act, as added by subsection (b) of this Act, in consultation with the heads of other appropriate Federal agencies, shall disseminate clear and concise resources to help small business concerns identify, assess, manage, and reduce their cybersecurity risks.

(2)

Requirements

The Director shall ensure that the resources disseminated pursuant to paragraph (1)—

(A)

are generally applicable and usable by a wide range of small business concerns;

(B)

vary with the nature and size of the implementing small business concern, and the nature and sensitivity of the data collected or stored on the information systems or devices of the implementing small business concern;

(C)

include elements, that promote awareness of simple, basic controls, a workplace cybersecurity culture, and third-party stakeholder relationships, to assist small business concerns in mitigating common cybersecurity risks;

(D)

include case studies of practical application;

(E)

are technology-neutral and can be implemented using technologies that are commercial and off-the-shelf; and

(F)

are based on international standards to the extent possible, and are consistent with the Stevenson-Wydler Technology Innovation Act of 1980 (15 U.S.C. 3701 et seq.).

(3)

National cybersecurity awareness and education program

The Director shall ensure that the resources disseminated under paragraph (1) are consistent with the efforts of the Director under section 401 of the Cybersecurity Enhancement Act of 2014 (15 U.S.C. 7451).

(4)

Small Business Development Center Cyber Strategy

In carrying out paragraph (1), the Director, to the extent practicable, shall consider any methods included in the Small Business Development Center Cyber Strategy developed under section 1841(a)(3)(B) of the National Defense Authorization Act for Fiscal Year 2017 (Public Law 114–328).

(5)

Voluntary resources

The use of the resources disseminated under paragraph (1) shall be considered voluntary.

(6)

Updates

The Director shall review and, if necessary, update the resources disseminated under paragraph (1) in accordance with the requirements under paragraph (2).

(7)

Public availability

The Director and the head of each Federal agency that so elects shall make prominently available on the respective agency’s public Internet website information about the resources and updates to the resources disseminated under paragraph (1). The Director and the heads shall each ensure that the information they respectively make prominently available is consistent, clear, and concise.

(d)

Other Federal cybersecurity requirements

Nothing in this section may be construed to supersede, alter, or otherwise affect any cybersecurity requirements applicable to Federal agencies.

(e)

Funding

This Act shall be carried out using funds otherwise authorized to be appropriated or made available to the National Institute of Standards and Technology.

Speaker of the House of Representatives

Vice President of the United States and President of the Senate