HR-10238-119
Referred to the House Committee on Small Business.
Sponsored by Tony Wied (R-WI)
What it does
This bill would require the Small Business Administration to develop and share cybersecurity information and best practices with small businesses, working with the Cybersecurity and Infrastructure Security Agency. It would also require the SBA to distribute information about Cybersecurity Maturity Model Certification (CMMC) compliance to small businesses seeking federal contracts, through small business development centers and district offices, and requires an annual report to Congress on related inquiries.
Who benefits
Small businesses, especially those seeking federal contracts or subcontracts requiring cybersecurity certification, who would gain access to compliance guidance and best-practice information. Small business development centers and SBA district offices, which would receive an expanded informational role. Federal contracting agencies, including the Department of Defense, that benefit from better-prepared small business contractors.
Who is hurt
No group is meaningfully harmed; the bill creates an information-dissemination duty rather than new compliance obligations. Cybersecurity consulting firms serving small businesses could see reduced demand if free SBA guidance substitutes for paid advisory services. SBA and CISA staff would bear modest administrative burden in producing materials and annual reports.
Supporters argue
Supporters argue that small businesses often lack the resources and technical expertise to navigate complex cybersecurity requirements like CMMC, putting them at a disadvantage when competing for federal contracts. They contend that free, centralized guidance from the SBA and CISA would reduce compliance costs, help prevent cyberattacks that could disrupt small business operations, and preserve small business participation in the federal supply chain.
Opponents argue
Opponents argue that the bill creates another reporting and coordination requirement without dedicated funding, risking underfunded or superficial implementation that duplicates existing SBA and CISA outreach efforts. They contend that information dissemination alone does little to address the underlying cost and complexity of cybersecurity compliance, potentially giving false assurance that the government has solved a problem it has only lightly addressed.