HR-8880-119
Motion to reconsider laid on the table Agreed to without objection.
Sponsored by Lateefah Simon (D-CA)
What it does
This bill would require the Government Accountability Office (GAO) — the nonpartisan congressional watchdog — to conduct a study of all existing federal cybersecurity programs, tools, and resources available to small businesses. The study would assess how aware small businesses are of these programs, how well the programs work, how well they are coordinated with each other, and what gaps exist. The GAO would then submit a report with findings and recommendations to the House and Senate Small Business committees. No new funds are authorized to carry out the study.
Who benefits
Small business owners who may gain access to better-coordinated or more visible federal cybersecurity resources as a result of the study's recommendations. Small businesses in sectors with high cyberattack rates (retail, healthcare, financial services) that are disproportionately targeted. Congress and policymakers who would receive actionable data to guide future legislation. Federal agencies whose programs may be better integrated or publicized. Cybersecurity vendors and consultants who may see increased demand if small businesses become more aware of cyber risks.
Who is hurt
Federal agencies whose programs are found to be ineffective or duplicative may face future budget pressure or consolidation. GAO staff would bear the workload of conducting the study, though this is within their existing mandate. Taxpayers bear a marginal cost if GAO reallocates resources from other studies, though no new appropriations are authorized. Small businesses that need immediate help — rather than a future report — would not benefit in the near term.
Supporters argue
Supporters argue that small businesses are the most frequent targets of cyberattacks — the SBA and CISA have both documented that small businesses account for 43% of all cyberattack targets — yet federal assistance is fragmented across multiple agencies with little coordination. They contend that a GAO study is a low-cost, evidence-based first step that ensures any future federal action is grounded in data rather than assumption, avoiding wasteful duplication of programs that may already exist.
Opponents argue
Opponents argue that the federal government already has extensive documentation of small business cybersecurity gaps through CISA, the SBA, and NIST, making another study an unnecessary delay before taking meaningful action. They contend that a report with no accompanying funding, mandates, or enforcement mechanisms is unlikely to produce real improvements for small businesses facing active cyber threats today, and that Congress could instead direct existing agencies to improve coordination without waiting for a GAO review.