SBA must share cybersecurity guidance with small businesses
H.R. 10238 — Cybersecurity for Small Businesses Act of 2026 · Filed by Tony Wied (R-WI) · 2 cosponsors · Introduced Sep 2, 2026 · Referred to committee
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This bill requires the Small Business Administration (SBA) to create and share cybersecurity information and resources with small businesses, including guidance on federal contracting requirements like the Cybersecurity Maturity Model Certification program. The SBA must work with the Cybersecurity and Infrastructure Security Agency, the Department of Defense, and other federal agencies to distribute this information through SBA development centers and websites, and must report annually to Congress on how many small businesses seek cybersecurity help.
Why we flagged it
The bill's sole operative mechanism is a mandate for federal agencies to develop and disseminate cybersecurity information and resources to small businesses. It is a straightforward information-sharing and technical-assistance measure with no regulatory, financial, or commemorative components.
What the text implies
- Annual reporting requirement may create administrative burden on the SBA's Office of Advocacy, though the burden appears modest (90-day initial report, then annual updates).
- Coordination across multiple federal agencies (SBA, CISA, DoD, others) may face implementation delays or inconsistent messaging if agencies do not align on resource priorities.
The full analysis lists 3 implications of this text.
Who it affects
Small business owners gain free access to federal cybersecurity guidance and compliance resources, reducing their costs and security vulnerabilities. The bill imposes no new restrictions on citizens or businesses—it only requires the SBA to share information already held by federal agencies.