Congress demands SBA fix broken IT systems before they fail again
H.R. 4491 — SBA IT Modernization Reporting Act · Filed by Gilbert Cisneros (D-CA) · 1 cosponsor · Introduced Jul 17, 2025 · Passed chamber
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This bill requires the Small Business Administration to implement recommendations from a November 2024 Government Accountability Office (GAO) report identifying serious IT security and project-management risks in the SBA's newly deployed systems. The SBA must submit a detailed implementation plan within 180 days outlining how it will adopt better risk management, cybersecurity, cost estimation, and project-scheduling practices for all future IT modernization projects, and brief Congress 30 days later on progress.
Why we flagged it
The bill is a straightforward mandate for the SBA to adopt better IT project management and cybersecurity practices based on GAO audit findings. It is a governance and accountability measure, not a spending bill, tax provision, or industry carve-out.
What the text implies
- The bill ties SBA IT modernization to specific GAO best-practice publications (Schedule Assessment Guide, Cost Estimating Guide), effectively embedding federal project-management standards into SBA operations and potentially raising the bar for IT governance across other federal agencies.
- Requiring security-subject-matter experts in contractor selection may increase procurement costs and timelines for SBA IT projects, but reduces the risk of security-compromised systems that could expose small-business data.
The full analysis lists 3 implications of this text.
Who stands to gain
IT consulting and systems-integration firms (potential contractors for SBA modernization projects); Cybersecurity service providers