Congress demands SBA fix urgent IT security risks—and prove it
S. 4948 — SBA IT Modernization Reporting Act · Filed by Adam Schiff (D-CA) · 1 cosponsor · Introduced Jul 13, 2026 · Referred to committee
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This bill requires the Small Business Administration to create and submit a detailed plan within 180 days showing how it will fix serious IT system risks identified in a November 2024 government audit. The plan must establish policies for managing technology projects, including risk identification, cybersecurity oversight, contractor vetting, and cost controls—and the SBA must brief Congress on progress within 30 days of submission.
Why we flagged it
The bill is a straightforward oversight and accountability mechanism requiring the SBA to implement IT modernization best practices and report progress to Congress. It is not a spending bill, tax measure, or deregulation—it is a governance and transparency mandate.
What the text implies
- Establishes a precedent for congressional oversight of federal IT modernization across other agencies, potentially triggering similar reporting requirements elsewhere in government.
- May indirectly increase SBA operational costs in the near term as the agency hires or reallocates staff to implement new risk management and cybersecurity procedures.
The full analysis lists 3 implications of this text.
Who stands to gain
IT consulting and systems integration firms; Cybersecurity service providers; Government IT contractors with GAO-compliant project management experience