SBA IT Modernization Reporting Act
Click any stage to learn more about the legislative process.
Would require the Small Business Administration to implement specific GAO recommendations for modernizing its IT systems — particularly a certification platform that helps small businesses apply for and manage federal contracting certifications — and submit a detailed implementation plan to Congress within 180 days of enactment.
What this bill would do
What it would do
The bill would direct the SBA Administrator, acting through the agency's Chief Information Officer, to implement the recommendations from a GAO report published November 6, 2024 (GAO-25-106963), titled "IT MODERNIZATION: SBA Urgently Needs to Address Risks on Newly Deployed System." It would require the SBA to submit an implementation plan to the House and Senate Small Business committees within 180 days of enactment, detailing policies and procedures to govern the agency's IT modernization projects. That plan must cover eleven specific areas, including identifying and documenting project risks, managing cybersecurity vulnerabilities, ensuring strategic plans address cyber risks, involving security experts in contractor selection, and building project schedules and cost estimates using established GAO best-practice guides.
The bill would not itself appropriate money or mandate completion of the modernization — it focuses on requiring a formal, documented plan and accountability to Congress. Within 30 days of submitting the plan, the SBA Administrator would also be required to brief both congressional small business committees on its contents.
Key provisions
- 1Would require the SBA Administrator, through the Chief Information Officer, to implement all recommendations from GAO report GAO-25-106963 on SBA IT modernization risks.
- 2Would require the SBA to submit an IT modernization implementation plan to congressional small business committees within 180 days of enactment, covering eleven specific risk-management and cybersecurity policy areas.
- 3Would require the implementation plan to identify the responsible SBA office and completion timelines for each of the eleven required policy and procedure areas.
- 4Would require the SBA Administrator to brief both congressional small business committees on the implementation plan within 30 days of its submission.
Who would be affected
The Small Business Administration — specifically its Administrator and Chief Information Officer — would bear the primary obligations. Small businesses that use SBA's certification platform to apply for and manage federal contracting certifications would be the downstream beneficiaries of a more secure, modernized system. Congressional small business committees would receive the implementation plan and briefing.
Why it matters
If enacted, the SBA would face a hard deadline to produce a structured, publicly accountable roadmap for fixing risks in a certification system used by small businesses seeking federal contracts. Without such a plan, the GAO-identified cybersecurity vulnerabilities and project management gaps in that system could remain unaddressed, potentially exposing small business applicants' data and disrupting access to contracting programs.
What would change
Agencies directed to act
Effective dates
- Deadline for SBA to submit IT modernization implementation plan to Congress
- Deadline for SBA Administrator to brief congressional committees on the plan
How implementation would work
The SBA Administrator, acting through the Chief Information Officer, would have 180 days after enactment to submit a written implementation plan to both congressional small business committees. The plan must specify which office within SBA is responsible for each action and set timelines for completion. Within 30 days of submitting the plan, the Administrator must also personally brief the committees. The bill does not require agency rulemaking; compliance is measured by the timely submission of the plan and the briefing. There is no explicit enforcement mechanism beyond the reporting obligation itself.
Legislative status & sources
Latest action
Received in the Senate and Read twice and referred to the Committee on Small Business and Entrepreneurship.
Official CRS summary
Show the CRS summaryHide the CRS summary
This bill requires the Small Business Administration (SBA) to implement the recommendations from a Government Accountability Office (GAO) report published on November 6, 2024, related to modernizing the SBA's information technology systems.
Specifically, the SBA must address risks related to its certification project that allows small businesses to apply for and manage government contracting certifications. The GAO recommendations include developing a project risk management strategy and risk mitigation plan and managing cybersecurity vulnerabilities.
The SBA must submit to Congress an implementation plan for the modernization not later than 180 days after the enactment of this bill.
Legislative subjects
Commerce; Computer security and identity theft; Computers and information technology; Small Business Administration; Technology assessment
Committee report
H. Rept. 119-223