HR 4491 · 119th Congress

SBA IT Modernization Reporting Act

small business contractinggovernment IT modernizationcybersecurityfederal oversight
Share

Last action 2025-12-02

Sponsored by Rep. Cisneros, Gilbert Ray [D-CA-31] (D) — CA

Click any stage to learn more about the legislative process.

Would require the Small Business Administration to implement specific GAO recommendations for modernizing its IT systems — particularly a certification platform that helps small businesses apply for and manage federal contracting certifications — and submit a detailed implementation plan to Congress within 180 days of enactment.

What this bill would do

What it would do

The bill would direct the SBA Administrator, acting through the agency's Chief Information Officer, to implement the recommendations from a GAO report published November 6, 2024 (GAO-25-106963), titled "IT MODERNIZATION: SBA Urgently Needs to Address Risks on Newly Deployed System." It would require the SBA to submit an implementation plan to the House and Senate Small Business committees within 180 days of enactment, detailing policies and procedures to govern the agency's IT modernization projects. That plan must cover eleven specific areas, including identifying and documenting project risks, managing cybersecurity vulnerabilities, ensuring strategic plans address cyber risks, involving security experts in contractor selection, and building project schedules and cost estimates using established GAO best-practice guides.

The bill would not itself appropriate money or mandate completion of the modernization — it focuses on requiring a formal, documented plan and accountability to Congress. Within 30 days of submitting the plan, the SBA Administrator would also be required to brief both congressional small business committees on its contents.

Key provisions

  1. 1Would require the SBA Administrator, through the Chief Information Officer, to implement all recommendations from GAO report GAO-25-106963 on SBA IT modernization risks.Sec. 2(a)
  2. 2Would require the SBA to submit an IT modernization implementation plan to congressional small business committees within 180 days of enactment, covering eleven specific risk-management and cybersecurity policy areas.Sec. 2(b)
  3. 3Would require the implementation plan to identify the responsible SBA office and completion timelines for each of the eleven required policy and procedure areas.Sec. 2(c)
  4. 4Would require the SBA Administrator to brief both congressional small business committees on the implementation plan within 30 days of its submission.Sec. 2(d)

Who would be affected

The Small Business Administration — specifically its Administrator and Chief Information Officer — would bear the primary obligations. Small businesses that use SBA's certification platform to apply for and manage federal contracting certifications would be the downstream beneficiaries of a more secure, modernized system. Congressional small business committees would receive the implementation plan and briefing.

Why it matters

If enacted, the SBA would face a hard deadline to produce a structured, publicly accountable roadmap for fixing risks in a certification system used by small businesses seeking federal contracts. Without such a plan, the GAO-identified cybersecurity vulnerabilities and project management gaps in that system could remain unaddressed, potentially exposing small business applicants' data and disrupting access to contracting programs.

What would change

Agencies directed to act

Small Business Administration

Effective dates

  • Deadline for SBA to submit IT modernization implementation plan to CongressSec. 2(b)Within 180 days of enactment
  • Deadline for SBA Administrator to brief congressional committees on the planSec. 2(d)Within 30 days of the plan's submission

How implementation would work

The SBA Administrator, acting through the Chief Information Officer, would have 180 days after enactment to submit a written implementation plan to both congressional small business committees. The plan must specify which office within SBA is responsible for each action and set timelines for completion. Within 30 days of submitting the plan, the Administrator must also personally brief the committees. The bill does not require agency rulemaking; compliance is measured by the timely submission of the plan and the briefing. There is no explicit enforcement mechanism beyond the reporting obligation itself.

Legislative status & sources

Latest action

Received in the Senate and Read twice and referred to the Committee on Small Business and Entrepreneurship.

2025-12-02

Official CRS summary

Show the CRS summary

This bill requires the Small Business Administration (SBA) to implement the recommendations from a Government Accountability Office (GAO) report published on November 6, 2024, related to modernizing the SBA's information technology systems.

Specifically, the SBA must address risks related to its certification project that allows small businesses to apply for and manage government contracting certifications. The GAO recommendations include developing a project risk management strategy and risk mitigation plan and managing cybersecurity vulnerabilities.

The SBA must submit to Congress an implementation plan for the modernization not later than 180 days after the enactment of this bill.

From the Congressional Research Service.

Legislative subjects

Commerce; Computer security and identity theft; Computers and information technology; Small Business Administration; Technology assessment

Committee report

H. Rept. 119-223

Congressional Bill

Ask GovernmentReporter about this bill

Ask anything about this bill. The AI can look up referenced laws and statutes to provide context.

HR 4491: SBA IT Modernization Reporting Act | Legislation Reporter