The bill aims to improve SBA IT security, budgeting, and accountability—benefiting small businesses and taxpayers—but raises near-term costs, risks procurement delays, and may under-deliver if additional funding isn't provided.
Small-business owners' data and SBA systems will be better protected because acquisition and strategic plans must include cybersecurity input and cyber-risk information.
Taxpayers and small-business owners should face fewer costly delays, outages, and surprise costs because SBA must adopt GAO best-practice guidance and clearer risk controls to produce more realistic schedules and cost estimates.
Taxpayers and Congress will get greater oversight and accountability for SBA IT modernization because the agency must provide briefings and committee submissions on project status and risks.
Small-business owners may experience slower delivery of IT improvements because stricter acquisition and contractor-selection requirements can lengthen procurement timelines.
Taxpayers and federal employees could face higher near-term costs because implementing and documenting new processes will increase SBA administrative workload and may require new hires or contractors.
Federal employees and small-business owners risk limited benefit if SBA lacks funding to fully implement GAO-recommended controls, since mandates could strain resources and lead to partial compliance.
Based on analysis of 3 sections of legislative text.
Requires the SBA to implement GAO IT modernization recommendations and deliver a plan within 180 days that enforces specified project controls and timelines.
Official title: Require the Administrator of the Small Business Administration to implement certain recommendations relating to information technology modernization, and for other purposes.
Introduced July 13, 2026 by Adam Schiff · Last progress July 13, 2026
Requires the Small Business Administration (SBA) Administrator, through the SBA Chief Information Officer, to implement recommendations from a GAO report on SBA IT modernization risks. Within 180 days of enactment the Administrator must submit to the House and Senate small business committees a detailed implementation plan that establishes policies and procedures for SBA IT modernization projects and meets specified risk-management, scheduling, cost-estimating, acquisition, traceability, and security requirements, and must brief those committees within 30 days after submitting the plan. The bill defines the terms “Administration” and “Administrator,” sets the short title, and assigns the SBA responsibility for tracking which office will implement each action and timelines for completion. The plan must address 11 enumerated controls and identify responsible offices and schedules for each item.