Directs GAO to study and report on federal cybersecurity assistance for small businesses and recommend improvements; no new funding is authorized.
Official title: Require the Comptroller General to evaluate Federal cybersecurity assistance to small business concerns, and for other purposes.
Introduced August 6, 2026 by Adam Schiff · Last progress August 6, 2026
The bill funds a GAO study that can identify cyber threats, program gaps, and funding options to help small businesses improve cyber resilience, but it does not provide funding or require implementation, so meaningful benefits depend on follow-on resources and action.
Small-business owners will get a GAO study that clarifies the most common cyberattacks and provides clearer guidance on identifying, prioritizing, and recovering from incidents, improving their resilience against cyber threats.
The report will identify existing program gaps and recommend ways to improve awareness and uptake of federal resources, potentially increasing small-business use of existing help without new legislation.
The study will catalog sources of capital and financing options for cybersecurity and recovery, helping small businesses and lenders better understand and access funding for protections and recovery measures.
The study does not authorize funding or new programs, so federal recommendations may not be implemented quickly (or at all) without subsequent appropriations or legislative action.
If the GAO's recommendations are not paired with funding or targeted implementation plans, small businesses may see little practical change despite identified gaps and suggestions.
Conducting the study adds workload for the Comptroller General and federal staff without additional funding, which could delay completion or limit the scope and usefulness of the report.
Based on analysis of 2 sections of legislative text.
Directs the Government Accountability Office to study federal cybersecurity initiatives, tools, services, and resources aimed at helping small businesses identify and manage cyber risks, recover from attacks, and obtain financing for cybersecurity activities. The GAO must catalog offerings, assess small business awareness and use, evaluate coordination and effectiveness, identify missing foundational concepts, and recommend improvements to increase effectiveness, awareness, and coordination. Requires GAO to report findings and recommendations to the House and Senate small business committees. No new funding is authorized to carry out the study.