← My Government dashboard

Government Watch

Dossier Legislative introduced 02-dec-2025
Bill introduced in Congress — not yet passed by either chamber, and not law.

SBA IT Modernization Reporting Act

Key claim: The SBA IT Modernization Reporting Act (HR4491) requires the Small Business Administration to implement GAO recommendations on modernizing its IT systems—including risk management and cybersecurity for its small-business contracting certification project—and to submit an implementation plan to Congress within 180 days of enactment.

Abstract

(HR4491 · 119th Congress) SBA IT Modernization Reporting Act This bill requires the Small Business Administration (SBA) to implement the recommendations from a Government Accountability Office (GAO) report published on November 6, 2024, related to modernizing the SBA’s information technology systems. Specifically, the SBA must address risks related to its certification project that allows small businesses to apply for and manage government contracting certifications. The GAO recommendations include developing a project risk management strategy and risk mitigation plan and managing cybersecurity vulnerabilities. The SBA must submit to Congress an implementation plan for the modernization not later than 180 days after the enactment of this bill. Latest action (2025-12-02): Received in the Senate and Read twice and referred to the Committee on Small Business and Entrepreneurship.

Why this matters

The bill converts nonbinding GAO recommendations into a statutory reporting obligation, using congressional oversight to compel SBA to address known cybersecurity and risk-management gaps in its contracting certification IT systems. Because SBA’s certification platforms underpin federal small-business set-aside eligibility, unresolved vulnerabilities have downstream implications for procurement integrity across agencies.

Source

Link

Briefing card

SBA IT Modernization Reporting Act
Stage: introduced · congress · 02-dec-2025

The SBA IT Modernization Reporting Act (HR4491) requires the Small Business Administration to implement GAO recommendations on modernizing its IT systems—including risk management and cybersecurity for its small-business contracting certification project—and to submit an implementation plan to Congress within 180 days of enactment.

Cross-references (0)

None recorded — doctrine links and citations appear here as scans and citation sweeps find them.

External: congress:119-hr-4491:introduced

Ask about this finding

Replies are grounded in the abstract and metadata above. The model will quote directly when possible and say so if a question isn't covered.

Stages other doctrine resolution introduced proposed rule passed chamber executive action final rule enacted district opinion circuit opinion opinion

build build 392 · ea9c128-dirty · 2026-08-09