SBA IT Modernization Reporting Act
Key claim: The SBA IT Modernization Reporting Act (HR4491) requires the Small Business Administration to implement GAO recommendations on modernizing its IT systems—including risk management and cybersecurity for its small-business contracting certification project—and to submit an implementation plan to Congress within 180 days of enactment.
Abstract
(HR4491 · 119th Congress) SBA IT Modernization Reporting Act This bill requires the Small Business Administration (SBA) to implement the recommendations from a Government Accountability Office (GAO) report published on November 6, 2024, related to modernizing the SBA’s information technology systems. Specifically, the SBA must address risks related to its certification project that allows small businesses to apply for and manage government contracting certifications. The GAO recommendations include developing a project risk management strategy and risk mitigation plan and managing cybersecurity vulnerabilities. The SBA must submit to Congress an implementation plan for the modernization not later than 180 days after the enactment of this bill. Latest action (2025-12-02): Received in the Senate and Read twice and referred to the Committee on Small Business and Entrepreneurship.
Why this matters
The bill converts nonbinding GAO recommendations into a statutory reporting obligation, using congressional oversight to compel SBA to address known cybersecurity and risk-management gaps in its contracting certification IT systems. Because SBA’s certification platforms underpin federal small-business set-aside eligibility, unresolved vulnerabilities have downstream implications for procurement integrity across agencies.