WASHINGTON, DC - Congressman Tony Wied (R-WI) introduced legislation this week to help small businesses strengthen their cybersecurity while streamlining coordination among federal agencies to reduce unnecessary costs.
The Cybersecurity for Small Businesses Act requires the Small Business Administration to work with the Cybersecurity and Infrastructure Security Agency to provide small businesses with information on cybersecurity best practices. It also requires coordination with the Secretary of War to provide specific information on the levels of cybersecurity requirements under the Department of War's Cybersecurity Maturity Model Certification (CMMC) program.
"In today's rapidly evolving digital world, it is critical for small businesses to maintain the highest-quality and most up-to-date cybersecurity infrastructure," said Congressman Wied. "However, small businesses shouldn't be forced to spend hundreds of thousands of dollars to obtain a level of cybersecurity they don't need simply because Washington has failed to provide clear rules. The Cybersecurity for Small Businesses Act will provide much-needed clarity to help small businesses protect themselves without forcing them to spend excessive amounts of money trying to comply with vague guidelines."
Background: Cybersecurity has become an increasingly important consideration for small businesses, but many struggle to find clear, up-to-date guidance. Currently, the SBA's website provides some information for small businesses looking to secure their cyber infrastructure, but it may not reflect other agencies' best-practice recommendations. This leaves small businesses' cyber infrastructure vulnerable to nefarious actors. Additionally, the SBA lacks information on complying with the Department of War's new cybersecurity initiative, the Cybersecurity Maturity Model Certification (CMMC). This certification is multi-tiered based on the sensitive information a contractor or subcontractor may handle. The DoW has paused Phase II and III requirements while it conducts a 60-day review. Before the temporary pause, many small businesses were unsure of which level they were required to have. Without clear instructions, many were forced to spend upwards of hundreds of thousands of dollars to comply with requirements they may not have needed. This bill ensures the SBA can provide small businesses with the most accurate and relevant information once Phase II and III requirements are reimplemented.
Representatives Beth Van Duyne (R-TX) and Kimberlyn King-Hinds (R-CNMI) are original cosponsors of this legislation.
"North Texas is one of America's fastest-growing hubs for firms offering professional, scientific, and technical services, and thousands of tech-oriented small businesses call our region home. They shouldn't have to spend six figures trying to decipher Washington's one-size-fits-all bureaucratic cybersecurity rules. I am glad to help introduce the Cybersecurity for Small Business Act to give small businesses clear guidance on best practices to protect their networks without wasting time and money on unnecessary requirements," said Congresswoman Van Duyne.
"Cyberattacks do not just target the federal government or large corporations. Small businesses are also targets for foreign adversaries, including the Chinese Communist Party. Many lack the resources or expertise of larger companies to protect themselves. These attacks cost American businesses and our economy. This legislation gives small businesses clearer access to federal cybersecurity guidance. It also helps those seeking to work with the federal government understand the requirements they need to meet. Protecting America's small businesses is part of protecting our economy and our national security," said Congresswoman King-Hinds.
The Cybersecurity for Small Businesses Act:
-
Requires the Small Business Administration to collaborate with the Cybersecurity and Infrastructure
-
Security Agency to provide small businesses with information on cybersecurity best practices.
-
Requires the Small Business Administration, in coordination with the Secretary of War to provide specific information related to the levels of cybersecurity requirements for the Department of War's Cybersecurity Maturity Model Certification (CMMC).
-
Requires the Administrator to consult the Chief Counsel for Advocacy at the SBA's Office of Advocacy to determine best practices for disseminating information.
-
Adds an annual reporting requirement to Section 10 of the Small Business Act.
Read the full bill text HERE.