H.R. 10238 (119th)Bill Overview

Cybersecurity for Small Businesses Act of 2026

domestic policy
Cosponsors
Support
Republican
Introduced
Sep 2, 2026
Discussions
Bill Text
Current stageCommittee

Referred to the House Committee on Small Business.

Introduced
Committee
Floor
President
Law
Congressional Activities
01 · The brief
Plain-English summaryWhat this bill actually does

Requires the Small Business Administration, with CISA consultation, to develop and share cybersecurity information and resources for small businesses. Mandates SBA outreach on Cybersecurity Maturity Model Certification (CMMC) compliance for federal contract seekers via small business development centers and district offices.

Why people may split

Progressives want funding and targeted outreach; conservatives worry about new federal costs

Watch point

Relative to its intended legislative type, this bill clearly assigns administrative duties to the SBA and related offices to develop and disseminate cybersecurity information to small businesses and establishes a recurring reporting mechanism.

Requires the Small Business Administration, with CISA consultation, to develop and share cybersecurity information and resources for small businesses.

Mandates SBA outreach on Cybersecurity Maturity Model Certification (CMMC) compliance for federal contract seekers via small business development centers and district offices.

Requires SBA publication of materials online, annual consultation with the Chief Counsel for Advocacy on dissemination best practices, and an annual report from the Chief Counsel describing small businesses that contacted the office about cybersecurity.

Passage75/100

Small, administratively focused bills that aid businesses and impose minimal costs historically pass more easily; modest bureaucratic coordination is the main friction.

CredibilityPartially aligned

Relative to its intended legislative type, this bill clearly assigns administrative duties to the SBA and related offices to develop and disseminate cybersecurity information to small businesses and establishes a recurring reporting mechanism. It uses existing institutional channels (SBDCs, district offices, SBA website) and names coordinating agencies.

Contention52/100

Progressives want funding and targeted outreach; conservatives worry about new federal costs

02 · What it does

Who stands to gain, and who may push back.

Likely benefits vs burdens50% / 50%
Small businesses · Federal agenciesTaxpayers · Federal agencies

These are examples from the analysis, not a ranked list of the most-affected groups.

Likely helped
  • Small businessesIncreases small businesses' access to cybersecurity best practices, potentially reducing breach frequency and recovery…
  • Federal agenciesImproves small firms' ability to comply with federal contractor cybersecurity requirements, aiding contract eligibility…
  • Small businessesCentralizes guidance via SBA websites and SBDCs, lowering search and compliance costs for small businesses.
Likely burdened
  • TaxpayersRequires SBA staff time and funding for development and maintenance, creating potential taxpayer costs.
  • Potential burdenGuidance on programs like CMMC could become outdated or incomplete, leaving firms with compliance uncertainty.
  • Federal agenciesDuplicates existing federal, state, or private cybersecurity resources, potentially causing inefficiencies and confusio…
03 · Why people split

Why the argument around this bill splits.

Progressives want funding and targeted outreach; conservatives worry about new federal costs
Progressive80%

Generally supportive because it expands federal assistance and access to cybersecurity resources for small businesses.

Likely to seek stronger funding, targeted outreach to underserved businesses, and explicit protections for privacy and equity.

Leans supportive
Centrist70%

Cautiously supportive as pragmatic help for small businesses seeking federal contracts and better cyber hygiene.

Will want clarity on funding, timelines, duplication avoidance, and measurable outcomes.

Leans supportive
Conservative35%

Skeptical about expanding federal roles, but acknowledges value in helping small businesses with cybersecurity.

Concerned about bureaucratic growth and potential increased compliance costs for vendors.

Likely resistant
04 · Can it pass?

The path through Congress.

Introduced

Reached or meaningfully advanced

Committee

Reached or meaningfully advanced

Floor

Still ahead

President

Still ahead

Law

Still ahead

Passage likelihood75/100

Small, administratively focused bills that aid businesses and impose minimal costs historically pass more easily; modest bureaucratic coordination is the main friction.

Scope and complexity
24%
Scopenarrow
24%
Complexitylow
Why this could stall
  • No specific funding authorization or cost estimate included
  • Degree of DoD cooperation on CMMC-related guidance
05 · Recent votes

Recent votes on the bill.

No vote history yet

The bill has not accumulated any surfaced votes yet.

06 · Go deeper

Go deeper than the headline read.

Included on this page

Progressives want funding and targeted outreach; conservatives worry about new federal costs

Small, administratively focused bills that aid businesses and impose minimal costs historically pass more easily; modest bureaucratic coord…

Unlocked analysis

Relative to its intended legislative type, this bill clearly assigns administrative duties to the SBA and related offices to develop and disseminate cybersecurity information to small businesses and establishes a recurr…

Go beyond the headline summary with full stakeholder mapping, legislative design analysis, passage barriers, and lens-by-lens tradeoff breakdowns.

Perspective breakdownsPassage barriersLegislative design reviewStakeholder impact map
Open full analysis