Congressional Legislation · bill 119hr4491 · built from our database

Both sides have signed this (Bill Ranking)

SBA IT Modernization Reporting Act

H.R. 4491 · 119th Congress (2025-2026)

H.R. 4491119TH CONGRESSINTRODUCED 07/17/2025REP. CISNEROSD-CA · SPONSORLeft: no (Sponsor Ranking)Lean left: DW-NOMINATE -0.46 (Sponsor Ranking)Center: no (Sponsor Ranking)Lean right: no (Sponsor Ranking)Right: no (Sponsor Ranking)LEAN LEFT(SPONSOR RANKING)COMMERCE

2 members · Left 1 · Center 0 · Right 1 (Bill Ranking)

SponsorRep. Cisneros, Gilbert Ray (D-CA) (Introduced 07/17/2025)
Sponsor Voting RecordLean left · DW-NOMINATE -0.46 · measured from every roll-call vote this member has cast (voteview.com) (Sponsor Ranking)
Support
LLLCLRR

support across the spectrum: 2 members signed on (Bill Ranking) this bill: sponsor + current cosponsors, each once

CommitteesSenate - Small Business and Entrepreneurship Committee; House - Small Business Committee; House - Small Business Committee; House - Small Business Committee
Latest Action12/02/2025 Received in the Senate and Read twice and referred to the Committee on Small Business and Entrepreneurship.
Roll Call VotesThere have been no roll call votes
Sourceview on congress.gov →
IntroducedPassed HousePassed SenateResolving DifferencesTo PresidentBecame Law

Summary (1)

Reported to House (08/15/2025)

SBA IT Modernization Reporting Act

This bill requires the Small Business Administration (SBA) to implement the recommendations from a Government Accountability Office (GAO) report published on November 6, 2024, related to modernizing the SBA's information technology systems.

Specifically, the SBA must address risks related to its certification project that allows small businesses to apply for and manage government contracting certifications. The GAO recommendations include developing a project risk management strategy and risk mitigation plan and managing cybersecurity vulnerabilities.

The SBA must submit to Congress an implementation plan for the modernization not later than 180 days after the enactment of this bill.

Text (4)

Engrossed in House (EH)

119 HR 4491 EH: SBA IT Modernization Reporting Act U.S. House of Representatives text/xml EN Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain. IB 119th CONGRESS1st Session H. R. 4491

IN THE HOUSE OF REPRESENTATIVES AN ACT To require the Administrator of the Small Business Administration to implement certain recommendations relating to information technology modernization, and for other purposes.

1.Short titleThis Act may be cited as the SBA IT Modernization Reporting Act.

2.Implementation of recommendations relating to information technology modernization for the Small Business Administration (a)In generalThe Administrator of the Small Business Administration, acting through the Chief Information Officer of the Administration, shall take such actions as may be necessary to implement the recommendations contained in the report of the Comptroller General of the United States titled IT MODERNIZATION: SBA Urgently Needs to Address Risks on Newly Deployed System (GAO–25–106963; published November 6, 2024). (b)Implementation planNot later than 180 days after the date of the enactment of this Act, the Administrator shall submit to the Committee on Small Business of the House of Representatives and the Committee on Small Business and Entrepreneurship of the Senate an implementation plan detailing the actions the Small Business Administration will undertake to establish and implement policies and procedures to govern information technology modernization projects of the Administration. Such policies and procedures shall, with respect to each project— (1)for each risk identified, explicitly state the source of such risk in the relevant risk documentation; (2)clearly define risk parameters; (3)establish and maintain risk management strategies; (4)identify and document risks for all phases of the life cycle; (5)evaluate, categorize, and prioritize risks based on defined risk parameters and develop project risk management plans; (6)connect measures to mitigate risk to risk mitigation plans; (7)require that any information technology acquisition plan and any strategic plan contains information needed to manage cyber risks; (8)require that a traceability analysis is performed and documented; (9)require that security-related subject matter experts are involved in selection process for contractors for a project; (10)develop master schedules using the guidelines contained in the publication of the Comptroller General titled GAO Schedule Assessment Guide: Best Practices for Project Schedules (GAO–16–89G; published December 22, 2015); and (11)develop cost estimates using the guidelines contained in the publication of the Comptroller General titled Cost Estimating and Assessment Guide: Best Practices for Developing and Managing Program Costs (GAO–20–195G; published March 12, 2020). (c)Additional requirementsThe implementation plan required by this section shall include the actions required to carry out the requirements listed in paragraphs (1) through (11) of subsection (b), an identification of the office of the Administration responsible for implementation, and the timelines for completion of each action. (d)Briefing requiredNot later than 30 days after the submission of the implementation plan required under this section, the Administrator shall provide to the Committee on Small Business of the House of Representatives and the Committee on Small Business and Entrepreneurship of the Senate a briefing on the plan. Passed the House of Representatives December 1, 2025.Kevin F. McCumber,Clerk.

Introduced in House (IH)

119 HR 4491 IH: SBA IT Modernization Reporting Act U.S. House of Representatives 2025-07-17 text/xml EN Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain. I119th CONGRESS1st SessionH. R. 4491IN THE HOUSE OF REPRESENTATIVESJuly 17, 2025Mr. Cisneros (for himself and Mr. Jack) introduced the following bill; which was referred to the Committee on Small BusinessA BILLTo require the Administrator of the Small Business Administration to implement certain recommendations relating to information technology modernization, and for other purposes.

1.Short titleThis Act may be cited as the SBA IT Modernization Reporting Act.

2.Implementation of recommendations relating to information technology modernization for the Small Business Administration (a)In generalThe Administrator of the Small Business Administration, acting through the Chief Information Officer of the Administration, shall take such actions as may be necessary to implement the recommendations contained in the report of the Comptroller General of the United States titled IT MODERNIZATION: SBA Urgently Needs to Address Risks on Newly Deployed System (GAO–25–106963; published November 6, 2024). (b)Implementation planNot later than 180 days after the date of the enactment of this Act, the Administrator shall submit to the Committee on Small Business of the House of Representatives and the Committee on Small Business and Entrepreneurship of the Senate an implementation plan detailing the actions the Small Business Administration will undertake to establish and implement policies and procedures to govern information technology modernization projects of the Administration. Such policies and procedures shall, with respect to each project— (1)for each risk identified, explicitly state the source of such risk in the relevant risk documentation; (2)clearly define risk parameters; (3)establish and maintain risk management strategies; (4)identify and document risks for all phases of the life cycle; (5)evaluate, categorize, and prioritize risks based on defined risk parameters and develop project risk management plans; (6)connect measures to mitigate risk to risk mitigation plans; (7)require that any information technology acquisition plan and any strategic plan contains information needed to manage cyber risks; (8)require that a traceability analysis is performed and documented; (9)require that security-related subject matter experts are involved in selection process for contractors for a project; (10)develop master schedules using the guidelines contained in the publication of the Comptroller General titled GAO Schedule Assessment Guide: Best Practices for Project Schedules (GAO–16–89G; published December 22, 2015); and (11)develop cost estimates using the guidelines contained in the publication of the Comptroller General titled Cost Estimating and Assessment Guide: Best Practices for Developing and Managing Program Costs (GAO–20–195G; published March 12, 2020). (c)Additional requirementsThe implementation plan required by this section shall include the actions required to carry out the requirements listed in paragraphs (1) through (11) of subsection (b), an identification of the office of the Administration responsible for implementation, and the timelines for completion of each action. (d)Briefing requiredNot later than 30 days after the submission of the implementation plan required under this section, the Administrator shall provide to the Committee on Small Business of the House of Representatives and the Committee on Small Business and Entrepreneurship of the Senate a briefing on the plan.

Referred in Senate (RFS)

IIB119th CONGRESS1st SessionH. R. 4491IN THE SENATE OF THE UNITED STATESDecember 2, 2025Received; read twice and referred to the Committee on Small Business and EntrepreneurshipAN ACTTo require the Administrator of the Small Business Administration to implement certain recommendations relating to information technology modernization, and for other purposes.1.Short titleThis Act may be cited as the SBA IT Modernization Reporting Act.2.Implementation of recommendations relating to information technology modernization for the Small Business Administration(a)In generalThe Administrator of the Small Business Administration, acting through the Chief Information Officer of the Administration, shall take such actions as may be necessary to implement the recommendations contained in the report of the Comptroller General of the United States titled IT MODERNIZATION: SBA Urgently Needs to Address Risks on Newly Deployed System (GAO–25–106963; published November 6, 2024).(b)Implementation planNot later than 180 days after the date of the enactment of this Act, the Administrator shall submit to the Committee on Small Business of the House of Representatives and the Committee on Small Business and Entrepreneurship of the Senate an implementation plan detailing the actions the Small Business Administration will undertake to establish and implement policies and procedures to govern information technology modernization projects of the Administration. Such policies and procedures shall, with respect to each project—(1)for each risk identified, explicitly state the source of such risk in the relevant risk documentation;(2)clearly define risk parameters;(3)establish and maintain risk management strategies;(4)identify and document risks for all phases of the life cycle;(5)evaluate, categorize, and prioritize risks based on defined risk parameters and develop project risk management plans;(6)connect measures to mitigate risk to risk mitigation plans;(7)require that any information technology acquisition plan and any strategic plan contains information needed to manage cyber risks;(8)require that a traceability analysis is performed and documented;(9)require that security-related subject matter experts are involved in selection process for contractors for a project;(10)develop master schedules using the guidelines contained in the publication of the Comptroller General titled GAO Schedule Assessment Guide: Best Practices for Project Schedules (GAO–16–89G; published December 22, 2015); and(11)develop cost estimates using the guidelines contained in the publication of the Comptroller General titled Cost Estimating and Assessment Guide: Best Practices for Developing and Managing Program Costs (GAO–20–195G; published March 12, 2020).(c)Additional requirementsThe implementation plan required by this section shall include the actions required to carry out the requirements listed in paragraphs (1) through (11) of subsection (b), an identification of the office of the Administration responsible for implementation, and the timelines for completion of each action.(d)Briefing requiredNot later than 30 days after the submission of the implementation plan required under this section, the Administrator shall provide to the Committee on Small Business of the House of Representa-tives and the Committee on Small Business and Entrepreneurship of the Senate a briefing on the plan.Passed the House of Representatives December 1, 2025.Kevin F. McCumber,Clerk.

Reported in House (RH)

119 HR 4491 RH: SBA IT Modernization Reporting Act U.S. House of Representatives 2025-08-15 text/xml EN Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain. IBUnion Calendar No. 181119th CONGRESS1st SessionH. R. 4491[Report No. 119–223]IN THE HOUSE OF REPRESENTATIVESJuly 17, 2025Mr. Cisneros (for himself and Mr. Jack) introduced the following bill; which was referred to the Committee on Small BusinessAugust 15, 2025Committed to the Committee of the Whole House on the State of the Union and ordered to be printedA BILLTo require the Administrator of the Small Business Administration to implement certain recommendations relating to information technology modernization, and for other purposes.1.Short titleThis Act may be cited as the SBA IT Modernization Reporting Act.2.Implementation of recommendations relating to information technology modernization for the Small Business Administration(a)In generalThe Administrator of the Small Business Administration, acting through the Chief Information Officer of the Administration, shall take such actions as may be necessary to implement the recommendations contained in the report of the Comptroller General of the United States titled IT MODERNIZATION: SBA Urgently Needs to Address Risks on Newly Deployed System (GAO–25–106963; published November 6, 2024).(b)Implementation planNot later than 180 days after the date of the enactment of this Act, the Administrator shall submit to the Committee on Small Business of the House of Representatives and the Committee on Small Business and Entrepreneurship of the Senate an implementation plan detailing the actions the Small Business Administration will undertake to establish and implement policies and procedures to govern information technology modernization projects of the Administration. Such policies and procedures shall, with respect to each project—(1)for each risk identified, explicitly state the source of such risk in the relevant risk documentation;(2)clearly define risk parameters;(3)establish and maintain risk management strategies;(4)identify and document risks for all phases of the life cycle;(5)evaluate, categorize, and prioritize risks based on defined risk parameters and develop project risk management plans;(6)connect measures to mitigate risk to risk mitigation plans;(7)require that any information technology acquisition plan and any strategic plan contains information needed to manage cyber risks;(8)require that a traceability analysis is performed and documented;(9)require that security-related subject matter experts are involved in selection process for contractors for a project;(10)develop master schedules using the guidelines contained in the publication of the Comptroller General titled GAO Schedule Assessment Guide: Best Practices for Project Schedules (GAO–16–89G; published December 22, 2015); and(11)develop cost estimates using the guidelines contained in the publication of the Comptroller General titled Cost Estimating and Assessment Guide: Best Practices for Developing and Managing Program Costs (GAO–20–195G; published March 12, 2020).(c)Additional requirementsThe implementation plan required by this section shall include the actions required to carry out the requirements listed in paragraphs (1) through (11) of subsection (b), an identification of the office of the Administration responsible for implementation, and the timelines for completion of each action.(d)Briefing requiredNot later than 30 days after the submission of the implementation plan required under this section, the Administrator shall provide to the Committee on Small Business of the House of Representatives and the Committee on Small Business and Entrepreneurship of the Senate a briefing on the plan.August 15, 2025Committed to the Committee of the Whole House on the State of the Union and ordered to be printed

The bill's own words, from our database (synced from the GPO BILLS XML); paragraph breaks added at the bill's section boundaries, nothing else changed.

All Actions (15)

DateChamberAll Actions
07/17/2025Library of CongressIntroduced in House
07/17/2025Library of CongressIntroduced in House
07/17/2025House floor actionsReferred to the House Committee on Small Business.
07/22/2025House committee actionsCommittee Consideration and Mark-up Session Held
07/22/2025House committee actionsOrdered to be Reported by the Yeas and Nays: 23 - 0.
08/15/2025Library of CongressReported by the Committee on Small Business. H. Rept. 119-223.
08/15/2025House floor actionsReported by the Committee on Small Business. H. Rept. 119-223.
08/15/2025House floor actionsPlaced on the Union Calendar, Calendar No. 181.
12/01/2025House floor actionsMr. Williams (TX) moved to suspend the rules and pass the bill.
12/01/2025House floor actionsConsidered under suspension of the rules. (consideration: CR H4913-4914)
12/01/2025House floor actionsDEBATE - The House proceeded with forty minutes of debate on H.R. 4491.
12/01/2025Library of CongressPassed/agreed to in House: On motion to suspend the rules and pass the bill Agreed to by voice vote. (text: CR H4913-4914)
12/01/2025House floor actionsOn motion to suspend the rules and pass the bill Agreed to by voice vote. (text: CR H4913-4914)
12/01/2025House floor actionsMotion to reconsider laid on the table Agreed to without objection.
12/02/2025SenateReceived in the Senate and Read twice and referred to the Committee on Small Business and Entrepreneurship.

Titles (7)

Title TypeTitle
Display TitleSBA IT Modernization Reporting Act
Short Titles from RFS (Referred to Senate) bill textSBA IT Modernization Reporting Act
Short Title(s) as Passed HouseSBA IT Modernization Reporting Act
Official Titles from EH (Engrossed in House) bill textTo require the Administrator of the Small Business Administration to implement certain recommendations relating to information technology modernization, and for other purposes.
Short Title(s) as Reported to HouseSBA IT Modernization Reporting Act
Short Title(s) as IntroducedSBA IT Modernization Reporting Act
Official Title as IntroducedTo require the Administrator of the Small Business Administration to implement certain recommendations relating to information technology modernization, and for other purposes.

Amendments (0)

There are no amendments to this bill.

Cosponsors (1)

* = Original cosponsor

Committees (4)

CommitteeActivity
Senate - Small Business and Entrepreneurship Committee12/02/2025 Referred To
House - Small Business Committee08/15/2025 Reported By
House - Small Business Committee07/22/2025 Markup By
House - Small Business Committee07/17/2025 Referred To

Related Bills (1)

Subjects (4)

Policy Area: Commerce

All data on this page comes from our own database (legislation.congress_* tables), synced daily from the GPO govinfo BILLSTATUS and BILLS collections. Formatted after congress.gov; nothing is generated. Member placement is their DW-NOMINATE score (voteview.com, Lewis et al.) - a measurement of roll-call voting behavior, not our judgement. Buckets: Left below −0.50 · Lean Left to −0.25 · Center to +0.25 · Lean Right to +0.50 · Right above +0.50. The bill's Support meter aggregates the people who signed the bill - sponsor and current cosponsors, each counted once - nothing else.