This bill requires the Administrator of the Small Business Administration, working through the SBA Chief Information Officer, to implement the recommendations in the Comptroller General report titled "IT MODERNIZATION: SBA Urgently Needs to Address Risks on Newly Deployed System" (GAO-25-106963; published November 6, 2024). The Administrator must submit an implementation plan to the Senate and House small business committees within 180 days. The plan must set policies and procedures for each IT modernization project that address identified risks, define risk parameters, keep risk management strategies, document risks for all project phases, prioritize risks and create risk plans, link mitigation measures to plans, include cyber risk information in acquisition and strategic plans, perform traceability analyses, involve security experts in contractor selection, use GAO guidance for project schedules (GAO-16-89G), and use GAO guidance for cost estimates (GAO-20-195G). The plan must say which SBA office will carry out each action and give timelines. The Administrator must brief the same committees within 30 days after submitting the plan.
The bill directs the SBA to create and share a written plan to improve how it runs IT modernization projects. The plan focuses on better documenting and managing risks, adding cyber risk details, using standard guides for schedules and cost estimates, and involving security experts when choosing contractors. The plan and a follow-up briefing will go to the congressional committees that oversee small business programs. The bill text does not specify changes to programs, services, fees, or funding.
No publicly available information on total costs or appropriations. The bill does require the SBA to develop cost estimates using the Comptroller General's cost estimating guidance (GAO-20-195G).
No publicly available information.
No publicly available information.