Section 1. Short title
This Act may be cited as the Cybersecurity for Small Businesses Act of 2026.
Section 2. Information and resources relating to cybersecurity matters for small business concerns
The Administrator of the Small Business Administration, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, shall develop and disseminate information and resources to assist small business concerns in strengthening the cybersecurity infrastructure of such concerns and implementing cybersecurity best practices.
(a) Cybersecurity compliance resources
The Administrator of the Small Business Administration, in coordination with the Secretary of Defense and other appropriate Federal agencies, shall disseminate information to a small business concern seeking to enter into a contract with the Federal Government, or seeking to be a subcontractor on a Federal contract, regarding the Cybersecurity Maturity Model Certification program (or successor program), including information necessary to facilitate compliance with such requirements, through small business development centers (as defined in section 3 of the Small Business Act (15 U.S.C. 632)) and district offices of the Administration.
(b) Publication
The Administrator shall include the information described in subsection (a) in outreach and communications of the Small Business Administration, including through publication on a website of the Administration.
(c) Best practices
The Administrator shall annually consult with the Chief Counsel for Advocacy of the Office of Advocacy of the Administration to determine best practices for the dissemination of other information relating to cybersecurity matters to small business concerns.
(d) Annual report
Not later than 90 days after the date of the enactment of this Act, and annually thereafter, the Chief Counsel for Advocacy shall submit to Congress a report that includes the number and a description of small business concerns that contacted the Chief Counsel for Advocacy during the year covered by the report with matters relating to cybersecurity of such concerns.