United States Congress · 119 session
HR 8880 changesSmall Business Cybersecurity Assistance Evaluation Act of 2026
Precomputed change summary for the public. Sign in for the Diff Viewer (word-level redline, evidence, annotations, and exports).
What changed
+498 / −378 words · LargeConfidence: high
This revision fundamentally guts the Small Business Cybersecurity Assistance Evaluation Act by removing nearly all substantive provisions while retaining only the shell of the original bill. The changes delete the entire mandate for the Comptroller General to study Federal cybersecurity assistance to small businesses, eliminating requirements to identify cyber risks and vulnerabilities, assess small business preparedness, evaluate planning and mitigation efforts, examine capital sources for cybersecurity activities, inventory Federal cybersecurity programs, assess awareness and coordination among initiatives, identify gaps in assistance, and provide recommendations for improvement. What remains is essentially the short title, a reporting requirement stripped of its underlying study mandate, and a prohibition on additional funding—transforming a comprehensive evaluation framework into a largely hollow legislative structure.
Change log
SECTION 2 >cont.
modifiedhigh confidenceTechnical/conforming change
This change adds formatting codes, page/line numbering, and version control metadata typical of legislative printing (e.g., 'VerDate Sep 11 2014 01:32 May 20, 2026 Jkt 069200'). The substantive text of subsection (c) regarding the Comptroller General's report to the House and Senate committees remains unchanged. The addition at lines 19-22 appears to be a continuation of preceding subsection text describing the scope of the study (effectiveness, awareness, and coordination of Federal cybersecurity initiatives for small businesses), which provides context but does not alter subsection (c) itself.
SECTION 2 > (2)
removedhigh confidenceRemoval of requirement to identify and describe Federal cybersecurity initiatives in study
This subsection previously required the study to include an identification and description of Federal cybersecurity initiatives, programs, resources, tools, and services. The entire provision has been removed from the bill, eliminating this specific study component.
SECTION 1
modifiedhigh confidenceTechnical/conforming change
Line numbers have been added to the section text. The substantive content of the short title provision remains unchanged.
SECTION 2 > (b)
removedhigh confidenceTechnical/conforming change
The subsection header and introductory clause for '(b) Required Content' was removed. This appears to be a structural reorganization rather than a substantive policy change, as the section previously introduced requirements for a study mandated in subsection (a).
SECTION 2 > (1)
removedhigh confidenceRemoval of provision requiring information on common cyberattacks affecting small businesses
This subsection, which previously required information on the most common cyberattacks affecting small business concerns, has been removed entirely from the bill. No replacement language appears in the diff.
SECTION 2 > (4)
removedhigh confidenceAssessment of coordination among Federal cybersecurity initiatives removed
This section, which previously required an assessment of how various Federal cybersecurity initiatives, programs, resources, tools, and services coordinate and integrate with one another, has been entirely removed from the bill. No replacement language was provided.
SECTION 2 > (3)
removedhigh confidenceRemoved requirement to assess awareness and use of Federal cybersecurity resources by small businesses
This subsection previously required an assessment of how aware small businesses are of Federal cybersecurity initiatives, programs, resources, tools, and services, and how much they use them. It also required examining reasons for differences in awareness and use levels among small businesses. This entire requirement has been deleted from the bill.
SECTION 2 > (a)
removedhigh confidenceStudy mandate on Federal cybersecurity assistance for small businesses removed
This section previously directed the Comptroller General to conduct a study of Federal cybersecurity initiatives, programs, resources, tools, and services intended to assist small business owners. The entire study mandate has been removed from the bill. The study would have examined assistance provided to small business concerns as defined under section 3 of the Small Business Act.
SECTION 2 > (1)
removedhigh confidenceRemoval of provision identifying cyber risks, threats, and vulnerabilities
This section, which previously addressed identifying cyber risks, cyber threats, and cybersecurity vulnerabilities relating to certain concerns, has been removed in its entirety. The deletion eliminates language that established a requirement or framework for identifying these cybersecurity-related issues. No replacement text was provided.
SECTION 2 > (2)
removedhigh confidenceRemoval of assessment of small business preparedness for cyber risks
This paragraph previously required assessing the preparedness of small business concerns for cybersecurity risks, threats, and vulnerabilities. The entire provision has been removed from the bill. No replacement language appears to address preparedness assessment.
SECTION 2 > (3)
removedhigh confidenceSubsection on cybersecurity planning, mitigation, and recovery removed entirely
This subsection, which previously addressed planning for, mitigating, and recovering from cyberattacks and incidents of social engineering, scams, and fraud, has been deleted in its entirety. The removed text included references to developing, adopting, and implementing cybersecurity measures, training, protocols, tools, and infrastructure. No replacement language appears in the diff.
SECTION 2 > (4)
removedhigh confidenceProvision removed: identifying and obtaining capital for cybersecurity activities
A paragraph that authorized identifying sources of capital or obtaining capital to carry out previously specified activities has been deleted. This removal eliminates explicit language regarding capital acquisition for the activities outlined in paragraphs (1), (2), and (3).
SECTION 2 > (5)
removedhigh confidenceAssessment requirement for federal cybersecurity program effectiveness removed
This section previously required an assessment of how effective federal cybersecurity initiatives, programs, resources, tools, and services were in assisting small business concerns with certain activities. The entire assessment requirement has been removed from the bill.
SECTION 2 > (1)
removedhigh confidenceTechnical/conforming change
A reference to subsection (a) paragraphs (1) through (4) was removed from this section. This appears to be a structural or cross-reference adjustment with no substantive policy change evident in the isolated text provided.
SECTION 2 > (6)
removedhigh confidenceRequirement to identify gaps in foundational cybersecurity concepts removed
This provision previously required an identification of foundational cybersecurity concepts that were missing from Federal cybersecurity initiatives, programs, resources, tools, and services. The entire provision has been deleted from the bill, eliminating this gap-analysis requirement.
SECTION 2 > (7)
removedhigh confidenceRequirement for recommendations on improving Federal cybersecurity initiatives for small businesses removed
The bill removes a provision that previously required recommendations on how to improve the effectiveness, awareness, and coordination of Federal cybersecurity initiatives, programs, resources, tools, and services for small business concerns. This deletion eliminates the mandate to provide such improvement recommendations entirely.
SECTION 3
modifiedhigh confidenceTechnical/conforming change
This section retains identical substantive text prohibiting additional funding authorization for the Act. The changes consist solely of line numbering additions (5 and 6), updated formatting codes, and revised publication metadata (date stamp changed from June 4 to May 20, 2026, and document designation from RH to IH).
PREAMBLE
modifiedhigh confidenceTechnical/conforming change
The preamble was updated to reflect a different version of the bill text. The union calendar number, report number, and committee commitment language were removed. Formatting elements such as versioning metadata and line numbers were added or modified. The substantive language requiring the Comptroller General to evaluate Federal cybersecurity assistance to small businesses remains unchanged.
Word-level redline mode, annotations, and exports require a signed-in workspace. Track this bill.