The Cyber Security for Small Business Act, introduced in September 2026 by Rep. Tony Wied with Rep. Beth Van Duyne as co-sponsor, directs the SBA to coordinate with the DoD and give small businesses information about CMMC. The lawmakers’ press release promised relief from six-figure compliance costs and vague rules. The hosts read the bill text and found something much smaller: the SBA would point businesses to existing DoD resources (the Office of Small Business Programs, Project Spectrum, and APEX Accelerators), publish that information on an official website, and report annually to Congress on how many small businesses contacted it with cybersecurity questions. Jason sees a possible upside in better awareness and routing, while Jacob calls the bill performative given that five years have passed since the 2021 hearing.
Key Takeaways
- It’s an outreach bill, not a funding or reform bill. No money, no new programs, and no changes to CMMC requirements.
- The SBA gets no new authority. It can’t change CMMC, set the level a contract requires, waive requirements, or reinterpret DoD rules.
- The resources aren’t new. Everything the bill names has existed for years. The SBA becomes a middleman or “distribution layer.”
- The bill was scaled back before markup. Wied filed a replacement version the day after the committee scheduled markup, reducing the SBA’s role in building its own CMMC expertise.
- The press release oversold it. The promise to cut through bureaucracy and reduce consulting costs doesn’t match the text.
- The optimistic case: Many small businesses may simply not know these programs exist, and the SBA’s network could improve awareness and route them efficiently.
- Status: The committee advanced the amended bill unanimously on September 16. The House then left early for its pre-election recess, so passage is most likely in the post-midterm lame-duck session, and the text could still change.
Transcript
Jacob: All right, folks. It’s October, and five years after a House Small Business Subcommittee held a hearing specifically on the impact of CMMC on small businesses, we have some new legislation. The Cyber Security for Small Business Act requires the Small Business Administration to coordinate with the Department of Defense to provide information and resources to small businesses dealing with CMMC.
So is this a fundamental change in how the government approaches small businesses wrestling with cybersecurity requirements? Does this bill empower the SBA to cut through the bureaucracy people talked about when the CMMC Phase 2 suspension was announced in July? Does it empower the SBA to develop its own cybersecurity and compliance expertise and outreach? Or does the bill simply turn the SBA into a distribution layer for DoD’s existing assistance programs? That’s what we’re going to talk about today.
Jason, maybe this is the piece that was missing all along. The people on the Small Business Committee held that hearing in 2021. They took a long time to think about how to help everybody. Here it is.
Jason: From my perspective, it is the piece that’s been missing. People have always added ingredients to the pot, but those ingredients were what wasn’t working in the program. They weren’t a solution for how to move forward or how to solve the problems that exist. We know cost is one of the largest complaints from any business, especially small businesses trying to implement controls to meet NIST and DFARS requirements. So now there’s a solution that says, “This is how we can help you get to this point.”
We need to identify that there’s a need for cybersecurity requirements for a certain audience of DIB contractors. Small business is the biggest argument that comes up: “This is not affordable. This is bureaucratic. This is red tape.” Now somebody comes out with a presented solution. What are you going to do about it?
Jacob: Very exciting stuff. We say all the time that the agencies only have so many levers they can pull. Congress is really the center of power when it comes to something like this. Standalone legislation on this problem is super exciting.
What Lawmakers Say the Bill Will Do
Jacob: Let’s hear what the authors have to say. On September 3rd, 2026, less than two months after the DoD suspended CMMC Phase 2 implementation and launched a review looking at cost, burden, and impact on small business, Representative Tony Wied of Wisconsin, the bill’s author, said it’s critical for small businesses to maintain the highest quality and most up-to-date cybersecurity infrastructure. However, he said, small businesses shouldn’t be forced to spend hundreds of thousands of dollars to obtain a level of cybersecurity they don’t need simply because Washington has failed to provide clear rules. He went on: “The Cyber Security for Small Business Act will provide much-needed clarity to help small businesses protect themselves without forcing them to spend excessive amounts of money trying to comply with vague guidelines.”
All right, Tony, I like the sound of that.
Then Representative Beth Van Duyne of Texas, a co-sponsor of the bill and, for the OGs out there, the ranking Republican on the 2021 subcommittee hearing on CMMC we mentioned earlier, had this to say: small businesses shouldn’t have to spend six figures trying to decipher Washington’s one-size-fits-all bureaucratic cybersecurity rules. She said she was glad to help introduce the bill to give small businesses clear guidance on best practices to protect their networks without wasting time and money on unnecessary requirements.
Jason, Beth and Tony are cooking. Let them cook.
Jason: This sounds outstanding.
Jacob: It does.
Jason: It’s music to my ears. Do you have a demonstrated need for these funds? Do you have a purpose for us in the government, and do we have funds we can give you to help you achieve the cybersecurity to protect the data? Small and innovative businesses are being held out of working with the Defense Department because these cybersecurity requirements are costly and burdensome. They take a lot of time, money and people. So how do we solve that? Now we’re introducing an act that provides funding if you show that you deserve it. This isn’t a PPP loan. This isn’t any of the…
Jacob: No, the system is working. Congress has heard everybody. They listened for five years, apparently, and now we’ve got a piece of legislation.
Jason: Well, the system will be working if the legislation goes through, right?
Jacob: Yes, and we’ll talk about that at the end. Spoiler alert: it’s flying through the process.
What the Bill Actually Says
Jacob: Let’s look at what the bill actually says, since they’re out here making big claims about what it does. It’s very short, shorter than DFARS 7012. Section 3, under “Cybersecurity Compliance Information,” specifically “Cybersecurity Maturity Model Certification Resources,” says:
“The Small Business Administration, in coordination with the Department of Defense and other appropriate federal agencies, shall provide information and resources to small businesses seeking to enter a Federal contract or subcontract regarding the Cybersecurity Maturity Model Certification program, including information and resources produced and provided by the DoD Office of Small Business Programs, Project Spectrum, and the APEX Accelerators program.”
Wait, hold on.
Jason: Is that right?
Jacob: Yes. The SBA and DoD are going to provide information and resources to small businesses: the Office of Small Business Programs, Project Spectrum, the APEX Accelerators program. Wait, hold on. Those are all things that have existed for the last five years. This isn’t anything new.
Jason: But now they’re saying they’re going to do it, Jacob.
Jacob: Okay, well, let’s go on. The bill also says the SBA shall include this information in its outreach and communications, including through publication on an official website.
Jason: That’s exciting.
Jacob: I guess. And the SBA Administrator has to report annually to Congress the number of small businesses that contacted the agency with cybersecurity-related matters.
Hold on. Tony and Beth were out here breathing fire, saying this would reduce the need to spend all this money to understand the requirements. And the legislation says the SBA will put people in contact with the Office of Small Business Programs, Project Spectrum and the APEX Accelerators. Tony, Beth, I love the energy, and I love where you’re coming from, but I don’t know how to tell you this: putting people in contact with those programs doesn’t match the energy in your press release. It’s not going to overhaul the problem.
Jason: But there’s a new coach in charge, right? You changed the regime, you put new people in charge, and the offense fires off the way it’s supposed to. Or it’s like repurposing a closet in your house that just collected junk and turning it into a spacious reading room.
Jacob: Well, I mean, that’s what’s happening here. Repurposing these things.
Jason: Yes. Repurpose the Office of Small Business Programs, Project Spectrum, and the APEX Accelerator program, which I’ve had to work with directly. If these things fire off and get motivated like they haven’t been before, this can be great.
Jacob: Sure. Like in The Big Short, it’s not old fish, it’s a whole new thing. We just put the fish in the soup and now it’s a whole new thing on the menu.
What the SBA Still Can’t Do
Jacob: Here’s what the bill doesn’t do. It doesn’t give the SBA any authority to change CMMC. It doesn’t let the SBA determine what CMMC level should apply to a contract. It doesn’t let the SBA waive any requirements. It doesn’t let the SBA reinterpret any DoD cybersecurity rules, CMMC or otherwise. It doesn’t appear to create a new SBA CMMC compliance center staffed with people who have developed independent guidance, like “here’s how to interpret and understand CMMC.” Instead, the bill uses the SBA network to connect businesses with resources the DoD has already put out there over the last five years. To me, that doesn’t match what they said about the bill in the press release.
Jason: Okay, until we see how it goes. Maybe it is a process. I’m the eternal optimist, and there’s an optimist case here. To help you do business with the DoD more easily, the SBA, which has all these businesses having trouble working with the DoD, readies these resources and makes them known. We know these resources exist, Jacob, but how heavily were they leveraged?
Jacob: Sure.
Jason: Maybe the missing piece, the reason people struggled with CMMC, was that they didn’t know APEX Accelerators or Project Spectrum existed. Let us know in the comments: do you think that was the missing piece? We’ll have to see.
Jacob: Call your reps and let them know. There’s also an interesting detail I’ve held until the end.
The CMMC Provision Changed
Jacob: Let’s talk about how this bill changed during its short legislative history. On September 2nd, Tony Wied introduces the bill, and the House sends it to the Small Business Committee for markup. On September 14th, the committee schedules the bill for markup and consideration, so things are moving quickly. The next day, Wied files a replacement version that changes how the CMMC assistance piece is supposed to work. He created the bill and put out the press release, it went to the committee, and they scheduled it for markup. Then the day before the markup, he says, “No, no, no, do this version instead.”
The change reduces the extent to which the SBA would need to develop independent CMMC expertise. Instead, the SBA becomes a bridge between small businesses and existing DoD assistance programs and infrastructure. Essentially, the SBA should use its enormous small business distribution network, through its development centers, regional hubs and so on, to get cybersecurity assistance to these companies. For CMMC specifically, it does that with resources the DoD has already created for this purpose.
Jason: So it’s not actually empowering the SBA to become the center of expertise on DoD requirements.
Jacob: No, it turns them into the middleman. It basically says, “If you’re a contractor or subcontractor who wants to work with the government, call the SBA.” And they’ll say, “Do you know about Project Spectrum? Do you know about APEX Accelerators? Have you read the FAQ? Here are some websites.”
Jason: So why do you need a bill for this?
Jacob: Good point. Then on September 16th, the Small Business Committee voted unanimously to advance that second version of the bill. The next step is for the committee to formally report the amended bill to the full House, and we may even get a committee report explaining the legislation, which would be very interesting. The problem is that the committee approved the bill immediately before the House left Washington for its pre-election recess, two weeks early. This might have passed if they hadn’t gone on their extended break, but that’s another podcast for another day.
So now we wait. The odds of passing are pretty good in the lame-duck session after the midterms. But they talked a big game in the press release. That came after the suspension announcement, and the SBA was all over that announcement: “We’re empowering the SBA. We’re cutting through the bureaucracy. We’re getting rid of the need to hire consultants by putting you in contact with Project Spectrum.”
Jason: A bit of inside radio for the audience: sometimes I don’t fully know what the topic will be before we talk about it. The intro led me to believe there was funding galore, like Oprah, “You get a loan! You get a loan!” And now it’s just a repurposing of resources that were heavily underutilized in the first iteration of the program, with the Small Business Administration as the gatekeeper of those connections. Maybe you get a reference number or ticket number to go to Project Spectrum or the DoD Office of Small Business, whatever. But there’s no money.
Jacob: Yep. Five years after the hearing on this exact topic, Beth Van Duyne and Tony Wied’s best idea is that if only people knew about APEX Accelerators, they wouldn’t have to hire consultants. That was the problem?
Jason: Hm.
Will This Actually Help Small Businesses?
Jacob: Ultimately, the bill doesn’t change requirements, doesn’t change the program, and doesn’t really empower the SBA to do much other than tell people DoD resources exist. It’s intended to help companies navigate those resources, which then help them navigate the requirements, and these aren’t new resources. They’re what the DoD has had around for a while. So it’s lots of talk and not a lot of substance, like many things involving the description of the CMMC Phase 2 suspension. But this is still in process. The bill could still change in some way when they come back. We’ll keep our eye on it.
We’ll add links below so you can track the bill’s progress yourself. We’ll also link to the 2021 hearing, if you’d like to hear what they heard five years ago and then came up with this plan afterward. Do you think this will be a big benefit? Is this the missing piece that will solve the problem? Let us know in the comments.
Jason: The optimist in me again thinks this works, and I use the term “gatekeeping” not in a negative light. It gatekeeps the resources so they aren’t burdened by small businesses that don’t necessarily have a need. Say I’m a small, innovative business that’s been blindsided by these requirements and wants to do business with the DoD. I talk to the SBA, and they say, “Yes, you’ve been blindsided. Here are these resources, and you’re not waiting in line behind 200 organizations that haven’t done anything for 10 years.” Optimism. I’m just trying to be optimistic.
Jacob: That’s totally fine. I’m not optimistic that this legislation, as written and as of this conversation, would help. It feels performative, hollow and meaningless, and a joke, because it’s been five years. But that’s just my opinion, which is why we save it for the end.
Jason: But they were cooking.
Jacob: The press release was cooking.
Jason: They were cooking. So maybe they have something in store for us. They had to rush this and then go on break. Maybe when they come back, they’ll have some better ideas and expand it. We’ll just have to see.
Jacob: Like and subscribe for updates on pending legislation to help small businesses with their cybersecurity requirements, and we’ll see you next week.
Jason: See you next week.
Contact
Speak With Our Team
Our team of compliance and cybersecurity experts are on standby and ready to help. We’ll walk you through what you need and what to expect.
