132 STAT. 2444 PUBLIC LAW 115–236—AUG. 14, 2018 Public Law 115–236 115th Congress An Act Aug. 14, 2018 [S. 770] NIST Small Business Cybersecurity Act. 15 USC 271 note. 15 USC 272 note. dkrause on DSKBC28HB2PROD with PUBLAWS Deadline. Consultation. VerDate Sep 11 2014 06:22 Jun 26, 2019 To require the Director of the National Institute of Standards and Technology to disseminate guidance to help reduce small business cybersecurity risks, and for other purposes. Be it enacted by the Senate and House of Representatives of the United States of America in Congress assembled, SECTION 1. SHORT TITLE. This Act may be cited as the ‘‘NIST Small Business Cybersecurity Act’’. SEC. 2. IMPROVING CYBERSECURITY OF SMALL BUSINESSES. (a) DEFINITIONS.—In this section: (1) DIRECTOR.—The term ‘‘Director’’ means the Director of the National Institute of Standards and Technology. (2) RESOURCES.—The term ‘‘resources’’ means guidelines, tools, best practices, standards, methodologies, and other ways of providing information. (3) SMALL BUSINESS CONCERN.—The term ‘‘small business concern’’ has the meaning given such term in section 3 of the Small Business Act (15 U.S.C. 632). (b) SMALL BUSINESS CYBERSECURITY.—Section 2(e)(1)(A) of the National Institute of Standards and Technology Act (15 U.S.C. 272(e)(1)(A)) is amended— (1) in clause (vii), by striking ‘‘and’’ at the end; (2) by redesignating clause (viii) as clause (ix); and (3) by inserting after clause (vii) the following: ‘‘(viii) consider small business concerns (as defined in section 3 of the Small Business Act (15 U.S.C. 632)); and’’. (c) DISSEMINATION OF RESOURCES FOR SMALL BUSINESSES.— (1) IN GENERAL.—Not later than one year after the date of the enactment of this Act, the Director, in carrying out section 2(e)(1)(A)(viii) of the National Institute of Standards and Technology Act, as added by subsection (b) of this Act, in consultation with the heads of other appropriate Federal agencies, shall disseminate clear and concise resources to help small business concerns identify, assess, manage, and reduce their cybersecurity risks. (2) REQUIREMENTS.—The Director shall ensure that the resources disseminated pursuant to paragraph (1)— (A) are generally applicable and usable by a wide range of small business concerns; (B) vary with the nature and size of the implementing small business concern, and the nature and sensitivity Jkt 089139 PO 00236 Frm 00002 Fmt 6580 Sfmt 6581 E:\PUBLAW\PUBL236.115 PUBL236

Select target paragraph3