Idaho 2026 Regular Session

Idaho House Bill H0888

Introduced
3/12/26  
Refer
3/13/26  
Refer
3/16/26  
Report Pass
3/23/26  
Engrossed
3/24/26  
Refer
3/25/26  

Caption

INFORMATION TECHNOLOGY SERVICES – Amends existing law to revise provisions regarding the powers and duties of the Office of Information Technology Services.

Summary

House Bill 888 revises Idaho Code section 67-827A governing the Office of Information Technology Services (OITS). The bill updates and reorganizes OITS’s powers and duties over state information technology and telecommunications procurement, including its authority to control or coordinate acquisitions for state agencies, higher education, and the legislative and judicial branches, while preserving military division control over public safety and microwave equipment. It also clarifies when OITS may use third-party brokers or the division of purchasing, exempts certain smaller purchases under $15,000, and requires reporting to the governor and legislature when purchases are made contrary to OITS direction or the state’s overall telecommunications plan. The bill also expands and modernizes OITS’s cybersecurity-related responsibilities. It directs OITS to oversee cybersecurity policy implementation, consult with agencies on information security, direct penetration testing and vulnerability scans, require employee cybersecurity training, maintain a statewide cybersecurity website, ensure agencies follow cybersecurity best practices, and require multifactor authentication for access to state IT systems and services. In addition, it authorizes criminal history checks for certain OITS employees and contractors in sensitive technical roles, and makes technical corrections and conforming changes throughout the section. The bill includes an emergency clause and would take effect July 1, 2026. The bill’s impact on state law is to strengthen and clarify centralized oversight of state IT procurement and cybersecurity governance. It affects state agencies, institutions of higher education, the legislative and judicial branches, and OITS contractors and employees, while also touching the division of purchasing and the military division’s existing responsibilities. By codifying more detailed cybersecurity directives and procurement procedures, it increases the statutory specificity of how state technology purchases and security practices must be handled. The general sentiment reflected in the available voting history appears supportive, as the bill passed House third reading 51-14. However, it was later recommitted to State Affairs, suggesting that while it had broad support, some members or procedural concerns remained. No committee transcript was provided, so the record does not show detailed debate or testimony. Notable points of contention likely center on the scope of OITS authority over procurement, the exemption from general purchasing rules, the use of third-party brokers with vendor commissions, and the mandatory cybersecurity requirements such as multifactor authentication and employee training. The criminal history check requirement for certain IT employees and contractors may also raise privacy, hiring, or administrative burden concerns. Supporters likely view the bill as a modernization and security measure, while critics may be concerned about centralized control, compliance costs, and implementation details.

Impact

The bill amends section 67-827A, Idaho Code, to revise the Office of Information Technology Services’ statutory powers over procurement, coordination, cybersecurity oversight, and personnel screening. It changes how state IT and telecommunications equipment may be acquired, adds reporting and exemption provisions, and imposes new statewide cybersecurity and authentication requirements on state agencies and officials. It also authorizes background checks for certain OITS personnel and contractors and makes technical corrections and conforming changes to existing law.

Sentiment

The available voting history suggests generally favorable sentiment, with the bill passing House third reading by a substantial margin, 51-14. At the same time, its later recommittal to State Affairs indicates that some members wanted further review or refinement. Because no committee transcript is available, the record does not reveal specific arguments, but the overall posture appears supportive with some unresolved concerns.

Contention

Likely areas of contention include the breadth of OITS control over state technology procurement, the exemption from standard purchasing procedures, and the use of third-party brokers who may receive commissions from vendors. The bill’s mandatory cybersecurity directives, especially multifactor authentication, training requirements, and required penetration testing, may also be debated for cost and implementation burden. The criminal history check requirement for certain technical employees and contractors could raise concerns about privacy, hiring flexibility, and administrative complexity.

Companion Bills

No companion bills found.

Similar Bills

No similar bills found.