Commission to Review and Assess Racial Disparities in the State Criminal Justice System - Establishment
HB1309 makes a series of changes to Maryland’s education and state cybersecurity laws, with a particular focus on local school systems. It removes the existing requirement that county boards of education prioritize purchasing digital devices with certain education technology funds, while expanding the reporting and compliance obligations tied to those funds. Local school systems would have to report cybersecurity staffing and cybersecurity-related expenditures, in addition to connectivity and technology staffing information, and the target per pupil foundation amount would explicitly include cybersecurity as an allowable educational technology cost.
The bill also creates new operational requirements for school systems beginning in 2026. Each local school system would have to comply with State minimum cybersecurity standards, conduct a cybersecurity maturity assessment every two years, and certify compliance to the Office of Security Management. The Department of Information Technology would be required to update the State minimum cybersecurity standards annually, assign at least three information security officers to support local school systems, and focus on Standard 6.2 Protect (PR) Controls for the 2025-2026 school year. In addition, the Office of Legislative Audits would be directed to use the State minimum cybersecurity standards as a guide when conducting audits.
In terms of state law impact, the bill amends the Education Article, State Finance and Procurement Article, and State Government Article to formalize cybersecurity as a core compliance area for local school systems and to strengthen oversight by the Department of Information Technology and the Office of Legislative Audits. It would likely increase administrative obligations for county boards of education and local school systems, while also expanding the role of state cybersecurity officials in setting standards, providing technical assistance, and monitoring compliance.
The general sentiment reflected by the bill text is one of strengthening cybersecurity readiness and accountability in schools and local government operations. Because there are no committee transcripts or recorded votes provided, there is no direct evidence of support or opposition from discussion or voting history. Based on the structure of the bill, the policy emphasis appears to be on improving protection against cyber threats, standardizing reporting, and ensuring that school systems have sufficient staffing and guidance to meet state expectations.
The main points of potential contention are the added compliance burden, staffing expectations, and reporting requirements placed on local school systems and county boards. Some stakeholders may be concerned about the cost of meeting the new standards, hiring or contracting cybersecurity personnel, and completing recurring maturity assessments and certifications. Others may support the bill as a necessary response to cybersecurity risks in education systems and as a way to align school technology spending with security needs.
The bill would amend Maryland law to make cybersecurity a more explicit and enforceable obligation for local school systems, while also changing how education technology funds are described and reported. It adds cybersecurity to the list of educational technology uses under the Blueprint funding provisions, removes the mandate to prioritize digital device purchases, and requires more detailed reporting on IT staffing and cybersecurity expenditures. It also requires annual updates to state cybersecurity standards, periodic compliance certifications by school systems, and guidance from those standards in legislative audits, thereby increasing state oversight and standardization across local systems.
No committee transcript or vote record is provided, so there is no direct evidence of legislative debate or recorded support/opposition. The bill’s language suggests a generally pro-cybersecurity, pro-accountability posture, with an emphasis on protecting school systems and improving statewide consistency. The overall tone is preventative and administrative rather than controversial on its face, though the added mandates could draw concern from local education agencies over implementation costs and capacity.
The likely areas of contention are the new mandates on local school systems: compliance with state cybersecurity standards, biennial maturity assessments, certification requirements, and staffing levels determined by the State Chief Information Security Officer. County boards and school systems may object to the cost and administrative burden of these requirements, especially if they must hire specialized staff or rely on contractors. There may also be debate over the removal of the requirement to prioritize digital device purchases, since some stakeholders may prefer education funds remain focused on student devices and connectivity rather than cybersecurity staffing and compliance.