Procurement - Major Information Technology Development Projects
Summary
SB 487 makes several changes to Maryland’s procurement and information technology oversight framework for major information technology development projects. It requires the Secretary of Information Technology to conduct a risk assessment before approving a project if the Secretary believes the project may pose an exceptional risk to the State, with the assessment focused in part on sensitive or personally identifiable information. If the risk assessment finds the standard limitation of liability is not enough, the Secretary may recommend a higher liability cap, and the Chief Procurement Officer must review that recommendation and may approve a change.
The bill also requires procurement contracts for major IT development projects to include terms governing indemnification and contractor liability, generally capping liability at twice the contract value, while preserving liability for intentional misconduct, fraud, recklessness, and certain injury or property-damage claims. In addition, it directs the Department of Information Technology to strengthen planning and modernization efforts by developing standards for identifying legacy systems, adopting an IT Investment Maturity Model, and creating a State Modernization Plan. The bill further requires annual reporting of risk-assessment recommendations and outcomes, and it orders a study of procurement timelines and staffing impacts for major IT procurements, with a report due to the General Assembly by December 1, 2026.
Impact
The bill amends provisions in the State Finance and Procurement Article governing major information technology development projects and adds a new section on liability terms in procurement contracts. It expands oversight authority for the Secretary of Information Technology and the Chief Procurement Officer, adds a formal risk-assessment and reporting process, and establishes a default statutory cap on contractor liability for major IT development contracts, subject to specified exceptions and possible upward adjustment in high-risk cases. It also imposes new planning, modernization, and reporting duties on the Department of Information Technology and the Modernize Maryland Commission.
Sentiment
Based on the bill text and the absence of recorded committee testimony or votes in the provided materials, the bill appears to be framed as a governance and risk-management measure rather than a controversial policy change. Its stated goals suggest support for stronger oversight, better project planning, and more disciplined procurement practices for large technology projects. The inclusion of a study and reporting requirements also indicates an effort to gather stakeholder input and refine procurement timelines before making broader changes.
Contention
The main points of potential contention are the liability provisions and the new authority to raise liability caps for certain projects. Contractors may be concerned that the bill increases exposure by allowing higher liability limits in exceptional-risk projects, while the State may view the change as necessary protection for sensitive data and high-impact systems. Another possible area of debate is the added oversight burden and whether the new risk-assessment, reporting, and modernization requirements will improve project outcomes or slow procurement and implementation. The required study of procurement timelines suggests lawmakers may also be concerned about whether current procurement schedules make it difficult for vendors to staff major IT projects effectively.
House Substitute for SB 51 by Committee on Legislative Modernization - Authorizing the chief information security officer to receive audit reports, updating statutes related to services provided by the chief information technology officer and authorizing the office of information technology services to provide certain services to political subdivisions and hospitals.