Cybersecurity - Standards, Compliance, and Audits - Alterations
SB 907 makes a series of changes to Maryland law aimed at strengthening cybersecurity in local school systems and aligning state oversight with updated cybersecurity standards. The bill removes the existing requirement that county boards of education prioritize purchasing digital devices with certain education technology funds, while preserving the broader use of those funds for educational technology, including cybersecurity. It also expands reporting requirements so local school systems must report spending on information technology staffing, including dedicated cybersecurity personnel, and report cybersecurity expenditures tied to the State minimum cybersecurity standards.
The bill requires each local school system, beginning in 2026, to comply with the State minimum cybersecurity standards, conduct a cybersecurity maturity assessment every two years, and certify compliance to the Office of Security Management. It directs the Department of Information Technology’s Office of Security Management to update the State minimum cybersecurity standards annually, and it requires the Department to assign at least three information security officers to support local school systems with compliance, assessments, and remediation. The bill also instructs the Office of Legislative Audits to use the State minimum cybersecurity standards as a guide when conducting audits, and it adds a school-year-specific directive for the Department to focus on Standard 6.2 Protect (PR) Controls for 2025-2026.
In practical terms, SB 907 would increase state-level cybersecurity oversight of local school systems and create a more formal compliance framework for school technology and security practices. It would affect county boards of education, local school systems, the Department of Information Technology, and the Office of Legislative Audits by adding reporting, certification, staffing support, and audit-reference requirements. The bill also updates statutory definitions and duties in the State Finance and Procurement Article to incorporate the State minimum cybersecurity standards into the broader cybersecurity governance structure.
Because there are no committee transcripts or recorded votes provided, there is no documented floor or committee sentiment to assess from the available materials. Based on the bill text alone, the measure appears to be framed as a modernization and risk-reduction effort, with an emphasis on standardization, accountability, and technical support rather than punitive enforcement.
The main point of potential contention is the added compliance burden on local school systems, which must now meet state cybersecurity standards, complete recurring maturity assessments, and certify compliance on a fixed schedule. Another possible issue is whether the Department of Information Technology has sufficient capacity to provide the required staffing support and annual standards updates. The removal of the digital-device purchasing priority may also draw attention from stakeholders who prefer more direct spending mandates for student devices versus cybersecurity infrastructure.
SB 907 amends the Education Article, State Finance and Procurement Article, and State Government Article to embed the State minimum cybersecurity standards into school funding, reporting, compliance, and audit processes. It eliminates a prior statutory priority for purchasing digital devices with certain education technology funds, while expanding reporting on IT staffing and cybersecurity spending. It also requires local school systems to comply with state cybersecurity standards, complete biennial maturity assessments, and certify compliance, and it directs state cybersecurity officials and auditors to use and update those standards in oversight activities.
No committee discussion or vote history was provided, so there is no recorded legislative sentiment to summarize from debate or roll call data. From the bill text, the measure appears generally supportive of stronger cybersecurity governance in schools and state oversight, with an implementation-oriented tone focused on standards, reporting, and technical assistance rather than controversy or opposition.
The likely areas of contention are the new compliance and reporting obligations placed on local school systems, including recurring maturity assessments and certification requirements, and whether those systems have enough staffing and resources to meet the mandate. The bill also requires the Department of Information Technology to provide at least three information security officers to support school systems, which could raise questions about administrative capacity and funding. Finally, removing the requirement to prioritize digital device purchases may concern stakeholders who want education technology dollars directed more toward student devices and connectivity rather than cybersecurity operations.