Income Tax – Cybersecurity Technology and Service Tax Credit – Alterations
HB0290 alters Maryland’s existing income tax credit for purchases of cybersecurity technology and services, renaming it the Buy Maryland Cybersecurity Tax Credit. The bill states that the credit is intended to promote the state’s cybersecurity industry by encouraging Maryland businesses and nonprofits to buy from Maryland-based cybersecurity companies in order to protect business and customer information.
The bill expands and modifies eligibility for both buyers and sellers. A qualified buyer would no longer be limited to entities with fewer than 50 employees in the State; instead, any entity required to file a Maryland income tax return could qualify. For qualified sellers, the bill raises the annual revenue cap from $5 million to $10 million and broadens the business categories that can qualify, including veteran-owned, service-disabled-veteran-owned, businesses owned by historically deprived groups, and businesses located in historically underutilized business zones. It also increases the aggregate annual credit cap for purchases from a single seller from $200,000 to $1 million.
The bill also makes the credit refundable, meaning a buyer could receive a refund if the credit exceeds the buyer’s state income tax liability. It removes the Department of Commerce’s authority to establish an expert panel to help determine qualified sellers, and it eliminates a prior requirement that 25% of annual credits be reserved for cybersecurity service purchases. In addition, the bill ends the Department’s ability to approve credits for taxable years beginning after December 31, 2030.
Overall, the bill appears supportive of Maryland’s cybersecurity sector and small business ecosystem, with a policy emphasis on keeping cybersecurity spending in-state and widening access to the credit. The available context shows no recorded votes or committee testimony, so there is no documented opposition or support in the provided materials beyond the bill’s sponsorship by the Ways and Means Committee at the request of the Department of Commerce.
The main points of potential contention are the broader eligibility rules, the larger credit cap, and the move to a refundable credit, all of which could increase state revenue exposure. At the same time, the bill narrows administrative oversight by repealing the expert panel process and changes the distribution rules for service purchases, which may draw interest from both industry advocates and fiscal watchdogs.
HB0290 would amend § 10-733.1 of the Tax-General Article to revise the Buy Maryland Cybersecurity Tax Credit. It expands who may claim the credit, broadens who may qualify as a seller, increases the per-seller annual cap, makes the credit refundable, removes the panel-based qualification process, and sunsets new approvals after tax year 2030. These changes would affect Maryland taxpayers, cybersecurity vendors, and the Department of Commerce’s administration of the credit, while potentially increasing the state’s fiscal exposure through larger and refundable credits.
The bill’s overall tone is favorable toward Maryland’s cybersecurity industry and toward encouraging in-state purchasing of cybersecurity products and services. Because the bill is introduced by the Ways and Means Committee at the request of the Department of Commerce and there are no recorded votes or hearing transcripts in the provided materials, the available context suggests institutional support rather than visible controversy. The policy direction appears to be economic development-oriented, with an emphasis on helping Maryland businesses and nonprofits strengthen cybersecurity while supporting local vendors.
The most likely areas of contention are fiscal and administrative. Making the credit refundable, expanding buyer eligibility to all Maryland income tax filers, and raising the cap on credits tied to a single seller could increase the cost to the State. Some may also question the removal of the Department’s expert panel for evaluating qualified sellers, since that reduces a layer of outside review. Others may support the broader eligibility changes, especially the inclusion of veteran-owned, service-disabled-veteran-owned, HUBZone, and historically deprived-group-owned businesses, as well as the higher cap for Maryland cybersecurity firms.