Maryland 2026 Regular Session

Maryland House Bill HB957

Introduced
2/5/26  
Refer
2/5/26  
Report Pass
3/20/26  
Engrossed
3/21/26  
Refer
3/23/26  
Report Pass
4/2/26  
Enrolled
4/8/26  
Chaptered
4/14/26  

Caption

Cybersecurity - Standards and Compliance - Alterations

Summary

HB957 makes several changes to Maryland’s cybersecurity requirements, with a particular focus on local school systems. It requires each local school system to designate a local point of contact for cybersecurity communications, notify the State Chief Information Security Officer of that designation, comply with State minimum cybersecurity standards beginning in 2027, conduct a cybersecurity maturity assessment every two years, and certify compliance to the Office of Security Management. The bill also directs the Department of Information Technology to annually review and update the State minimum cybersecurity standards if needed, and to focus on Standard 6.2 Protect (PR) Controls for the 2026–2027 school year. The bill also revises how education technology funds are treated under the Blueprint for Maryland’s Future. It removes the prior requirement that county boards prioritize the purchase of digital devices with certain educational technology funds and instead expands reporting to include cybersecurity expenditures related to the State minimum cybersecurity standards. The Department must compile local reports and submit them to the General Assembly, which increases oversight of how school systems spend technology-related funds. In addition, HB957 clarifies and expands the Department of Information Technology’s support role for local governments and school systems. The Office of Security Management is required to assist local school systems with compliance, maturity assessments, and remediation efforts, while making clear that the Department is not responsible for day-to-day management or successful performance of local duties. The bill also updates statutory definitions to include “State minimum cybersecurity standards” and reinforces existing cybersecurity planning and incident-reporting requirements for counties, local school systems, and local health departments. The overall sentiment around the bill appears strongly favorable and noncontroversial. It passed the House 124-0 and the Senate 43-0, indicating broad bipartisan support and no recorded opposition in the voting history provided. The absence of committee transcript material also suggests there was little publicly noted dispute during consideration. The main policy tension in the bill is between stronger statewide cybersecurity expectations and the administrative burden on local school systems. Supporters appear to favor more consistent standards, regular assessments, and clearer reporting, while the bill also carefully limits the State’s role so it provides guidance and technical support without taking over local operations. Another notable point is the shift away from a device-purchase priority toward broader cybersecurity and reporting requirements, which may affect how local education technology funds are allocated.

Impact

HB957 amends the Education Article and State Finance and Procurement Article to impose new cybersecurity compliance, assessment, and reporting duties on local school systems and to strengthen the Department of Information Technology’s oversight and support functions. It changes the use and reporting of Blueprint-related educational technology funds by removing a device-purchase priority and adding cybersecurity spending as a required reporting category. The bill also updates the statutory framework governing the Office of Security Management and local government cybersecurity preparedness, while preserving local responsibility for implementation.

Sentiment

The bill appears to have been received positively and without significant opposition. It passed both chambers unanimously, with 124-0 in the House and 43-0 in the Senate. That voting record suggests broad agreement that the cybersecurity changes were needed and that the bill’s balance between statewide standards and local implementation was acceptable to lawmakers.

Contention

The most notable issue is the added compliance and reporting burden on local school systems, which must designate contacts, certify compliance, and complete recurring maturity assessments. A related point is the bill’s shift in educational technology funding priorities: it repeals the requirement to prioritize digital device purchases and instead emphasizes cybersecurity expenditures and reporting. The Department of Information Technology’s role was also carefully limited, indicating sensitivity to concerns about state overreach into local school operations, even as the State sets standards and provides technical assistance.

Companion Bills

MD SB601

Crossfiled Cybersecurity - Standards and Compliance - Alterations

Previously Filed As

MD SB907

Cybersecurity - Standards, Compliance, and Audits - Alterations

MD HB0957

Cybersecurity - Standards and Compliance - Alterations

MD HB376

Maryland Cybersecurity Council - Alterations

MD SB294

Maryland Cybersecurity Council - Alterations

MD HB235

State Government - Information Technology - Cybersecurity Revisions

MD SB244

State Government - Information Technology - Cybersecurity Revisions

MD HB0290

Income Tax – Cybersecurity Technology and Service Tax Credit – Alterations

MD SB691

Healthcare Ecosystem Stakeholder Cybersecurity Workgroup

MD HB333

Healthcare Ecosystem Stakeholder Cybersecurity Workgroup

MD SB239

State Finance and Procurement - Local Cybersecurity Preparedness and Response Plan and Assessment - Repeal

Similar Bills

US HB1664

Deploying American Blockchains Act of 2025

US SB1492

Deploying American Blockchains Act of 2025

MS SB2653

Mississippi IT Optimization Act; enact.

KS SB51

House Substitute for SB 51 by Committee on Legislative Modernization - Authorizing the chief information security officer to receive audit reports, updating statutes related to services provided by the chief information technology officer and authorizing the office of information technology services to provide certain services to political subdivisions and hospitals.

NJ S1298

Provides that fusion energy and fusion technology companies are eligible to receive benefits under certain economic incentive programs.

MS HB1724

Statewide Information Technology Optimization Program; create for coordinated efforts across agencies.

NJ A838

Requires State agencies to develop and submit information technology strategic plan.

CA SB1079

Department of Forestry and Fire Protection: Fire Innovation Unit.