Cybersecurity - Standards and Compliance - Alterations
Summary
SB601 makes several changes to Maryland’s cybersecurity requirements, with a particular focus on local school systems. It requires each local school system to designate a local cybersecurity point of contact, notify the State Chief Information Security Officer of that designation, comply with State minimum cybersecurity standards beginning in 2027, conduct a cybersecurity maturity assessment every two years, and certify compliance to the Department of Information Technology on a recurring schedule. The bill also directs the Department to annually review and update the State minimum cybersecurity standards if needed, and to focus on Standard 6.2 Protect (PR) Controls for the 2026–2027 school year.
The bill also revises school funding reporting rules tied to the Blueprint for Maryland’s Future. It expands the definition of educational technology costs to include cybersecurity, removes the prior requirement that county boards prioritize digital device purchases with those funds, and requires annual reporting of cybersecurity expenditures related to the State minimum cybersecurity standards. In addition, the Department of Information Technology is directed to support and advise local school systems on compliance, maturity assessments, and remediation efforts, while clarifying that the Department is not responsible for day-to-day management of local school system duties.
Impact
SB601 amends the Education Article and State Finance and Procurement Article to impose new cybersecurity compliance, assessment, and reporting obligations on local school systems and to update the Department of Information Technology’s oversight role. It creates a formal statutory framework for local school system cybersecurity coordination, expands reporting on technology spending to include cybersecurity, and codifies the Office of Security Management’s duty to review and update statewide cybersecurity standards annually. The bill also broadens the use of per-pupil technology funds to encompass cybersecurity-related expenses and removes the earlier statutory preference for purchasing digital devices first.
Sentiment
The bill appears to have broad bipartisan support and little visible opposition. It passed the Senate 39-0 and the House 130-0, indicating unanimous support in both chambers. The absence of committee transcript material suggests there was no recorded public controversy in the available materials, and the final enactment reflects a consensus that stronger cybersecurity standards for schools and clearer reporting requirements were needed.
Contention
The main policy tension in SB601 is between stronger statewide cybersecurity oversight and local administrative burden. The bill requires local school systems to meet state standards, conduct recurring maturity assessments, and certify compliance, while also requiring the Department to provide support without taking over day-to-day management. Another point of change is fiscal prioritization: the bill removes the mandate to prioritize digital device purchases with technology funds and instead allows those funds to be used for cybersecurity, which may affect how school systems allocate limited technology resources. No specific organized opposition is reflected in the available voting or transcript record.
House Substitute for SB 51 by Committee on Legislative Modernization - Authorizing the chief information security officer to receive audit reports, updating statutes related to services provided by the chief information technology officer and authorizing the office of information technology services to provide certain services to political subdivisions and hospitals.