Maryland 2026 Regular Session

Maryland Senate Bill SB0601

Introduced
2/5/26  
Refer
2/5/26  
Report Pass
3/19/26  
Engrossed
3/20/26  
Refer
3/21/26  
Report Pass
4/8/26  
Enrolled
4/10/26  
Chaptered
4/14/26  

Caption

Cybersecurity - Standards and Compliance - Alterations

Summary

SB601 makes several changes to Maryland’s cybersecurity requirements, with a particular focus on local school systems. It requires each local school system to designate a local cybersecurity point of contact, notify the State Chief Information Security Officer of that designation, comply with State minimum cybersecurity standards beginning in 2027, conduct a cybersecurity maturity assessment every two years, and certify compliance to the Department of Information Technology on a recurring schedule. The bill also directs the Department to annually review and update the State minimum cybersecurity standards if needed, and to focus on Standard 6.2 Protect (PR) Controls for the 2026–2027 school year. The bill also revises school funding reporting rules tied to the Blueprint for Maryland’s Future. It expands the definition of educational technology costs to include cybersecurity, removes the prior requirement that county boards prioritize digital device purchases with those funds, and requires annual reporting of cybersecurity expenditures related to the State minimum cybersecurity standards. In addition, the Department of Information Technology is directed to support and advise local school systems on compliance, maturity assessments, and remediation efforts, while clarifying that the Department is not responsible for day-to-day management of local school system duties.

Impact

SB601 amends the Education Article and State Finance and Procurement Article to impose new cybersecurity compliance, assessment, and reporting obligations on local school systems and to update the Department of Information Technology’s oversight role. It creates a formal statutory framework for local school system cybersecurity coordination, expands reporting on technology spending to include cybersecurity, and codifies the Office of Security Management’s duty to review and update statewide cybersecurity standards annually. The bill also broadens the use of per-pupil technology funds to encompass cybersecurity-related expenses and removes the earlier statutory preference for purchasing digital devices first.

Sentiment

The bill appears to have broad bipartisan support and little visible opposition. It passed the Senate 39-0 and the House 130-0, indicating unanimous support in both chambers. The absence of committee transcript material suggests there was no recorded public controversy in the available materials, and the final enactment reflects a consensus that stronger cybersecurity standards for schools and clearer reporting requirements were needed.

Contention

The main policy tension in SB601 is between stronger statewide cybersecurity oversight and local administrative burden. The bill requires local school systems to meet state standards, conduct recurring maturity assessments, and certify compliance, while also requiring the Department to provide support without taking over day-to-day management. Another point of change is fiscal prioritization: the bill removes the mandate to prioritize digital device purchases with technology funds and instead allows those funds to be used for cybersecurity, which may affect how school systems allocate limited technology resources. No specific organized opposition is reflected in the available voting or transcript record.

Companion Bills

MD HB957

Crossfiled Cybersecurity - Standards and Compliance - Alterations

Previously Filed As

MD SB907

Cybersecurity - Standards, Compliance, and Audits - Alterations

MD HB0957

Cybersecurity - Standards and Compliance - Alterations

MD HB376

Maryland Cybersecurity Council - Alterations

MD SB294

Maryland Cybersecurity Council - Alterations

MD HB235

State Government - Information Technology - Cybersecurity Revisions

MD SB244

State Government - Information Technology - Cybersecurity Revisions

MD HB0290

Income Tax – Cybersecurity Technology and Service Tax Credit – Alterations

MD SB691

Healthcare Ecosystem Stakeholder Cybersecurity Workgroup

MD HB333

Healthcare Ecosystem Stakeholder Cybersecurity Workgroup

MD SB239

State Finance and Procurement - Local Cybersecurity Preparedness and Response Plan and Assessment - Repeal

Similar Bills

US HB1664

Deploying American Blockchains Act of 2025

US SB1492

Deploying American Blockchains Act of 2025

MS SB2653

Mississippi IT Optimization Act; enact.

KS SB51

House Substitute for SB 51 by Committee on Legislative Modernization - Authorizing the chief information security officer to receive audit reports, updating statutes related to services provided by the chief information technology officer and authorizing the office of information technology services to provide certain services to political subdivisions and hospitals.

NJ S1298

Provides that fusion energy and fusion technology companies are eligible to receive benefits under certain economic incentive programs.

MS HB1724

Statewide Information Technology Optimization Program; create for coordinated efforts across agencies.

NJ A838

Requires State agencies to develop and submit information technology strategic plan.

CA SB1079

Department of Forestry and Fire Protection: Fire Innovation Unit.