AN ACT TO AMEND SECTION 23-15-165, MISSISSIPPI CODE OF 1972, TO REQUIRE THE MISSISSIPPI DEPARTMENT OF INFORMATION AND TECHNOLOGY SERVICES TO ESTABLISH MINIMUM CYBERSECURITY STANDARDS AND POLICIES IN CONJUNCTION WITH THE SECRETARY OF STATE FOR COUNTY REGISTRARS AND ELECTION COMMISSIONERS; TO STIPULATE THAT SUCH STANDARDS AND POLICIES AIM TO ENSURE THE INTEGRITY OF MISSISSIPPI'S VOTER REGISTRATION AND ELECTION DATA IN THE STATEWIDE ELECTIONS MANAGEMENT SYSTEM; TO REQUIRE SUCH POLICIES TO BE ESTABLISHED NO LATER THAN JANUARY 1, 2027; TO PROVIDE FOR ASSESSMENTS OF ADHERENCE TO THE POLICIES; TO REQUIRE CONFIDENTIALITY OF INFORMATION; TO GRANT THE STATE AUDITOR'S OFFICE AUTHORITY TO USE SUCH INFORMATION FOR AUDITING PURPOSES; TO ALLOW MDITS AND THE SECRETARY OF STATE TO REQUEST RESULTS OF INTERNAL ASSESSMENTS; TO PROVIDE FOR FAILURE TO MEET THE ESTABLISHED CYBERSECURITY STANDARDS; AND FOR RELATED PURPOSES.
Summary
SB 2096 amends Mississippi’s voter registration law to require the Department of Information and Technology Services, working with the Secretary of State, to establish mandatory minimum cybersecurity standards for county registrars and election commissioners who access or export data from the Statewide Elections Management System (SEMS). The bill sets a deadline of January 1, 2027, for those standards and requires that they include internal assessments of county compliance. It also directs that the standards be designed to protect the integrity of voter registration and election data.
The bill keeps and reinforces the existing SEMS framework, which is the statewide centralized voter registration database and official record for registered voters. It preserves current rules on data access, system security, and public records exemptions for sensitive voter information such as Social Security numbers, phone numbers, email addresses, and date of birth/age data. It also allows the State Auditor, MDITS, and the Secretary of State to access assessment results for auditing and oversight purposes, while keeping those results confidential from the public.
Impact
SB 2096 changes Section 23-15-165 of the Mississippi Code by adding a cybersecurity compliance regime for county election officials using SEMS. It creates a new state-level mandate for minimum cybersecurity policies, requires assessments of county adherence, and gives the Secretary of State and MDITS oversight authority over those assessments. The bill also creates a funding consequence: counties that fail to comply may have their Election Support Fund monies restricted until they correct deficiencies, with a grace period through January 1, 2028, before the stricter funding limitation applies statewide.
Sentiment
The bill appears to have broad bipartisan support and little visible opposition. It passed the Senate 52-0, the House 120-0, and the Senate concurred in the House amendment 51-0. That voting record suggests strong agreement that election cybersecurity and protection of voter data are important administrative priorities.
Contention
No committee transcript or recorded debate is provided, and the unanimous votes indicate no major public contention in the available record. The main policy issue embedded in the bill is how to balance stronger cybersecurity oversight with county autonomy and administrative burden, especially because noncompliance can trigger limits on Election Support Fund spending. Another potential point of concern is the confidentiality of assessment results, which limits public visibility while allowing oversight by the State Auditor, MDITS, and the Secretary of State.