Senate Bill 1037, the DIGITAL NC Act, would create the Board of Governors of the North Carolina Digital Sovereignty Authority and task it with developing a comprehensive long-term plan for modernizing, consolidating, and strengthening the cybersecurity of state information technology systems. The bill does not itself reorganize state IT operations; instead, it establishes a nine-member board with specified expertise requirements and directs the board to study and recommend a broad set of reforms, including a 20-year strategic vision, cloud migration, data center divestment, workforce consolidation, an innovation center, and a statewide cyber defense model.
The board would be housed administratively within the Department of Information Technology for support, but would operate independently and consult with multiple state and local entities, including the National Guard, state agencies, school systems, and higher education institutions. It must submit a plan and draft implementing legislation to the General Assembly by March 1, 2027. The bill also provides $100,000 in nonrecurring General Fund support for the board in fiscal year 2026-27 and becomes effective July 1, 2026.
The bill would amend state administrative practice by creating a new advisory and planning body focused on state IT governance, cybersecurity, cloud procurement, workforce structure, and possible future reorganization of the Department of Information Technology into a Digital Sovereignty Authority. However, it expressly states that no substantive reorganization, fee-for-service structure, personnel transfer, or cybersecurity realignment occurs unless and until the General Assembly later enacts implementing legislation. Its immediate legal effect is therefore limited to establishing the board, authorizing consultation and reporting duties, and appropriating startup funding.
Based on the bill text alone, the measure appears generally reform-oriented and forward-looking, emphasizing modernization, cybersecurity, and long-range planning. There is no recorded committee debate or vote history provided, so no direct evidence of support or opposition is available from the supplied context. The structure of the bill suggests an effort to build consensus through study and recommendations rather than immediate restructuring.
The most notable points of potential contention are the bill’s proposed centralization of state IT authority, the possibility of divesting state data centers and moving to cloud-based services, and the idea of consolidating IT personnel across cabinet agencies under a unified enterprise. Other likely areas of debate include the board’s composition requirements, the prospect of fee-for-service funding and continuous appropriations, and the contemplated role of the National Guard and private-sector experts in cybersecurity operations. Because the bill only directs a plan and defers implementation, these issues are framed as future policy choices rather than immediate changes.